Quantum computing isn't a distant threat anymore. CISA and the G7 Cyber Security Working Group have issued a call to action urging organizations to transition to post-quantum cryptography (PQC) now. For defense contractors and public-sector teams, this isn't optional, it's a compliance imperative that will reshape how you protect Controlled Unclassified Information, maintain CMMC certification, and meet DFARS 252.204-7012 obligations.
This checklist helps you assess your organization's readiness for PQC integration and identify gaps before they become audit findings or contract barriers.
Prerequisites
Before starting this assessment, you'll need:
- Current cryptographic inventory: A complete list of where your organization uses encryption, data at rest, data in transit, authentication systems, digital signatures, and key management infrastructure.
- System boundary documentation: Your NIST SP 800-171 System Security Plan or FedRAMP authorization package showing which systems handle CUI or federal data.
- Procurement authority access: Input from whoever writes technical requirements into contracts and subcontracts.
- Vendor relationship map: Know which third parties provide cryptographic services or products to your organization.
If you don't have a cryptographic inventory, stop here. You can't transition to PQC if you don't know what you're transitioning from.
Readiness Checklist
1. Cryptographic Asset Discovery
Done when: You've documented every system, application, and device that uses cryptographic functions to protect CUI or federal data.
Include: VPNs, TLS/SSL certificates, encrypted storage volumes, authentication tokens, code signing certificates, and any FIPS 140-2 validated modules. Don't forget embedded cryptography in industrial control systems or IoT devices on your network.
What good looks like: A spreadsheet or asset management system listing each cryptographic implementation, the algorithm it uses (AES-256, RSA-2048, etc.), the system owner, and whether it's customer-facing or internal.
2. Quantum Vulnerability Assessment
Done when: You've identified which cryptographic algorithms in your inventory are quantum-vulnerable.
Focus on: Asymmetric algorithms (RSA, ECDSA, ECDH, DSA) used for key exchange, digital signatures, and authentication. Symmetric algorithms like AES-256 are less vulnerable but may need key length adjustments.
What good looks like: A risk-ranked list showing which systems use quantum-vulnerable algorithms, prioritized by the sensitivity of data they protect and the timeline for replacement.
3. Vendor Cryptographic Roadmap Review
Done when: You've contacted every vendor providing cryptographic products or services and obtained their PQC transition timeline.
Ask specifically: When will they support NIST-standardized PQC algorithms? What's their migration path? Will current hardware support the new algorithms, or will you need equipment replacement?
What good looks like: Written statements from each vendor with specific timelines, or documented escalation to procurement if a vendor can't commit to PQC support.
4. Procurement Language Update
Done when: Your standard contract templates and RFP language include PQC requirements.
Add clauses requiring: Vendor disclosure of cryptographic algorithms used, commitment to support NIST-standardized PQC algorithms within a defined timeframe, and notification requirements if they can't meet PQC transition deadlines.
What good looks like: Legal or procurement review confirming the language is enforceable, and new solicitations including these requirements by default.
5. Internal Awareness Campaign
Done when: Your technical staff, compliance team, and leadership understand what PQC is and why it matters to your organization's mission.
The G7 call to action lists raising awareness as the first priority for a reason, you can't execute a transition if your team doesn't understand the threat model.
What good looks like: Documented training sessions for system administrators and engineers, executive briefing materials showing how PQC affects contract eligibility, and updated security awareness content for general staff.
6. National Strategy Alignment Check
Done when: You've reviewed whether your organization's approach aligns with emerging federal PQC guidance.
Monitor: NIST's post-quantum cryptography standardization project, CISA's PQC guidance, and any DoD-specific implementation timelines. If you're a FedRAMP-authorized CSP, watch for updates to FIPS 140-2 requirements.
What good looks like: A documented process for tracking federal PQC policy updates, with assigned ownership for translating new requirements into your System Security Plan or CMMC implementation.
7. Public-Private Partnership Engagement
Done when: You've identified and engaged with industry groups, ISACs, or government programs focused on PQC transition.
The G7 specifically calls for fostering public-private partnerships to share expertise and resources. For DIB contractors, this might mean participating in NIST workshops, joining industry working groups through your trade association, or engaging with CISA's sector-specific resources.
What good looks like: Active membership or participation records in at least one forum where PQC implementation challenges are discussed, with documented takeaways applied to your transition planning.
8. System Security Plan PQC Addendum
Done when: Your SSP or authorization package includes a section addressing cryptographic agility and PQC transition planning.
Reference: NIST SP 800-53 Rev 5 control SC-12 (Cryptographic Key Establishment and Management) and SC-13 (Cryptographic Protection). Your plan should show how you'll update cryptographic implementations without disrupting authorized operations.
What good looks like: A documented cryptographic modernization plan that assessors can review during your next CMMC assessment or FedRAMP continuous monitoring cycle, showing you've considered quantum threats in your risk management approach.
9. Budget and Resource Allocation
Done when: You've estimated the cost of PQC transition and secured funding or included it in your next budget cycle.
Consider: Hardware replacement for devices that can't support new algorithms, software licensing for PQC-capable products, consulting or engineering time for implementation, and testing/validation costs.
What good looks like: A line-item budget or capital plan showing PQC transition costs, with executive approval or inclusion in your next fiscal year planning.
10. Testing Environment Establishment
Done when: You've set up a lab or test environment where you can evaluate PQC algorithms without affecting production systems.
Test: Performance impact, compatibility with existing infrastructure, and interoperability with partner systems. Some PQC algorithms have larger key sizes or different computational requirements than current standards.
What good looks like: A documented test plan showing which PQC algorithms you'll evaluate, success criteria, and a rollback plan if initial implementations cause issues.
Common Mistakes
Waiting for a mandate: By the time PQC becomes a contract requirement, you'll be behind. The G7 and CISA are issuing this call to action now because transition takes years.
Assuming your vendors will handle it: Many vendors won't prioritize PQC until customers demand it. If you don't ask, you won't get a roadmap.
Treating this as purely technical: PQC transition affects procurement, budgeting, contract flow-down requirements, and compliance attestations. It's a program management challenge, not just an IT project.
Ignoring cryptographic agility: The goal isn't just to swap algorithms once, it's to build systems that can adapt as cryptographic standards evolve. Design for replaceability.
Next Steps
Start with items 1 and 2. You can't make informed decisions about PQC transition until you know what cryptography you're using and where it's vulnerable.
Then tackle item 3. Vendor timelines will determine your critical path, if a key vendor can't support PQC on your required timeline, you need to know now so you can find alternatives.
Finally, integrate PQC planning into your existing compliance processes. If you're pursuing CMMC certification or maintaining a FedRAMP authorization, your assessor will eventually ask how you're addressing quantum threats. Having a documented plan in place now shows you're managing emerging risks proactively, not reactively.
The quantum threat timeline is uncertain, but the compliance timeline isn't. Organizations that treat PQC as a strategic priority today will have a significant advantage when it becomes a contract requirement tomorrow.



