Blog

PQC Audit Evidence

Auditors want artefacts, not assurances. The evidence set that demonstrates a post quantum secure position, and the findings that come up most often.

Evidencing post-quantum readiness to auditors and regulators

Auditors assess artefacts, not intentions. A post-quantum secure position is evidenced by a dated cryptographic inventory, a documented risk assessment, a migration plan with named owners, a supplier engagement record and an exception register. Statements of commitment carry no assurance value.

Who is asking, and why

Post-quantum readiness now appears in several assurance contexts at once.

Internal audit picks it up through cryptographic control testing and technology risk. External auditors encounter it where cryptography supports financial reporting controls or where certification is in scope. Certification bodies assess it under ISO 27001, where the control covering use of cryptography requires a policy and its implementation to be demonstrated.

Regulators arrive through sector routes. Financial entities face ICT risk and third-party oversight obligations under DORA. Organisations in scope of NIS2 face supply chain security requirements. UK critical national infrastructure operators are assessed against the NCSC Cyber Assessment Framework, where cryptographic protection of data and systems sits within the relevant principles.

Customers are frequently the most demanding source. Suppliers to US federal buyers face contractor obligations following Executive Order 14412, and prime contractors in regulated supply chains are passing cryptographic requirements down.

What counts as evidence

The pattern across the table is that every artefact carries a date, an owner and a scope. An undated inventory of unknown coverage is not evidence, and auditors treat it accordingly.

Why the inventory is the pivotal artefact

Every other artefact depends on it. Exposure cannot be assessed without knowing what cryptography exists. Migration duration cannot be estimated. Priorities cannot be justified. Exceptions cannot be enumerated.

It is also the artefact most often missing or inadequate. Ponemon's 2026 research found that 68 per cent of organisations consider managing cryptographic assets extremely or very difficult, which aligns with what assessments find: public certificates are enumerated, internal certificate authorities partially, and embedded keys, appliance firmware, hardcoded trust stores and supplier interfaces not at all.

Two properties make an inventory audit-ready. Coverage must be stated honestly, as a percentage of the estate with the excluded portion identified, because an inventory claiming completeness that an auditor can disprove is worse than one that states its limits. And it must be refreshed on a defined cadence, since a cryptographic inventory decays continuously as systems change. A machine-readable cryptographic bill of materials supports both properties in a way that a spreadsheet does not.

Mapping evidence to frameworks

The same artefact set satisfies most frameworks, which is worth stating explicitly when the programme is being funded.

Under ISO 27001, the cryptographic policy, inventory and key management records address the control on use of cryptography, and the migration plan and exception register support the risk treatment plan. Under the NCSC Cyber Assessment Framework, the inventory and risk assessment support the principles covering data and system security, with the migration plan evidencing that identified risk is being managed. Under DORA, the inventory and supplier engagement record support ICT risk management and third-party oversight requirements. Under NIS2, the supplier record and exception register support supply chain security obligations.

Against the NCSC migration timelines, the position is more direct. The 2028 milestone expects a completed discovery exercise, an initial migration plan identifying priorities, dependencies and investment, and communication of requirements to suppliers. Those are three of the artefacts above, and an organisation holding them is demonstrably on track.

Common audit findings

No inventory, or one limited to public certificates. This is the most frequent finding and the one that undermines every other answer, since without it no claim about coverage or priority can be substantiated.

An inventory that is stale. A snapshot taken eighteen months ago describes an estate that no longer exists. Auditors look for the refresh mechanism, not the document.

A plan without dates or owners. A migration roadmap expressed as phases with no named accountability and no milestone dates is treated as an intention rather than a plan.

Unrecorded exceptions. Assets that cannot be migrated are not a finding in themselves. Assets that cannot be migrated and are not recorded, with no compensating control and no acceptance, are.

No supplier evidence. Where third parties hold data or issue trusted credentials, the absence of any record of engagement is a gap in third-party risk management independent of the quantum question.

Metrics presented once. A single snapshot demonstrates a report was produced. A time series demonstrates a programme is running.

Keeping the evidence current

Three practices make the difference between an evidence set that holds up and one that has to be rebuilt before every audit.

Automate discovery so that inventory refresh is a scheduled process rather than a project. Where certificate lifecycle tooling is already deployed, much of this is a configuration exercise rather than new capability.

Record decisions when they are taken rather than reconstructing them later. Board minutes recording risk appetite, funding and target date are far more persuasive than a paper written afterwards describing what was decided.

Maintain the exception register as a live document with review dates. Exceptions accumulate, compensating controls degrade, and replacement dates pass. A register reviewed quarterly is evidence of control; one written once is evidence of an intention.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.

We produce the artefacts an audit requires rather than a report about them: a dated inventory with stated coverage through our PKI health check and cryptographic bill of materials services, a documented risk assessment, and a migration plan with owners, dependencies and dates aligned to the NCSC milestones. Through our PKI consultancy practice we also support cryptographic policy, exception handling and the reporting cadence that keeps the evidence current.

For the governance decisions these artefacts record, see placing post-quantum risk on the board register.

Frequently asked questions

What evidence do auditors expect on post-quantum readiness?

A cryptographic policy, a dated inventory with stated coverage, a documented risk assessment, a migration plan with owners and dates, a record of board decisions, evidence of supplier engagement, test results, and an exception register for assets that cannot be migrated. Each artefact needs a date, an owner and a defined scope.

Is a spreadsheet inventory sufficient?

Rarely. It records what someone entered rather than what exists, it has no refresh mechanism, and its coverage cannot be substantiated. A machine-readable cryptographic bill of materials generated from discovery tooling, with a stated refresh cadence, addresses the properties auditors test.

How do we evidence readiness when migration has not started?

Through discovery, assessment and planning artefacts. The NCSC expects a completed discovery exercise, an initial migration plan and supplier communication by 2028, not completed migration. An organisation holding those is demonstrably on track, and saying so with dated evidence is a strong position.

What should we do about assets that cannot be migrated?

Record them on an exception register with the compensating controls applied, a replacement date, and the authority who accepted the residual risk, then review it quarterly. Unmigratable assets are expected. Unmigratable assets that are undocumented and unaccepted are an audit finding.

Which frameworks does this evidence satisfy?

Largely the same set across ISO 27001, the NCSC Cyber Assessment Framework, DORA and NIS2, since all require cryptographic control, risk assessment, third-party oversight and documented treatment. Producing the artefacts once and mapping them to each framework is more efficient than responding separately.

How often should the inventory be refreshed?

Frequently enough that it describes the current estate, which in most environments means quarterly at minimum and continuously where tooling allows. Auditors assess the refresh mechanism rather than the document, so an automated process with a stated cadence is stronger evidence than a recent manual snapshot.
Author
Unsung Ltd
October 6, 2026
-