
The algorithms are settled. NIST published ML-KEM, ML-DSA and SLH-DSA as federal standards in August 2024, and regulators across Asia-Pacific, Europe and North America have now set migration dates. What most organisations lack is not a technical answer but a way to govern a programme that will run for five to ten years and touch almost every system they own. This article treats post-quantum readiness as what it is for a regulated organisation: a GRC programme with a register, a risk method, indicators, control mappings and a calendar of external deadlines.
Start with a register, not a spreadsheet
Every guidance document starts in the same place: know where your cryptography is. Australia's ASD, Singapore's CSA, the UK NCSC and the US federal migration memo of June 2026 all put discovery first. The difference between a programme that works and one that stalls is whether that inventory is a living register or a one-off spreadsheet.
A useful cryptographic register holds, for each entry:
- the system or product, its owner and its business service;
- the algorithms, key sizes and protocols in use, and where they are implemented (library, appliance, HSM, cloud service or third party);
- the data protected and how long it must stay confidential;
- certificates and their expiry, and whether renewal is automated;
- vendor post-quantum roadmap status and the date it was last confirmed;
- the migration path: hybrid, direct replacement, retire, or cannot migrate.
The machine-readable format to aim for is a Cryptography Bill of Materials, added to CycloneDX in version 1.6 and standardised as ECMA-424. Automated discovery through software composition analysis and network scanning should feed the register, so that it changes when systems change.
Score risk with Mosca's inequality

Michele Mosca's inequality turns the quantum threat into something a risk register can hold. If the years your data must stay confidential, plus the years migration will take, are greater than the years until a cryptographically relevant quantum computer exists, the risk is already unacceptable, because data captured today will be readable before its confidentiality expires.
For the third term, the Global Risk Institute's March 2026 expert survey put the chance of such a machine within ten years at 28% to 49%. Many organisations pick a planning assumption of around 2032 to 2035 and record it, so that each system's score is reproducible and can be revisited as estimates change.
| Example system | Confidentiality needed | Migration time | Result |
|---|---|---|---|
| Customer identity and biometric store | 20 years | 4 years | Critical: migrate key establishment first |
| Payment switch TLS links | 7 years | 3 years | High: hybrid key exchange pilot now |
| Marketing website | Under 1 year | 1 year | Low: follow vendor defaults |
| Firmware signing for field devices | 15 years of device life | 5 years | High: plan signature migration and device replacement |
Six KRIs that show whether the programme is moving
- Inventory coverage: the share of in-scope systems with a complete register entry, and the share discovered automatically.
- Key establishment migrated: the share of critical systems using post-quantum or hybrid key exchange, the first target in most regulator timelines.
- Signatures migrated: the share of critical signing uses, including code, firmware, certificates and documents, on ML-DSA or SLH-DSA.
- Cannot-migrate backlog: the number of systems with no migration path, each with an owner and a replacement date.
- Vendor readiness: the share of critical vendors with a written, dated post-quantum roadmap.
- Certificate automation: the share of public and internal certificates renewed automatically, ahead of public TLS lifetimes falling to 200 days in March 2026, 100 days in March 2027 and 47 days in March 2029.
External maturity scores are a useful cross-check. Singapore's CSA Quantum Readiness Index scores ten objectives across five domains on a scale from L0 to L3, and the HKMA's Quantum Preparedness Index gave Hong Kong's banking sector 2.3 out of 10 in July 2026. Scoring yourself against the model your regulator uses is the fastest way to find the gaps it will find.
Map it to controls you already run
Post-quantum work does not need a new control framework. It extends controls you are already assessed against:
| Framework | Where post-quantum work lands |
|---|---|
| ISO/IEC 27001:2022 | Annex A 8.24 Use of cryptography: rules for cryptography and key management, extended to algorithm transition |
| Australian ISM | Cryptography controls, including those added in December 2024 that approve ML-KEM and ML-DSA parameter sets |
| NCA ECC-2:2024 | The cryptography subdomain and the national cryptographic standards it references |
| NZISM | The section on preparation for post-quantum cryptography, which asks agencies to inventory long-lived sensitive data |
| SOC 2 | Encryption-related criteria under logical access and data protection, where customers ask about transition plans |
Linking migration tasks to these controls means progress shows up in the assessments you already report, rather than in a separate programme status that the board sees once a year. See the ISO/IEC 27001, IRAP and ISM and NCA ECC framework pages.
Track the regulator calendar

