PQC Readiness: Five Practical Steps That Cost Nothing
One of the most common misconceptions about post-quantum cryptography readiness is that it requires immediate, significant investment. The vendor narrative often reinforces this, framing PQC as a procurement challenge demanding urgent budget for new platforms, tools and services.
In reality, the most valuable steps an organisation can take today have very little to do with procurement. They are about focus, governance and planning discipline — the foundations that determine whether subsequent investment delivers genuine value or simply adds another layer of complexity to an already fragmented estate.
That is encouraging for organisations that recognise the importance of the quantum transition but are navigating competing budget priorities. PQC readiness does not start with a purchase order. It starts with a clear understanding of your risk, your data and your cryptographic landscape.
Here are five practical steps that lay the groundwork for a well-governed, phased approach.
1. Use architecture governance to drive PQC readiness
The most cost-effective way to build readiness is to embed it into decisions you are already making. Every enterprise has ongoing procurement cycles, technology refreshes and architecture reviews. Incorporating PQC considerations into those existing governance processes makes incremental progress possible without launching a dedicated programme.
In practical terms this means two things.
Decouple cryptographic functions from applications wherever possible. When new systems are designed or existing ones refreshed, cryptographic operations should be abstracted into centralised services and APIs rather than embedded within individual applications. This principle is valuable regardless of PQC, and it is the foundation of cryptographic agility over time.
Require PQC capability in procurement. As servers, network equipment, HSMs and endpoint devices come up for refresh, the specification should include support for post-quantum algorithms. Across successive refresh cycles the estate becomes progressively PQC-capable without a disruptive, estate-wide upgrade programme.
This is not a theoretical exercise. It is a change to governance processes that costs nothing to make, pays dividends immediately and compounds over time.
2. Know your data
Effective prioritisation must be grounded in a clear understanding of your data landscape: where data resides, what its sensitivity is, how it flows through business systems, and how long it needs to remain protected.
This matters because not all data carries the same quantum risk. As discussed in the context of harvest now, decrypt later, data whose confidentiality value declines rapidly presents a very different risk profile from data that remains sensitive for decades. Understanding the distinction is what prevents both over-investment in low-risk areas and under-investment in high-risk ones.
For some organisations the insight already exists within information governance frameworks, classification policies and compliance documentation. For others it will require structured conversations between technical and business stakeholders about what data matters most, where it sits and how it moves.
The practical addition to existing classification is a retention-of-confidentiality dimension. Sensitivity labels tell you how important data is now. PQC planning needs to know how long it stays that way. Most organisations find the genuinely long-lived category is far smaller than expected, which makes the rest of the work tractable.
None of this requires new tooling. It requires leadership attention, cross-functional collaboration and a willingness to ask fundamental questions that may not have been asked for some time.
3. Employ recognised frameworks for application portfolio management
Most enterprises manage a substantial application portfolio, from modern cloud-native services to legacy systems that have been running for decades. Understanding how that portfolio will evolve is essential to planning a transition that is both realistic and efficient.
Recognised frameworks such as the Gartner TIME model provide a practical way to categorise applications by technical fitness and business value — tolerate, invest, migrate or eliminate. That categorisation informs PQC planning directly by identifying which systems should be upgraded to support quantum-resistant algorithms, which will be retired before PQC becomes critical, and which may require interim mitigation such as architectural wrappers.
Aligning the two avoids two common pitfalls. The first is investing in PQC upgrades for systems approaching retirement, which wastes budget and effort. The second is failing to plan for legacy systems that will remain in service but cannot be upgraded, leaving gaps in the roadmap that surface late.
It also allows PQC changes to be synchronised with natural refresh cycles, reducing incremental cost and disruption. The result is a more predictable investment profile that can be planned across multiple budget periods. Our article on what your technology estate means for readiness covers this in more depth.
4. Understand where cryptography is used
Before you can plan a cryptographic transition, you need to understand what you are transitioning from: where cryptography is used, what algorithms are in play, and which systems depend on cryptographic services.
For many organisations that visibility does not currently exist in structured form. PKI environments evolve organically, with different teams deploying certificates for different purposes. Cryptographic functions sit embedded within applications, operating systems, network devices and cloud services, often with no central documentation.
A practical starting point is externally facing systems and services — the interfaces most exposed to network-level interception and therefore most relevant to immediate quantum risk. Alternatively, or in parallel, map cryptographic touchpoints by describing a "day in the life" of key user personas and identifying where cryptography is involved in their interactions with systems and data.
These initial exercises do not require specialist tooling. They require structured thinking and cross-functional input, and their value extends beyond the technical output: they create a shared understanding of how deeply cryptography is embedded in everyday operations, and build the stakeholder engagement needed to support later investment in automated discovery.
