Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

PQC Readiness Assessment: How Quantum-Ready Is Your Cryptography?

PQC

The PQC Readiness Assessment is a free tool that benchmarks how quantum-ready your cryptography is. You answer 20 quick questions in about four minutes, and it scores your organization against a five-level post-quantum and crypto-agility maturity model across five dimensions of readiness, with a personalized maturity report and tailored next steps.

The PQC Readiness Assessment is a free benchmarking tool from Encryption Consulting. Twenty questions, answered in about four minutes, place your organization on a five-level post-quantum and crypto-agility maturity model. Scores appear on screen across five dimensions of readiness, and a personalized maturity report with detailed recommendations is emailed to you.

Key Takeaways

  • The assessment is free, takes about four minutes, and benchmarks your organization against a five-level post-quantum and crypto-agility maturity model using 20 questions.
  • Results cover five dimensions: Governance & Strategy, Cryptographic Inventory, Crypto-Agility & Technical, PQC Migration Planning, and Operations & Supply Chain.
  • Scores appear on screen instantly, and the full personalized maturity report with recommendations arrives by email.
  • The deadlines it benchmarks against are public: NIST IR 8547 (draft) proposes deprecating RSA, ECDSA, and ECDH after 2030 and disallowing them after 2035, and NIST finalized the replacement standards (FIPS 203, 204, 205) on August 13, 2024.
  • Harvest-now-decrypt-later makes this a present-tense benchmark: data that must stay confidential beyond roughly ten years can be recorded today and decrypted later.

What the Assessment Measures

The 20 questions map to the five dimensions a post-quantum migration actually depends on. Each dimension measures a different failure mode, from strategy that exists only on slides to inventories that miss where keys really live.

DimensionWhat it measuresWhat strong looks like
Governance & StrategyWhether the migration has an owner, executive sponsorship, and enforced cryptographic policyA named accountable owner, a sponsored strategy, quantum risk assessed against how long each data set must stay secret, and approved algorithms and key sizes actually enforced
Cryptographic InventoryWhether you can see every key, certificate, and algorithm in use, and how fresh that picture isA current inventory whose discovery reaches application source code, HSMs, KMS, and database keys, and that can flag RSA, ECDH, and ECDSA across the estate on demand
Crypto-Agility & TechnicalHow much re-engineering it takes to change an algorithm in productionMapped dependencies between certificates, keys, and services; keys managed centrally with rotation; and ML-KEM or ML-DSA already piloted somewhere real
PQC Migration PlanningWhether a sequenced, funded migration exists or just an intentionA documented roadmap aligned to the 2030 and 2035 milestones, systems prioritized by risk and data sensitivity, vendors on the record about their PQC roadmaps, and progress tracked over time
Operations & Supply ChainWhether readiness survives contact with day-to-day operationsMonitoring and alerting for expiry and weak ciphers, a rehearsed response to a compromised CA or broken algorithm, audit-ready exportable evidence, and CBOM requirements written into procurement

The dimensions are sequenced the way real migrations fail. Strategy without inventory produces plans that cannot start. Inventory without agility produces visibility into systems that cannot change. And everything before operations produces a readiness that decays the day the project team moves on.

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

How the Assessment Works

The assessment is a questionnaire, not a scanner. It asks what your organization knows and does rather than probing systems, so there is nothing to install, connect, or expose.

  1. Answer 20 quick questions across the five dimensions. The full pass takes about four minutes, and anyone close to the security or PKI program can complete it.
  2. See your scores on screen. Results display immediately across the five dimensions, benchmarked against the five-level maturity model.
  3. Get your personalized maturity report. Provide your name, business email, and company, and the full report with detailed recommendations is emailed to you. Your details are used to contact you about the assessment and are not shared.
  4. Act on your weakest dimension. The report turns the lowest-scoring dimension into tailored next steps, and a PQC advisory session can pick up exactly where the self-assessment stops.

Why Benchmark PQC Readiness Now

The migration deadlines are already published while most organizations still cannot produce a cryptographic inventory. NIST finalized the first post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), on August 13, 2024, so the algorithm question is settled. NIST IR 8547, the draft transition roadmap released in November 2024, proposes deprecating quantum-vulnerable public key algorithms, including RSA, ECDSA, and ECDH, after 2030 and disallowing them after 2035. CNSA 2.0 targets quantum-resistant software and firmware signing in national security systems from 2027, and NSM-10 targets a quantum-resistant US federal estate by 2035.

