Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

PQC Security Maturity Model: From Beginner to Resilient

NIST New PQC Algorithms

Quick answer: Encryption Consulting’s PQC Maturity Model defines five levels, running from Level 0 to Level 4: the PQC Beginner (no visibility, 100% risk exposure), the PQC Latent (informal awareness with no coordinated action, 80% risk), the PQC Starter (formal acknowledgment and active risk assessment, 70% risk), the PQC Pilot (controlled real-system pilots, 40% risk), and the PQC Resilient (full enterprise integration and continuous crypto-agility, 10% risk). Each level is assessed across six domains, governance and leadership, cryptographic discovery and inventory, risk impact analysis, vendor and supply chain management, training and awareness, and pilot projects. A 2025 Capgemini report found that while 70% of organizations are exploring quantum-safe measures, only 15% qualify for mature governance and strong technical execution, the gap this model is built to close.

A Ponemon Institute study found that 74% of organizations are not ready for the security implications of quantum computing, and the root cause is usually the same: a lack of fundamental visibility into where cryptography actually lives across the enterprise. This model gives that gap a structure, so “how ready are we” gets a specific, evidence-based level rather than a guess.

Key Takeaways

  • The model runs from Level 0 (PQC Beginner, 100% risk) to Level 4 (PQC Resilient, 10% risk), with each level tied to a specific, falling risk percentage.
  • Six assessment domains, governance, cryptographic discovery, risk impact analysis, vendor management, training, and pilot projects, determine an organization’s actual level, not a single metric.
  • A 2025 Capgemini report found 70% of organizations exploring quantum-safe measures, but only 15% qualifying for mature governance and strong technical execution.
  • NIST finalized ML-KEM, ML-DSA, and SLH-DSA as federal standards in August 2024, and finalized HQC as the backup algorithm for ML-KEM in 2025, giving every level a concrete standards reference point.
  • Real-world adopters, including HSBC and Banco Sabadell, are already running PQC pilots, demonstrating that Level 3 is achievable now, not a distant aspiration.

Why This Gap Needs a Maturity Model

NIST has been direct about the stakes: if quantum computers can be built on a scale of thousands of logical qubits, nearly all public-key cryptography used today will become obsolete. The harder problem for most organizations is not disputing that statement, it is knowing where they actually stand against it. Common gaps include no centralized map of where cryptographic algorithms are deployed, no clear understanding of which systems are most exposed, no proactive quantum-impact assessment of critical assets, and a security foundation that has simply never been tested against this specific threat. A maturity model turns those open questions into a structured self-assessment across governance, technology, people, and process.

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

The Six Assessment Domains

Maturity is measured across six interconnected domains, not a single score:

  • Governance and leadership: an executive sponsor, a cross-functional steering committee spanning security, legal, infrastructure, and business, and dedicated budget and ownership for PQC.
  • Cryptographic discovery and inventory: a centralized, regularly updated inventory of where cryptography lives, from TLS certificates and SSH keys to IoT devices and APIs, across both IT and OT environments.
  • Risk impact analysis: which systems would cause the most damage if compromised, accounting for financial, legal, and reputational impact, and explicitly considering harvest-now-decrypt-later exposure for long-lived sensitive data.
  • Vendor and supply chain management: whether key vendors have been engaged on their PQC plans, and whether PQC requirements appear in RFPs, SLAs, and contracts.
  • Training and awareness: whether developers and security teams understand what PQC is and why it matters, with a continuous learning path as NIST standards evolve.
  • Pilot projects: whether hybrid approaches and NIST-approved algorithms have actually been tested in real systems, not just discussed.

Level 0: The PQC Beginner (Risk: 100%)

The lowest level of maturity: cryptography is hardcoded into applications and infrastructure with no clear ownership or documentation, there is no process to track or update cryptographic assets, and quantum risk is treated as tomorrow’s problem, or not discussed at all. Systems running RSA, ECC, or DSA are fully exposed to harvest-now-decrypt-later attacks with no visibility into where those algorithms actually sit. The path forward starts with quantum literacy for IT, security, and leadership teams, a cryptography foundation refresher (RSA, ECC, DSA, AES, SHA-2/3), and bringing harvest-now-decrypt-later risk into a boardroom conversation grounded in NIST’s actual PQC roadmap.

Level 1: The PQC Latent (Risk: 80%)

Emerging, often informal awareness: quantum risk gets raised in meetings, but there is no PQC working group, no budget, and no coordinated action. Crypto discovery may have started but remains patchy and high-level, and compliance and legal teams typically remain uninvolved. Evolving from Latent to Starter means securing formal leadership buy-in for a migration budget, running a real post-quantum risk assessment across high-risk systems, engaging legal and compliance early, assessing vendor PQC posture, and beginning full cryptographic discovery with automated scanning and audits rather than manual spot-checks.

Level 2: The PQC Starter (Risk: 70%)

Formal acknowledgment of the threat: a comprehensive cryptographic inventory is underway, quantum risk assessments have identified the most vulnerable systems, and early hybrid approach evaluations and vendor conversations about quantum-safe roadmaps are in motion. Quantum readiness is recognized as a business-wide issue touching regulation, privacy, and trust, not just a security team concern. Evolving to Pilot means formally approving a phased PQC transition plan with clear roles and KPIs, running a first real-world PQC deployment in a genuinely critical system, training developers and operations teams cross-functionally, and building quantum-safe design into standard CI/CD practice.

