Post-quantum readiness
Q-Day readiness: inventory before the deadline
Boards are asking for RSA/ECDSA exposure counts, not slide decks. The question is no longer whether post-quantum migration matters — it is whether you can prove what you have, what changed, and who owns the fix.
The Mosca clock is already ticking
Michele Mosca's inequality — X + Y > Z (data lifetime + migration time exceeds adversary capability) — turns abstract quantum risk into a planning deadline. For long-lived secrets, TLS certificates, and archived ciphertext, harvest-now-decrypt-later (HNDL) means exposure today is liability tomorrow.
Use the Mosca inequality guide and HNDL primer on our Q-Day hub to quantify shelf-life against migration runway — an inventory aid, not a formal attestation.
Inventory is the unblocker
Most enterprises cannot answer three basic questions: which systems still depend on RSA or ECDSA, which third-party libraries embed legacy crypto, and which teams own remediation. A one-time spreadsheet exercise decays within weeks as new deployments ship.
Qtangl's Assess tier produces a prioritized backlog with algorithm tags, compliance crosswalks (NSM-10, CNSA 2.0, NIST IR 8547), and signed scan artifacts suitable for audit evidence.
Monitor beats annual panic
A single assessment satisfies this quarter's board slide. It does not catch the microservice that shipped last Tuesday with an outdated OpenSSL pin, or the partner API that rolled back a hybrid TLS experiment.
Continuous Monitor diffs each scan against the prior baseline: new findings, resolved items, readiness score trends, and scheduled re-scan windows aligned to your change cadence.
Convert with evidence, not hope
Migration planning fails when backlog items lack owners, effort estimates, and dependency ordering. Convert ties remediation items to what-if projections: if you clear the top N findings this quarter, what does your readiness curve look like at the next audit?
Hybrid ML-KEM TLS handshakes — live in our demo — prove the target state is reachable without ripping out every legacy endpoint on day one.
Where to start
Run a Q-Day readiness demo against a representative environment. Map your current stage on the maturity model. Estimate status-quo cost vs Monitor with the ROI calculator.
Continue on the Q-Day hub: What is Q-Day?
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- National Security Memorandum on Post-Quantum Cryptography (NSM-10)White House · 2022-05Federal mandate requiring migration away from quantum-vulnerable algorithms by 2035.
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
- Q-Day: Accelerated Timeline Across Wider Attack SurfaceQuantum Computing Report · 2026-04Research summary on ECC-256 potentially breaking before RSA-2048 on accelerated timelines.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.