Skip to content
Three deadlines. One clock.

EU PQC roadmap milestone, December 31, 2026·CNSA 2.0 acquisition gate, January 1, 2027·US federal PQC deadlines, 2030 and 2031

See the calendar briefing
QCI-QS1 · Readiness checklist

The quantum readiness checklist

Ten steps that move an institution from awareness to evidence. They are drawn from the QCI-QS1 governance standard, which the Quantum Core Institute publishes free of charge. Each step names the proof a board or an examiner will ask for.

  1. Step 01

    Name an accountable owner

    Assign one named executive for cryptographic migration and give that person budget authority. Post-quantum work stalls when it sits across three teams and belongs to none.

    Evidence: A board minute naming the owner and the reporting line.

  2. Step 02

    Build a cryptographic inventory

    List every place your organisation uses cryptography. Applications, certificates, VPNs, code signing, backups, hardware modules, and third-party services all count.

    Evidence: A machine-readable inventory with an owner per entry.

  3. Step 03

    Classify data by how long it must stay secret

    Data that must remain confidential past 2035 is already exposed to harvest-now-decrypt-later collection. That data sets your migration order.

    Evidence: A retention map that ties data classes to migration priority.

  4. Step 04

    Find the RSA and ECC dependencies you do not control

    Most exposure sits in vendor products, embedded devices, and partner interfaces. Ask suppliers for their post-quantum roadmap in writing.

    Evidence: A supplier register with dated roadmap responses.

  5. Step 05

    Map the regulatory clock to your calendar

    European Union Member States must begin migration by December 31, 2026. New United States national security system acquisitions must support quantum-resistant algorithms from January 1, 2027. Federal deadlines land in 2030 and 2031.

    Evidence: A migration plan with dates that sit before the deadlines.

  6. Step 06

    Adopt the NIST standards, not a proprietary substitute

    ML-KEM for key establishment and ML-DSA or SLH-DSA for signatures. Treat anything else as a research project, not a control.

    Evidence: An approved algorithm policy referenced by architecture review.

  7. Step 07

    Design for crypto-agility

    Assume you will change algorithms again. Centralise trust stores, shorten certificate lifetimes, and remove hard-coded algorithm choices from application code.

    Evidence: A documented rotation test on a production-like system.

  8. Step 08

    Pilot hybrid key exchange on real traffic

    Run a hybrid classical and post-quantum handshake on one production path and measure latency, packet size, and failure modes before you scale.

    Evidence: A pilot report with performance numbers and rollback steps.

  9. Step 09

    Update procurement and contract language

    Every new contract with a life past 2030 should require post-quantum support. Retrofitting contracts costs far more than writing the clause now.

    Evidence: Standard clauses in the procurement template.

  10. Step 10

    Report readiness to the board on a schedule

    Migration is a multi-year programme. Report percentage of inventory migrated, exceptions, and supplier risk at a fixed cadence so progress is visible.

    Evidence: A quarterly board pack with a single readiness metric.

Work the checklist in the room

The full Quantum Readiness Workbook goes to attendees of the State of Quantum Readiness Summit on December 9, 2026 in Arlington, Virginia. Two hundred seats, one room, and a single track built for the institutions that have to migrate.