⚛ Quantum Security

Post-Quantum Cryptography Readiness Assessment

Score your organisation's exposure to quantum threats across 5 domains. Maps to NIST FIPS 203/204/205 and India regulatory context.

Why this matters now: NIST finalized three post-quantum cryptography standards in August 2024 — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). RSA, ECC, and Diffie-Hellman key exchange are all broken by a sufficiently powerful quantum computer. Nation-state adversaries are already capturing encrypted traffic today to decrypt later (Harvest Now, Decrypt Later). Migration takes 5-10 years. The planning window is now.
🔑
Domain 1: Cryptographic Inventory
Do you know what algorithms your organisation uses?
1. How complete is your organisation's inventory of cryptographic assets?
Cryptographic assets: TLS certificates, SSH keys, code-signing keys, VPN configs, PKI infrastructure, application-level encryption.
2. Do you use RSA or ECC for key exchange or digital signatures in production?
These algorithms are broken by Shor's algorithm on a large-scale quantum computer. Includes TLS certificates, SSH, VPN, code signing, JWT signing.
🗄️
Domain 2: Data Sensitivity & Longevity
How long does your data need to remain confidential?
3. How long does your most sensitive data need to remain confidential?
Harvest Now, Decrypt Later attacks capture today's encrypted traffic for future decryption. Data with a 5+ year sensitivity window is at risk right now.
4. Does your organisation transmit data that could be of strategic value to a nation-state adversary?
Nation-states are the primary actors conducting HNDL attacks. Defence, critical infrastructure, telecom, financial market operators, and government agencies are priority targets.
📜
Domain 3: PKI & Certificate Infrastructure
How quantum-resilient is your certificate chain?
5. What is your current TLS certificate configuration?
TLS 1.3 with ECDHE is vulnerable to quantum attacks on key exchange. Hybrid PQC (e.g. X25519Kyber768) runs classical + quantum-safe simultaneously.
6. Do you operate your own PKI or Certificate Authority?
Internal CAs issuing RSA/ECC certificates need to be migrated to PQC or hybrid CAs. This is a multi-year project for large PKI infrastructures.
🗺️
Domain 4: Awareness & Governance
Is quantum risk on your leadership's radar?
7. What is your CISO / security leadership's current awareness of post-quantum risk?
8. Have you assessed your third-party / supply chain quantum exposure?
Your vendors, cloud providers, and SaaS tools also use RSA/ECC. Even if you migrate, a vulnerable vendor link can expose your data.
⚙️
Domain 5: Technical Migration Readiness
Can your infrastructure support PQC algorithms?
9. Does your technology stack support NIST PQC standards (ML-KEM, ML-DSA, SLH-DSA)?
OpenSSL 3.5+ (April 2025), BoringSSL, AWS KMS, and Azure Key Vault now support ML-KEM. Java 24+ includes ML-KEM. Check your critical libraries.
10. How is your HSM (Hardware Security Module) / key management infrastructure positioned?
PQC key sizes are significantly larger than RSA/ECC. HSMs need firmware updates or replacement to handle ML-KEM and ML-DSA key operations.
-- / 30

⚡ Priority Actions

🇮🇳 Indian Regulatory Status — Post-Quantum

As of 2025, no Indian regulator has mandated PQC migration timelines. However, NIST standards being adopted globally will influence CERT-In, RBI, and SEBI guidance within 2-3 years. Organisations in regulated sectors should begin planning now.
CERT-In
Watching — no mandate yet
RBI
Monitoring NIST standards
SEBI CSCRF
No PQC requirement yet
DPDP Act
Encryption principle applies
MoD / Defence
DRDO QKD programme active
NQM
₹6,003 Cr — PQC in scope