As the picture matures, formalising it into a Cryptographic Bill of Materials makes the output structured, repeatable and ready to inform migration decisions. Our guide to building a cryptographic inventory covers the progression from manual analysis to automated discovery.
5. Ground every decision in risk
This is the most important step, and it underpins the four that precede it. How an organisation adopts post-quantum cryptography must be grounded in a clear, shared understanding of risk, expressed in language business leaders understand.
The risks introduced by quantum computing are not purely technical ones that can be delegated to the security team and managed operationally. They affect data protection, business continuity, regulatory compliance and competitive positioning, which makes them a business transformation rather than an algorithm swap. They need to be visible and actively governed at the highest levels.
For CISOs the risk lens must also extend inward. Cryptographic inventories, discovery findings and migration roadmaps are high-value assets in their own right — they map your weak points — and they require appropriate classification and protection.
Risk should also be the lens through which competing priorities are balanced. Not every system needs transitioning immediately. Not every data flow carries the same exposure. A risk-based approach lets you prioritise investment where it matters, sequence change in a way that is operationally manageable, and demonstrate to boards and regulators that the transition is being governed with appropriate rigour.
What to look for when choosing a quantum readiness vendor
The steps above cost nothing. At some point, most organisations will buy something — discovery tooling, a CLM platform, an HSM refresh, or consultancy. This is where the money goes, and where the market is least helpful.
"Quantum-safe" and "PQC-ready" are marketing terms with no agreed definition. Some questions worth asking before a purchase order is raised.
Which algorithms, and at what maturity?
Ask specifically which of the NIST standards are supported — ML-KEM, ML-DSA, SLH-DSA — and whether that support is generally available, in beta, or on a roadmap. "PQC-ready architecture" frequently means the vendor believes they could add it later.
Support or performance?
These are different questions. Post-quantum keys and signatures are substantially larger than their classical equivalents, and a platform that technically supports ML-DSA may not sustain your issuance volumes with it. Ask for benchmarks under realistic load rather than a feature tick. We cover this in PQC support vs performance: why vendor claims need scrutiny.
Does it handle hybrid?
The realistic transition path runs classical and post-quantum algorithms in parallel for years. A platform that can issue post-quantum certificates but not hybrid ones solves the end state without solving the journey.
What does the discovery actually reach?
For inventory and discovery tooling, coverage matters more than features. Does it reach operational technology, segmented networks, cloud accounts you do not centrally control? Does it distinguish what a system supports from what it actually negotiates? Does it output to an open format such as CycloneDX, or lock the data into a proprietary schema?
Is the urgency coming from evidence or from the vendor?
Anyone presenting a fixed date for cryptographically relevant quantum computing is guessing. The defensible timelines are the regulatory ones — NIST deprecating RSA and ECC from 2030, the NCSC expecting migration plans by 2028 — and those are public. A vendor whose case rests on imminent catastrophe rather than those deadlines is selling urgency.
The wider pattern is worth keeping in mind. We have written separately on why PQC must not repeat the mistakes of cloud and big data, where procurement consistently preceded strategy.
Why these steps matter
These five steps are not a substitute for the technical work the transition will eventually require. They are the foundation that work has to be built on. Without them, organisations commit budget to investments that are poorly targeted, insufficiently governed or misaligned with business priorities.
None of them require significant expenditure, and all of them precede technical implementation. They require leadership attention, governance discipline and cross-functional collaboration.
The acceleration will come — driven by regulatory deadlines, quantum computing developments, or simply the momentum of the industry. For the specific deadlines and algorithm standards driving it, see our guide to navigating the NIST post-quantum cryptography roadmap.
How Unsung can help
We work with organisations at every stage of PQC readiness — whether you are taking first steps towards understanding your exposure, developing architecture governance that embeds PQC considerations, or building the cryptographic visibility needed to prioritise your transition.
Our guidance is independent and vendor-neutral, and proportionate to your risk profile and budget. Our role is to help you make progress that is meaningful, well-governed and sustainable, not to create urgency or drive procurement.
A PKI health check establishes the current position, and PKI consultancy turns these foundational steps into a structured programme with clear milestones.
Talk to our team about where you are and what makes sense next.
Frequently Asked Questions
Can organisations prepare for PQC without major investment?
What are the five practical steps to PQC readiness?
Why is knowing your data important for PQC readiness?
How should organisations prioritise PQC decisions?
Want to explore this topic further?
This blog is part of a series drawn from our strategic whitepaper, Post-Quantum Cryptography: A Strategic Whitepaper for the C-Suite. It provides vendor-neutral, business-focused guidance on navigating the quantum era — covering the threats already in play, lessons from previous hype cycles, and practical steps your organisation can take today. Download your copy here: https://2f4v3l.share-eu1.hsforms.com/20qJjHSynQkuJKhI_xq9Msg