Level 3: The PQC Pilot (Risk: 40%)

Organizations move from strategy into hands-on testing: pilot projects using NIST-approved algorithms, often hybrid schemes like ML-KEM paired with classical ECC in TLS handshakes, run in non-production or carefully scoped production environments to evaluate latency, legacy integration, and HSM and TLS stack compatibility. Real-world adopters including HSBC and Banco Sabadell are already running exactly this kind of pilot, evidence that this level is achievable now rather than theoretical. Evolving to Resilient means centralizing key rotation and algorithm transitions through an enterprise crypto-agility platform, requiring quantum-safe capability in every RFP, reviewing PQC KPIs quarterly through a dedicated steering committee, and designing every new system with NIST-approved PQC or hybrid cryptography from inception.

Level 4: The PQC Resilient (Risk: 10%)

The highest level of maturity: post-quantum cryptography is embedded across infrastructure, policy, and workflow. All critical systems run PQC or hybrid encryption, algorithm and key updates flow through software pipelines without disrupting services, live cryptographic inventories and continuous key rotation are standard practice, and legal, compliance, and leadership remain actively engaged rather than treating PQC as a completed project. This is genuine crypto-agility: the organization can absorb a future algorithm change as an operational update, not a multi-year re-architecture, while continuing to monitor emerging standards from NIST, ETSI, and the NSA.

The Migration Pathway: Eight Steps From Beginner to Resilient

Across all five levels, the transition follows eight consistent phases: establishing governance and ownership with executive sponsorship and a cross-functional steering committee; building a centralized cryptographic asset discovery and inventory, complete with a cryptographic bill of materials; running risk assessment and prioritization to rank assets by sensitivity, exposure, and lifespan into a quantum risk matrix; designing the PQC migration strategy itself, choosing between hybrid rollout and a full shift while building in crypto-agility; pilot testing in sandboxed environments before production rollout; coordinating supply chain and vendor involvement, including CBOM review and updated SLAs; implementing a genuinely crypto-agile architecture that decouples cryptographic functions from business logic; and finally, training and monitoring, tracking standards updates from NIST, IETF, and regulators on an ongoing basis rather than treating migration as a one-time project.

What We’d Actually Recommend

Assess your organization honestly against all six domains, not just the one where you feel most confident, since governance, discovery, risk analysis, vendor management, training, and pilots need to advance together for a level to be credible. Treat the Beginner-to-Latent and Latent-to-Starter transitions as the highest-priority near-term work if you have not cleared them, since cryptographic discovery is the foundation every later domain depends on. Use real-world pilot activity, like the adopters already running hybrid schemes in production-adjacent systems, as evidence that Level 3 is a realistic near-term target, not a distant one.

How Encryption Consulting Can Help

Our PQC Advisory Services provide structured guidance across every phase of this maturity model, from cryptographic discovery and risk assessments through hybrid pilot deployments, crypto-agility platform design, and full-scale migration planning, helping organizations move deliberately from wherever they currently stand toward Level 4.

CBOM Secure is what most organizations need to advance out of the Beginner and Latent levels, producing the centralized, continuously updated cryptographic inventory that governance and risk analysis at every later level depend on.

A Lens for Resilience, Not Just a Scorecard

While the exact timeline for a cryptographically relevant quantum computer remains uncertain, the risk posed by harvest-now-decrypt-later attacks is already real today. This five-level model is a strategic lens for assessing cryptographic resilience, threat exposure, and long-term adaptability, not merely a technical checklist. Moving from Beginner toward Resilient demands crypto-agility, cross-functional governance, and a culture where cryptographic health is actively monitored and matured, not a single migration project with a defined end date.

Frequently Asked Questions

What are the five levels of Encryption Consulting’s PQC Maturity Model?

Level 0, the PQC Beginner (100% risk); Level 1, the PQC Latent (80% risk); Level 2, the PQC Starter (70% risk); Level 3, the PQC Pilot (40% risk); and Level 4, the PQC Resilient (10% risk), each defined by specific governance, discovery, and technical criteria.

What percentage of organizations are actually prepared for post-quantum migration today?

A 2025 Capgemini report found that while 70% of organizations are exploring quantum-safe measures, only 15% qualify for mature governance and strong technical execution, reflecting how few organizations have progressed past the earliest maturity levels.

Which domains determine an organization’s PQC maturity level?

Six domains: governance and leadership, cryptographic discovery and inventory, risk impact analysis, vendor and supply chain management, training and awareness, and pilot projects. A credible level requires progress across all six, not strength in just one.

Are any organizations actually running PQC pilots today?

Yes. Real-world adopters including HSBC and Banco Sabadell are already piloting hybrid classical-and-PQC approaches, demonstrating that Level 3 (the PQC Pilot) is an achievable near-term target rather than a theoretical stage.

What distinguishes Level 4 (Resilient) from simply completing a PQC migration?

Level 4 is defined by continuous crypto-agility, live cryptographic inventories, ongoing key rotation, and ongoing engagement with evolving standards, not a one-time migration event. An organization at this level can absorb a future algorithm change as a routine operational update rather than a new multi-year project.