The quantum readiness checklist
Ten steps that move an institution from awareness to evidence. They are drawn from the QCI-QS1 governance standard, which the Quantum Core Institute publishes free of charge. Each step names the proof a board or an examiner will ask for.
- Step 01
Name an accountable owner
Assign one named executive for cryptographic migration and give that person budget authority. Post-quantum work stalls when it sits across three teams and belongs to none.
Evidence: A board minute naming the owner and the reporting line.
- Step 02
Build a cryptographic inventory
List every place your organisation uses cryptography. Applications, certificates, VPNs, code signing, backups, hardware modules, and third-party services all count.
Evidence: A machine-readable inventory with an owner per entry.
- Step 03
Classify data by how long it must stay secret
Data that must remain confidential past 2035 is already exposed to harvest-now-decrypt-later collection. That data sets your migration order.
Evidence: A retention map that ties data classes to migration priority.
- Step 04
Find the RSA and ECC dependencies you do not control
Most exposure sits in vendor products, embedded devices, and partner interfaces. Ask suppliers for their post-quantum roadmap in writing.
Evidence: A supplier register with dated roadmap responses.
- Step 05
Map the regulatory clock to your calendar
European Union Member States must begin migration by December 31, 2026. New United States national security system acquisitions must support quantum-resistant algorithms from January 1, 2027. Federal deadlines land in 2030 and 2031.
Evidence: A migration plan with dates that sit before the deadlines.
- Step 06
Adopt the NIST standards, not a proprietary substitute
ML-KEM for key establishment and ML-DSA or SLH-DSA for signatures. Treat anything else as a research project, not a control.
Evidence: An approved algorithm policy referenced by architecture review.
- Step 07
Design for crypto-agility
Assume you will change algorithms again. Centralise trust stores, shorten certificate lifetimes, and remove hard-coded algorithm choices from application code.
Evidence: A documented rotation test on a production-like system.
- Step 08
Pilot hybrid key exchange on real traffic
Run a hybrid classical and post-quantum handshake on one production path and measure latency, packet size, and failure modes before you scale.
Evidence: A pilot report with performance numbers and rollback steps.
- Step 09
Update procurement and contract language
Every new contract with a life past 2030 should require post-quantum support. Retrofitting contracts costs far more than writing the clause now.
Evidence: Standard clauses in the procurement template.
- Step 10
Report readiness to the board on a schedule
Migration is a multi-year programme. Report percentage of inventory migrated, exceptions, and supplier risk at a fixed cadence so progress is visible.
Evidence: A quarterly board pack with a single readiness metric.
Work the checklist in the room
The full Quantum Readiness Workbook goes to attendees of the State of Quantum Readiness Summit on December 9, 2026 in Arlington, Virginia. Two hundred seats, one room, and a single track built for the institutions that have to migrate.
