PQC Audit Evidence
Evidencing post-quantum readiness to auditors and regulators
Auditors assess artefacts, not intentions. A post-quantum secure position is evidenced by a dated cryptographic inventory, a documented risk assessment, a migration plan with named owners, a supplier engagement record and an exception register. Statements of commitment carry no assurance value.
Who is asking, and why
Post-quantum readiness now appears in several assurance contexts at once.
Internal audit picks it up through cryptographic control testing and technology risk. External auditors encounter it where cryptography supports financial reporting controls or where certification is in scope. Certification bodies assess it under ISO 27001, where the control covering use of cryptography requires a policy and its implementation to be demonstrated.
Regulators arrive through sector routes. Financial entities face ICT risk and third-party oversight obligations under DORA. Organisations in scope of NIS2 face supply chain security requirements. UK critical national infrastructure operators are assessed against the NCSC Cyber Assessment Framework, where cryptographic protection of data and systems sits within the relevant principles.
Customers are frequently the most demanding source. Suppliers to US federal buyers face contractor obligations following Executive Order 14412, and prime contractors in regulated supply chains are passing cryptographic requirements down.
What counts as evidence

The pattern across the table is that every artefact carries a date, an owner and a scope. An undated inventory of unknown coverage is not evidence, and auditors treat it accordingly.
Why the inventory is the pivotal artefact
Every other artefact depends on it. Exposure cannot be assessed without knowing what cryptography exists. Migration duration cannot be estimated. Priorities cannot be justified. Exceptions cannot be enumerated.
It is also the artefact most often missing or inadequate. Ponemon's 2026 research found that 68 per cent of organisations consider managing cryptographic assets extremely or very difficult, which aligns with what assessments find: public certificates are enumerated, internal certificate authorities partially, and embedded keys, appliance firmware, hardcoded trust stores and supplier interfaces not at all.
Two properties make an inventory audit-ready. Coverage must be stated honestly, as a percentage of the estate with the excluded portion identified, because an inventory claiming completeness that an auditor can disprove is worse than one that states its limits. And it must be refreshed on a defined cadence, since a cryptographic inventory decays continuously as systems change. A machine-readable cryptographic bill of materials supports both properties in a way that a spreadsheet does not.
Mapping evidence to frameworks
The same artefact set satisfies most frameworks, which is worth stating explicitly when the programme is being funded.
Under ISO 27001, the cryptographic policy, inventory and key management records address the control on use of cryptography, and the migration plan and exception register support the risk treatment plan. Under the NCSC Cyber Assessment Framework, the inventory and risk assessment support the principles covering data and system security, with the migration plan evidencing that identified risk is being managed. Under DORA, the inventory and supplier engagement record support ICT risk management and third-party oversight requirements. Under NIS2, the supplier record and exception register support supply chain security obligations.
Against the NCSC migration timelines, the position is more direct. The 2028 milestone expects a completed discovery exercise, an initial migration plan identifying priorities, dependencies and investment, and communication of requirements to suppliers. Those are three of the artefacts above, and an organisation holding them is demonstrably on track.
Common audit findings
No inventory, or one limited to public certificates. This is the most frequent finding and the one that undermines every other answer, since without it no claim about coverage or priority can be substantiated.
An inventory that is stale. A snapshot taken eighteen months ago describes an estate that no longer exists. Auditors look for the refresh mechanism, not the document.
A plan without dates or owners. A migration roadmap expressed as phases with no named accountability and no milestone dates is treated as an intention rather than a plan.
Unrecorded exceptions. Assets that cannot be migrated are not a finding in themselves. Assets that cannot be migrated and are not recorded, with no compensating control and no acceptance, are.
No supplier evidence. Where third parties hold data or issue trusted credentials, the absence of any record of engagement is a gap in third-party risk management independent of the quantum question.
Metrics presented once. A single snapshot demonstrates a report was produced. A time series demonstrates a programme is running.
Keeping the evidence current
Three practices make the difference between an evidence set that holds up and one that has to be rebuilt before every audit.
Automate discovery so that inventory refresh is a scheduled process rather than a project. Where certificate lifecycle tooling is already deployed, much of this is a configuration exercise rather than new capability.
Record decisions when they are taken rather than reconstructing them later. Board minutes recording risk appetite, funding and target date are far more persuasive than a paper written afterwards describing what was decided.
Maintain the exception register as a live document with review dates. Exceptions accumulate, compensating controls degrade, and replacement dates pass. A register reviewed quarterly is evidence of control; one written once is evidence of an intention.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.
We produce the artefacts an audit requires rather than a report about them: a dated inventory with stated coverage through our PKI health check and cryptographic bill of materials services, a documented risk assessment, and a migration plan with owners, dependencies and dates aligned to the NCSC milestones. Through our PKI consultancy practice we also support cryptographic policy, exception handling and the reporting cadence that keeps the evidence current.
For the governance decisions these artefacts record, see placing post-quantum risk on the board register.
Frequently asked questions
What evidence do auditors expect on post-quantum readiness?
Is a spreadsheet inventory sufficient?
How do we evidence readiness when migration has not started?
What should we do about assets that cannot be migrated?
Which frameworks does this evidence satisfy?
How often should the inventory be refreshed?


