Before You Plan a PQC Migration: 7 Questions to Assess Your Readiness

Key Highlights 

Post-quantum cryptography (PQC) is moving from standards development toward implementation. NIST recommends that organizations begin transitioning to its finalized PQC standards, while recent EU roadmap feedback shows that organizations are now looking for clearer guidance on risk, prioritization, and implementation.¹ ²

Before building a migration roadmap, organizations need to know whether they have enough visibility to make informed decisions. These seven questions provide a quick readiness check to identify gaps that should be addressed before migration planning moves forward.

Are You Ready to Plan a PQC Migration?

On September 2, 2026, the European Commission published stakeholder feedback on its coordinated roadmap for the transition to PQC. Respondents welcomed its risk-based approach and practical guidance, but also called for greater clarity around quantum-risk estimation, migration prioritization, and implementation timelines.²

The feedback highlights an important gap between PQC awareness and PQC readiness.

An organization may understand that migration is necessary while still lacking the visibility needed to decide what should migrate first, what can wait, or where the greatest risks lie.

NIST recommends beginning the transition now and has identified cryptographic discovery and inventory as important parts of migration preparation.¹ Before developing a detailed roadmap, organizations should first determine whether they can answer the following questions.

1. Which data needs to remain protected for years?

Start by looking at the information that cryptography is protecting.

Some data loses sensitivity relatively quickly, while financial records, intellectual property, government information, or other sensitive data may require confidentiality for much longer.

This matters because quantum risk is not limited to the future arrival of a cryptographically relevant quantum computer. With a "harvest now, decrypt later" attack, encrypted information can be collected today and retained for possible decryption in the future.

Organizations should understand how long important information needs to remain confidential and which systems protect it. If those requirements are unclear, it becomes difficult to determine where PQC preparation is most urgent.

 2. Do you know where public-key cryptography is being used?

Public-key cryptography can be embedded throughout an organization's technology environment, including systems that security teams may not immediately associate with cryptographic infrastructure.

NIST's PQC migration work emphasizes the need to identify where quantum-vulnerable public-key algorithms are being used.¹

This requires more than knowing that the organization uses RSA or elliptic-curve cryptography. Teams need enough visibility to locate those uses and understand the systems or processes that depend on them.

If that information is incomplete or based largely on assumptions, cryptographic discovery should come before detailed migration planning.

3. Do you have a usable cryptographic inventory?

Cryptographic discovery provides the raw picture of what exists across the environment. The next step is turning those findings into a usable inventory that gives security teams enough context to assess risk and make migration decisions.

A Cryptographic Bill of Materials (CBOM) can provide a structured way to document cryptographic components and their relationships.

The broader objective, however, is not simply to produce documentation. The inventory needs to help teams understand where cryptography is deployed, what it protects, and which systems depend on it.

A useful test is whether the inventory can help answer practical migration questions.

  • Can the organization identify affected systems?
  • Can it connect cryptographic assets to owners or dependencies?
  • Can it determine which findings require further assessment?

If not, the inventory may not yet provide enough visibility for migration planning.

4. Can you identify which cryptographic assets face the greatest risk?

Finding quantum-vulnerable cryptography does not automatically tell an organization what should be addressed first.

Migration priorities need to reflect the context surrounding each asset.

Data confidentiality requirements are one consideration. System importance and exposure also affect the risk, while migration complexity can influence how early preparation needs to begin.

This is becoming a significant implementation question. In the European Commission's latest roadmap feedback, stakeholders specifically requested greater clarity around quantum-risk estimation and migration prioritization.²

The objective is to move from a technical inventory toward a risk-informed view of the cryptographic environment.

 5. Do you know which systems will be hardest to migrate?

Migration complexity should be identified early.

Legacy systems may be difficult to update, while some cryptographic dependencies may sit with external vendors or technology providers.

A difficult migration does not necessarily make a system lower priority. In some cases, the longer lead time is exactly why planning needs to begin earlier.