Two pressures make the benchmark personal rather than federal. First, harvest-now-decrypt-later: an adversary who records your encrypted traffic today decrypts it whenever quantum hardware matures, so any data that must stay confidential beyond roughly ten years is already in scope.

Second, operational compression: the CA/Browser Forum schedule cuts maximum TLS certificate validity to 200 days in March 2026, 100 days in March 2027, and 47 days in March 2029, which puts certificate automation on the same calendar as algorithm migration. A migration you cannot start is a migration you have not scoped, and scoping is exactly what a four-minute benchmark buys you.

What to Do With Your Results

Your weakest dimension is your starting point, and each dimension maps to a concrete follow-up.

If Cryptographic Inventory scored lowest, start discovery: automated cryptographic discovery with a CycloneDX-format inventory is what CBOM Secure builds. If Governance & Strategy or PQC Migration Planning scored lowest, the gap is strategic: Encryption Consulting’s PQC Advisory runs the quantum threat assessment and the phased roadmap aligned to the IR 8547 milestones. If Crypto-Agility & Technical scored lowest, review how hybrid certificates keep classical and post-quantum trust working side by side and how ML-DSA changes signing. If Operations & Supply Chain scored lowest, certificate expiry monitoring and lifecycle automation with CertSecure Manager closes the operational gaps first.

How Encryption Consulting Helps

The assessment tells you where you stand; PQC Advisory does the work that moves the maturity level. Encryption Consulting’s advisors run cryptographic discovery and inventory across on-premises, cloud, and SaaS environments, deliver a quantum threat assessment and readiness gap analysis, and build the phased migration roadmap aligned to the NIST standards and the IR 8547 milestones, with proof-of-concept validation before rollout. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

What is the PQC Readiness Assessment?

The PQC Readiness Assessment is a free, browser-based tool from Encryption Consulting. You answer 20 quick questions, and in about four minutes it benchmarks your organization against a five-level post-quantum and crypto-agility maturity model. Your scores appear on screen across five dimensions of readiness, and a personalized maturity report with detailed recommendations is emailed to you.

Is the PQC Readiness Assessment free?

Yes. Answering the questions and seeing your scores on screen costs nothing and requires no signup. To receive the full maturity report with detailed recommendations, you provide your name, business email, and company, and the report is emailed to you. Submitting means Encryption Consulting may contact you about your assessment; your details are not shared, and there is no obligation.

What are the five dimensions of PQC readiness?

The assessment benchmarks five dimensions: Governance & Strategy (ownership, sponsorship, and policy), Cryptographic Inventory (visibility into keys, certificates, and algorithms), Crypto-Agility & Technical (how easily algorithms can change), PQC Migration Planning (roadmap, priorities, and vendors), and Operations & Supply Chain (monitoring, incident response, audit evidence, and procurement). Together they cover the full distance from awareness to executed migration.

What are the 2030 and 2035 milestones?

They come from NIST IR 8547, the draft Transition to Post-Quantum Cryptography Standards released in November 2024. It proposes that quantum-vulnerable public key algorithms, including RSA, ECDSA, and ECDH, be deprecated after 2030 and disallowed after 2035. NSM-10 sets the same 2035 target for a quantum-resistant US federal estate, so migration roadmaps are commonly sequenced against those two dates.

How long does the assessment take, and do I need technical data?

About four minutes. The assessment is a questionnaire, not a scanner: it asks what your organization knows and does, so there is nothing to install, no systems to connect, and no sensitive data to upload. Anyone close to your security or PKI program can complete it, and teams often retake it quarterly to track how the maturity level moves.

What happens after I get my maturity level?

You see how each of the five dimensions scored, which makes your weakest dimension the obvious starting point, and the emailed report turns that into tailored next steps. From there you can close gaps and retake the assessment, or bring the report to an Encryption Consulting PQC advisor for cryptographic discovery, a quantum threat assessment, and a phased migration roadmap.

Benchmark Your Readiness Before the Deadlines Do

Take the free PQC Readiness Assessment to get your maturity level in four minutes, then plan your migration with an Encryption Consulting advisor when you are ready to move your weakest dimension. ISO 27001:2022 certified and SOC 2 attested.