For most organizations, the immediate focus is readiness for a future cryptographically relevant quantum computer: finding vulnerable public-key cryptography, estimating how long protected data must remain secret, and planning controlled migration before exposure becomes practical.
The discipline is broader than choosing a post-quantum cryptography (PQC) algorithm. It includes governance, data-retention horizons, cryptographic inventories, protocol and certificate dependencies, suppliers, replacement constraints, testing, crypto agility, incident planning, and the secure retirement of old keys and algorithms.
Key points
Threat and time horizonRelate plausible quantum capabilities to the algorithms in use, the confidentiality life of stored or intercepted data, the authenticity life of signatures, and realistic migration lead times.
Dependency inventoryTrace cryptography through applications, libraries, hardware security modules (HSMs), certificates, firmware, devices, archives, partner protocols, and managed services, including systems that cannot be upgraded easily.
Roadmap and agilityAssign ownership, require supplier plans, test approved replacements, manage hybrid or transitional designs carefully, prevent downgrade, and preserve the ability to change algorithms and parameters again.
Important limitationThe arrival date and capabilities of a cryptographically relevant quantum computer remain uncertain, and inventories or discovery tools will miss dependencies. PQC migration reduces particular cryptographic risks; it does not resolve weak implementations, endpoints, identities, access controls, or every threat to quantum systems.