Organizations may need time for testing, procurement, vendor coordination, or architectural changes before migration can take place.

Readiness therefore requires understanding not only where vulnerable cryptography exists, but also what stands between the current environment and a successful transition.

6. Do you know what should migrate first?

A cryptographic inventory can reveal the scale of the problem, but an organization still needs a way to turn that information into a migration sequence.

The EU's coordinated roadmap takes a risk-based approach and calls for high-risk use cases to transition earlier.³

At the organizational level, the same principle means identifying which systems warrant earlier action based on their exposure and the time required to migrate them.

The result should be a set of defensible priorities.

If every affected system is classified as equally urgent, the assessment has not yet provided enough information to guide migration.

7. Can your environment adapt when cryptography changes again?

PQC migration should not recreate the same cryptographic management problem for the next generation of algorithms.

Standards will continue to evolve, and organizations need to be prepared for future changes.

A recent example came in July 2026, when NIST reported that an additional digital-signature algorithm under consideration for standardization had been withdrawn after researchers identified a vulnerability. NIST confirmed that the issue did not affect its three finalized PQC standards.¹

This is where crypto-agility becomes part of readiness.

Organizations should consider how quickly they can locate affected cryptography and implement changes when requirements evolve. The easier those changes are to manage, the less disruptive future cryptographic transitions become.

Quick PQC Readiness Check

This is a directional check rather than a formal maturity assessment.

6–7 questions answered clearly:
You may have enough visibility to move into more detailed migration planning. Validate the information before setting migration priorities.

3–5 questions answered clearly:
Important gaps remain. Determine whether those gaps are primarily related to cryptographic visibility, risk assessment, or migration planning.

0–2 questions answered clearly:
Focus first on cryptographic discovery and inventory. Building a detailed migration sequence without sufficient visibility is likely to introduce assumptions into the plan.

The goal is not to achieve a perfect score. It is to identify what the organization still needs to understand before committing resources to migration.

What Should You Do With the Results?

The gaps identified by this readiness check can help determine the next step.

Organizations with limited cryptographic visibility should focus on discovery and inventory, while those that already understand their environment can move toward risk assessment and migration prioritization.

Organizations that know what needs to change but face difficult implementation constraints can begin developing a phased migration roadmap. Crypto-agility should also be considered where future cryptographic changes remain difficult to manage.

PQC readiness is ultimately about having enough information to make defensible migration decisions.

For CeQureX (CQX), that starts with understanding the existing cryptographic environment before determining how the transition should proceed.

Find out where your organization stands on PQC readiness.

Book Wave-Key Demoto identify where your organization should start its PQC migration.

About CeQureX

CeQureX (CQX) helps organizations prepare for and manage the transition to post-quantum cryptography. The CQX Wave Series includes:

  • Wave-Key: a cryptographic inventory and assessment tool for discovering and understanding cryptographic assets.
  • Wave-On: a PQC card for deploying post-quantum cryptography and supporting cryptographic modernization.
  • Wave-Plus: a translation proxy designed to bridge PQC and existing environments during migration.
  • WaaS (Wave as a Service): a service-based approach to ongoing PQC and cryptographic management.

Together, the CQX Wave Series supports the PQC journey from cryptographic visibility and assessment through migration and ongoing management.

Reference materials

1. National Institute of Standards and Technology (NIST) “Post-Quantum Cryptography” and “Migration to Post-Quantum Cryptography.” 

NIST Post-Quantum Cryptography

NIST NCCoE Migration to Post-Quantum Cryptography

2. European Commission, “EU Roadmap on Post-Quantum Cryptography: Survey Feedback,” September 2, 2026.
The feedback covers implementation timelines, risk-based approaches, hybrid schemes, crypto-agility, quantum-risk estimation, and prioritization.

European Commission survey feedback

3. European Commission and NIS Cooperation Group “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography,” June 2025.

EU coordinated PQC roadmap