When Marin Ivezic, CEO of Applied Quantum, led post-quantum cryptography migration programs with over 120,000 tasks, only 30,000 involved cryptography directly. The remaining 90,000 tasks dealt with inventory management, vendor coordination, regulatory reporting, and team upskilling.
This highlights a core issue: organizations aren't just swapping algorithms. They're restructuring how they manage cryptographic dependencies across systems handling sensitive data.
Key Findings
Governance gaps are more obstructive than technical complexity. Gregory Skulmoski, professor at Bond University, notes that organizations prioritize AI governance and zero trust hardening. This focus makes it hard to allocate resources to quantum threats, which seem distant. This delay could be risky as quantum computing advances.
Vendor management is a major untracked dependency. Your payment gateway, HSM provider, TLS termination service, and cloud key management service all need quantum-safe updates. Each vendor has its own timeline, requiring testing and updated contracts. Without a vendor quantum readiness scorecard, you're already behind.
Cryptographic discovery is ongoing, not a one-time audit. Every code deployment, new SaaS integration, and infrastructure change introduces new cryptographic dependencies. Muria Roberts, director at QTM-X Quantum Advisory Indonesia, emphasizes treating this as a cyber hygiene issue. Embed quantum-safe requirements into your change management process.
The scope is beyond your CISO's capacity alone. A migration program with 120,000 tasks spans procurement, legal, compliance, application development, infrastructure, and third-party risk management. This is an enterprise transformation needing executive sponsorship and cross-functional governance.
Your PCI DSS compliance program offers a template. You already manage cryptographic inventory for cardholder data environments. You track key management practices under PCI DSS 4.0 Requirements 3.6 and 3.7. Post-quantum migration extends that discipline across your entire estate, not just the CDE.
What This Means for Your Team
If you manage fraud detection, payment processing, or AML transaction monitoring, your systems rely on RSA and ECDSA for API authentication, TLS for data in transit, and symmetric encryption for data at rest. These dependencies aren't just in your application layer. They're in your HSMs, TLS terminators, database encryption, SFTP connections to correspondent banks, and vendor APIs.
When NIST finalizes its post-quantum cryptography standards, you won't just update a certificate. You'll need to:
- Identify every system performing cryptographic operations (discovery)
- Determine which algorithms each system uses and if quantum-safe alternatives exist (assessment)
- Test hybrid implementations running both classical and post-quantum algorithms (validation)
- Coordinate vendor upgrades across payment processors, core banking systems, and fraud detection platforms (orchestration)
- Update procurement requirements to mandate quantum-safe cryptography for new vendors (governance)
- Train your teams on new key sizes, performance implications, and failure modes (enablement)
This isn't a project. It's a multi-year program.
Action Items by Priority
Immediate (next 30 days):
Start cryptographic inventory in your highest-risk environments. Focus on systems handling long-lived secrets: key management infrastructure, certificate authority, encrypted backup archives, and authentication tokens with multi-year validity. Document algorithms, key sizes, and vendor dependencies. Aim for a defensible starting point.
Add post-quantum readiness questions to your vendor risk assessment process. Ask your payment gateway, HSM provider, and fraud detection platform vendor: What is your timeline for supporting NIST-approved post-quantum algorithms? Will the transition require hardware replacement or firmware updates? What testing support will you provide during hybrid operation? Include these answers in your vendor scorecard.
Next 90 days:
Assign executive ownership. This can't reside solely within your information security team. You need a program sponsor who can allocate budget across IT, procurement, legal, and compliance. Use the 120,000-task benchmark to justify the ask: this is larger than most ERP implementations.
Integrate post-quantum requirements into your existing governance frameworks. If implementing zero trust architecture, include post-quantum cryptography in your identity and access management roadmap. If updating AI governance policies, address cryptographic requirements for model integrity and data provenance. Embed it into initiatives with momentum and budget.
Next 12 months:
Build a vendor transition roadmap. Map every third-party service performing cryptographic operations. Prioritize based on data sensitivity and replacement complexity. Your core banking platform will take longer to migrate than your email gateway. Start conversations with high-complexity vendors now.
Establish a cryptographic hygiene baseline. Require all new code deployments to document cryptographic dependencies. Ensure all new vendor contracts include quantum-safe transition timelines. Make infrastructure changes trigger a cryptographic review. Integrate this into your change advisory board process, not as a separate approval gate.



