Q-Day checklist
20-point crypto agility checklist
Use this as a self-audit worksheet — or automate each step with Qtangl Assess and Monitor.
Inventory & visibility
- Document all TLS endpoints exposed to the internet
- Inventory code-signing and artifact signing keys
- Map JWKS and OAuth/OIDC signing algorithms
- Catalog HSM and KMS key types and sizes
- Identify third-party SaaS with embedded legacy crypto
Risk & deadlines
- Apply Mosca inequality (X + Y > Z) to long-lived data
- Classify HNDL exposure for archived ciphertext
- Map findings to NSM-10 / CNSA 2.0 / NIST IR 8547 tiers
- Set internal migration milestones before regulatory deadlines
- Prioritize by data sensitivity, not alphabetically
Migration & proof
- Assign owners to every quantum-vulnerable finding
- Define hybrid TLS rollout plan (ML-KEM + legacy fallback)
- Require re-scan verification after each remediation sprint
- Export CycloneDX CBOM for CMDB and GRC ingestion
- Maintain signed evidence pack for each audit cycle
Operations & monitoring
- Schedule recurring crypto posture scans (not annual panic)
- Alert on new quantum-vulnerable endpoints after deploy
- Detect certificate and cipher suite regressions
- Track readiness score trend for board reporting
- Integrate drift alerts with Slack, email, or SIEM webhooks