Quantum readiness checklist for CIOs and CISOs (2026)

Twenty items in four groups, each tied to a published framework, so you can see what your organization has done, what is missing and who should own it.

Security · Published September 23, 2026 · 7 min read

This checklist is for the CIO or CISO who has been asked “are we ready for quantum?” and needs an answer that holds up in an audit. It has 20 items in four groups. Each one points to a published framework, mainly the UK NCSC migration milestones, the US OMB memorandum M-26-15 and NIST’s standards, so you can report progress against dates other people recognize.

Few organizations will tick many boxes on a first pass. That is expected. The value is in knowing which items to do next and who owns them.

What frameworks does this quantum readiness checklist use?

It uses four public sources that agree on the order of work even when their dates differ. You don’t have to be a US agency or a UK company to borrow their structure.

Framework Who publishes it Phases or milestones Binding for
OMB M-26-15 (24 June 2026) US Office of Management and Budget Phase 1 strategy, planning and discovery (2026 to 2027); Phase 2 pilots and early migration (2027 to 2028); Phase 3 prioritized migration of key establishment (2028 to 2030); Phase 4 signature migration (2031); Phase 5 full migration (2035) US federal agencies, excluding national security systems
NCSC PQC migration timelines (20 March 2025) UK National Cyber Security Centre Discovery and initial plan by 2028; priority migrations by 2031; all systems by 2035 Advisory, aimed at large organizations and critical infrastructure
NIST FIPS 203, 204, 205 (13 August 2024) and draft IR 8547 (November 2024) US National Institute of Standards and Technology Standards for ML-KEM, ML-DSA and SLH-DSA; proposed deprecation of RSA and elliptic-curve algorithms at 112-bit security after 2030 and disallowance after 2035 Standards used worldwide by vendors
G7 Cyber Expert Group roadmap (January 2026) G7 finance ministries and central banks Six phases from awareness to validation; 2035 overall target, critical systems around 2030 to 2032 Non-binding, financial sector

Companies outside the US and UK feel these dates through their suppliers. Google set 2029 for its own migration on 25 March 2026, and CISA published in January 2026 a list of product categories where post-quantum options are already widely available. Our post-quantum migration deadlines article has the full calendar.

Governance and ownership (items 1 to 5)

Governance comes first because every later item needs an owner and a budget. M-26-15 is blunt about this: the migration “is not only the responsibility” of the CIO and CISO, and roles must be clearly defined.

# Checklist item Owner Maps to
1 A named executive sponsor and a PQC migration program lead, with written responsibilities CIO and CISO M-26-15 Appendix B roles; G7 phase 1
2 Quantum risk recorded in the enterprise risk register, with a stated risk appetite CISO and risk M-26-15 Phase 1; G7 governance line of effort
3 A board or executive committee briefing in the last 12 months CIO G7 phase 1 (executive-level awareness)
4 A budget line for discovery and planning in the current fiscal year CIO and CFO M-26-15 plan requirement: funding and personnel estimate
5 Security architects and application owners trained on why RSA and elliptic-curve cryptography are at risk CISO M-26-15 Phase 1 (awareness and training)

Discovery and inventory (items 6 to 10)

You cannot migrate what you haven’t found. This group matches the NCSC’s 2028 discovery milestone and Phase 1 of M-26-15, which lasts through 2027.

# Checklist item Owner Maps to
6 A cryptographic inventory (CBOM) covering TLS and VPN endpoints, PKI, code signing, HSMs, databases and backups CISO NCSC 2028 discovery; M-26-15 Phase 1
7 Automated discovery in place: code scanning, software composition analysis and network scans feeding the inventory CISO M-26-15 Appendix A (automated cryptographic inventory)
8 Each system tagged with how long its data must stay confidential (for example, “still sensitive in 2030 or later”) Data owners M-26-15 prioritization criteria; harvest now, decrypt later risk
9 Third-party and SaaS dependencies listed, with the cryptography each one controls Procurement and CISO G7 phase 2; M-26-15 third-party coordination plan
10 Legacy systems that cannot support post-quantum or hybrid algorithms identified and flagged for replacement CIO M-26-15 system modernization

Item 8 is the one teams skip, and it decides your priorities. Data that must stay secret for ten years is already exposed to harvest now, decrypt later collection. Our guide to building a cryptographic inventory covers items 6, 7 and 9 step by step.

Planning and procurement (items 11 to 15)

This group turns the inventory into a dated plan and stops new vulnerable purchases. It matches the “initial plan” part of the NCSC 2028 milestone and the plan requirements in M-26-15, which federal agencies must submit within 120 days of 24 June 2026, that is, by late October 2026.