| Date | Milestone |
|---|---|
| End of 2026 | ASD refined transition plan; EU national roadmaps; UAE government entity plans; MAS supervisory expectations expected |
| 1 January 2027 | US NSA CNSA 2.0: new national security system acquisitions must support quantum-resistant algorithms |
| 31 March 2027 | Singapore critical information infrastructure migration plans (CSA handbook) |
| End of 2028 | ASD: transition of critical systems started; UK discovery and initial plan complete |
| End of 2030 | ASD: stop using traditional asymmetric cryptography; EU high-risk use cases migrated; US federal key establishment target |
| 2030 to 2032 | G7 Cyber Expert Group window for migrating critical financial systems |
| End of 2031 | Singapore critical information infrastructure migration complete; UK highest-priority migrations |
| 2035 | UK, EU and US full migration; NIST's draft proposal to disallow today's quantum-vulnerable algorithms |
Several of these are guidance rather than law, and NIST IR 8547 is still a draft. Record the status of each date alongside it, so the board knows which are binding and which are supervisory expectations.
Governance that holds for ten years
The US federal memo of June 2026 is a useful template for accountability anywhere. It makes the CIO and CISO accountable for prioritisation and risk acceptance, asks the CFO to carry post-quantum needs into budget requests, and names a migration programme manager with system owners responsible for their own estates. It also lists the contents of a credible plan: prioritisation, phase milestones, inventory methods, a crypto-agile architecture, third-party coordination, funding and a risk strategy for the transition period.
In GRCLens, the cryptographic register can run as a configurable register linked to risks, controls and suppliers; the migration risks sit in the risk register with owners and treatment dates; vendor roadmaps are captured through supplier assessments; and the six indicators are tracked with thresholds so a stalled workstream turns amber before it turns into a missed deadline.
Frequently asked questions
What is a cryptographic inventory?
A register of where and how cryptography is used across systems, products and suppliers, including algorithms, keys, certificates and the data they protect. CycloneDX's Cryptography Bill of Materials is the emerging machine-readable format.
What is Mosca's inequality?
A way to decide whether quantum risk is already live: if data shelf life plus migration time exceeds the time until a capable quantum computer, data captured today will be exposed before it stops being sensitive.
Which ISO 27001 control covers post-quantum cryptography?
Annex A 8.24, Use of cryptography, which requires rules for effective use of cryptography and key management. Post-quantum transition extends those rules.
Are the 2030 and 2035 dates legally binding?
It depends on the jurisdiction and the sector. Many, including NIST IR 8547 and Singapore's CSA handbook, are guidance or drafts, while some government policies are mandatory for public entities. Record the status of each date in your plan.
How Security Solution Consultants can help
Security Solution Consultants runs post-quantum readiness assessments and migration planning for banks, payment providers and critical infrastructure operators across Australia, New Zealand, Singapore, Malaysia and the Gulf. For the executive roadmap and regulator expectations, read our post-quantum cryptography roadmap for APAC banks, or see our security compliance advisory. GRCLens then keeps the register, risks, supplier roadmaps and indicators current for the life of the programme. Request a demonstration.
Keep reading

Autonomous Fleets Meet Critical Infrastructure Law: SOCI, New Zealand and the Gulf
Once an autonomous fleet moves freight or carries the public at scale, its operator starts to look like a critical infrastructure operator. What the SOCI Act, New Zealand's proposed regime and the Gulf rules ask for, and how to evidence it.

Governing AI Agents Under ISO/IEC 42001: Registers, Impact Assessments and Evidence
ISO/IEC 42001 was published before most organisations ran AI agents, but its structure fits them well. How to extend an AI management system to agents: the register, the impact assessment trigger, the life cycle controls and the evidence.

Continuous Compliance: One Piece of Evidence for NCA ECC, ISO 27001 and SOC 2
Organisations that answer to the Saudi NCA, an ISO certification body and SOC 2 customers often collect the same access review three times. How evidence captured once really works, and the traps that make auditors reject reused evidence.