# Checklist item Owner Maps to
11 A risk-ranked migration plan with milestones, reviewed at least once a year Program lead NCSC 2028 initial plan; M-26-15 plan submission
12 Post-quantum and crypto-agility clauses in new contracts and RFPs Procurement M-26-15 vendor requirements; CISA product categories list
13 Written roadmaps from your top vendors (cloud, HSM, PKI, core platforms) with PQC dates CIO G7 note on vendor transparency; NCSC
14 A target algorithm set: ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) or SLH-DSA (FIPS 205) for signatures Security architecture NIST FIPS 203, 204, 205; M-26-15 Appendix A
15 A documented decision on hybrid schemes (classical plus post-quantum), system by system Security architecture M-26-15 Appendix A (hybrid architecture); NIST IR 8547

On item 15, M-26-15 calls hybrid architecture a useful tool for managing risk during migration but also “an intricate and resource-intensive stopgap”. Hybrid key exchange for TLS is already the default in major browsers. Hybrid signatures are harder, so decide per system rather than by policy.

Technical readiness and testing (items 16 to 20)

These are the items that prove you can change cryptography in production. They correspond to M-26-15 Phases 2 and 3 and the NCSC 2031 milestone for priority migrations.

# Checklist item Owner Maps to
16 TLS 1.3 supported on external and internal services, with a date for the rest Infrastructure M-26-15 (federal deadline 2 January 2030)
17 Crypto-agility built in: algorithms set in configuration, not hardcoded, and modern libraries with pluggable providers Engineering NIST CSWP 39; M-26-15 Appendix A
18 HSMs and key management systems able to generate and store post-quantum keys, or a replacement plan CISO M-26-15 Appendix A (agile key management)
19 At least one pilot migration completed on a non-critical system, with lessons written down Program lead M-26-15 Phase 2 (2027 to 2028); G7 phases 4 and 5
20 A dashboard that tracks migration progress against the plan and reports to leadership Program lead M-26-15 automated compliance and monitoring; G7 phase 6

How should you score the checklist?

Give each item 0 (not started), 1 (in progress) or 2 (done and evidenced), for a maximum of 40. The total matters less than the pattern. A high score in technical items with zeros in governance usually means an enthusiastic engineering team without a budget, and that kind of effort tends to stall. Zeros in items 6 to 10 mean every date in your plan is a guess.

As a rough guide, if items 1, 2, 6 and 8 are not at least in progress by the end of 2026, you will struggle to meet the NCSC’s 2028 discovery milestone, and your large suppliers, who are aiming at 2029, will finish before you.

What changed in the 2026 edition?

Three things moved in 2026. OMB M-26-15 turned the US federal migration into five dated phases and added a TLS 1.3 deadline. The G7 published a financial-sector roadmap that treats 2030 to 2032 as the window for critical systems. And large vendors shortened their own targets: Google set 2029 in March and Microsoft moved its program target to 2029 in June. For a Latin American bank, insurer or government agency, none of these is law, but all of them will reach you through contracts and the products you buy.

Where to start this quarter

If you can only do three things before the end of 2026, do items 1, 6 and 8: an owner, an inventory, and a view of which data has to stay secret longest. The quantum readiness assessment covers those three in four to six weeks and gives you a dated plan. When the plan is ready, the post-quantum cryptography migration service handles items 11 to 20. Teams in regulated sectors can also check the specific pressures in banking and finance and government and the public sector.

Sources

  1. OMB, M-26-15 Execution of the Migration to Post-Quantum Cryptography, 24 June 2026
  2. UK NCSC, Timelines for migration to post-quantum cryptography, 20 March 2025
  3. NIST, Post-quantum cryptography FIPS approved (FIPS 203, 204, 205), August 2024
  4. NIST, IR 8547 initial public draft, Transition to Post-Quantum Cryptography Standards, 12 November 2024
  5. NIST, CSWP 39 Considerations for Achieving Cryptographic Agility
  6. CISA, Product categories for technologies that use post-quantum cryptography standards, 23 January 2026
  7. G7 Cyber Expert Group, PQC roadmap statement for the financial sector, January 2026
  8. Google, Our timeline for post-quantum cryptography migration, 25 March 2026

Questions we get about this

What is a quantum readiness checklist?

It is a list of the governance, inventory, planning and technical steps an organization needs to move from today's public-key cryptography to post-quantum algorithms. A good one maps each step to a published framework, such as the UK NCSC milestones or the US OMB M-26-15 phases, so progress can be reported against recognized dates.

Who should own quantum readiness, the CIO or the CISO?

Both, with a named program lead under them. OMB M-26-15 makes the CIO and CISO accountable for prioritization, risk acceptance and resources, and it says explicitly that the migration is not only their responsibility. Application owners, procurement and finance each have a role.

What should a company do first to prepare for quantum computing?

Name an owner and build a cryptographic inventory. Every major framework puts both near the start. The UK NCSC asks organizations to finish discovery and an initial plan by 2028, and OMB M-26-15 puts inventory in its first phase, covering 2026 to 2027.

Do these deadlines apply to companies in Latin America?

Not directly. OMB M-26-15 binds US federal agencies and the NCSC guidance is advisory. But Latin American companies inherit the dates through US and European customers, cloud providers, card networks and parent companies, and NIST's draft plan to deprecate RSA and elliptic-curve algorithms after 2030 will shape the products they buy.

Keep reading

Get in before the queue forms

We are taking a short list of companies for our first readiness assessments and post-quantum migrations. Tell us what you are working on and we will get back to you within two business days.

Write to us