Most companies are in the same spot right now. Someone on the board read about quantum computing. Someone in security heard that it breaks encryption. Nobody knows whether this is a 2027 problem or a 2040 problem, or what it would cost to find out. The experts don’t agree either: in the Global Risk Institute’s Quantum Threat Timeline Report 2025, published in March 2026, 26 specialists put the chance of a cryptographically relevant quantum computer within 10 years at 28 to 49 percent.
A readiness assessment answers that question for your company specifically. It takes a few weeks, and at the end you know which parts of quantum you can ignore for now, which ones to watch, and which ones need a budget line this year.
Why assess quantum readiness before the machines are ready?
A quantum readiness assessment is worth doing now because one risk does not wait for the hardware. Attackers can record encrypted traffic today and decrypt it once a large quantum computer exists, and replacing cryptography across a company takes years. Starting the inventory early keeps both problems manageable.
When a quantum computer large enough to run Shor’s algorithm exists, anything protected by RSA or elliptic-curve keys can be decrypted after the fact. Security people call this “harvest now, decrypt later,” and the Federal Reserve Board examined it in a September 2025 working paper (FEDS 2025-093). If your data has to stay confidential for ten years (medical records, contracts, customer financial data, trade secrets), the clock started already.
The other reason is that migrations are slow, and the dates are set. NIST published its first post-quantum standards in August 2024, and its draft IR 8547 (November 2024) proposes deprecating RSA and elliptic-curve algorithms after 2030 and disallowing them after 2035. Replacing cryptography touches libraries, hardware security modules, certificates, vendor contracts and embedded devices that nobody has updated in years. Large organizations that did the SHA-1 to SHA-2 migration remember how long it dragged on. The post-quantum move is bigger.
What does a quantum readiness assessment cover?
A quantum readiness assessment covers four areas: where your systems use public-key cryptography that a quantum computer could break, which business problems might benefit from quantum methods, which people on your team could grow into the work, and the outside signals that should trigger each next step on your roadmap.
Cryptographic exposure
We build an inventory of where your systems use public-key cryptography: TLS endpoints, VPNs, code signing, databases, backups, PKI, APIs to partners, and the vendor products you can’t change yourself. Then we rank each item by two numbers: how long the data it protects must stay secret, and how hard it will be to replace. Starting with the inventory is also what CISA, NSA and NIST recommend in their joint Quantum-Readiness factsheet from August 2023.
This is not a full migration. It is enough to show where the real exposure is and what a migration would involve. If you decide to go ahead, the post-quantum cryptography migration picks up from here.
Business problems
We go through your operations with the people who run them and look for problems with the shapes quantum algorithms are good at: large combinatorial optimization (routing, scheduling, portfolio construction), simulation of molecules and materials, and some sampling and machine learning tasks.
Most of what we find will not be a quantum problem, and we say so. A good classical solver or a better data pipeline will often do more for you this year than any quantum experiment. The point is to know which two or three problems are worth tracking as the hardware improves.
People and skills
We map who on your team could grow into quantum work: engineers with linear algebra, people who already write optimization code, security staff who will run the cryptographic migration. This shapes the training plan if you want one.
Signals and timing
The roadmap you get is tied to external signals, not to guesses. Examples: a cloud provider offering logical qubits with error rates below a set threshold, your main bank or cloud vendor announcing post-quantum TLS by default, or a regulator in your country publishing a transition deadline. Each signal maps to an action you already agreed on.
What happens during a quantum readiness assessment?
A quantum readiness assessment for a mid-sized company runs in four stages over about six weeks: a kickoff to set scope, three weeks of inventory and interviews, a shorter stretch of analysis to rank risks and opportunities, and a readout where leadership receives the written report and the dated roadmap.
| Stage | Weeks | What happens | What you get |
|---|---|---|---|
| Kickoff | Week 1 | We agree on scope, meet the people who own your key systems and collect architecture documents | Agreed scope and interview list |
| Inventory and interviews | Weeks 2 to 4 | Cryptographic discovery, including automated scans where you allow them, and short interviews with business owners | Draft exposure list and candidate problems |
| Analysis | Weeks 4 to 5 | We rank risks and opportunities and draft the roadmap | Ranked risks and a draft roadmap |
| Readout | Week 6 | A working session with leadership and the technical team | Written report, dated roadmap and a 60-minute readout |
Everything is delivered in Spanish or English, whichever your team prefers. If your team mixes both languages, so can the meetings.
Which companies need a quantum readiness assessment?
The companies that need a quantum readiness assessment most are those holding data that must stay confidential for many years, such as banks, insurers, health providers, telecom operators and public agencies. Smaller firms can benefit too, with a lighter and cheaper version, especially before vendors start selling them quantum-safe products they may not need.
The usual trigger is a security team that already feels stretched and a leadership team that wants a grounded answer before signing anything labeled “quantum-safe.”
If you are not sure you need this, write to us and describe your situation. Sometimes the honest answer is that a two-hour conversation covers it.
Sources
- NIST CSRC, Post-quantum cryptography FIPS approved (FIPS 203, 204, 205), August 13, 2024
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
- Federal Reserve Board, FEDS 2025-093, Harvest Now Decrypt Later: Examining Post-Quantum Cryptography and the Data Privacy Risks for Distributed Ledger Networks, September 2025
- CISA, NSA and NIST, Quantum-Readiness: Migration to Post-Quantum Cryptography, August 21, 2023
- Global Risk Institute, Quantum Threat Timeline Report 2025, March 9, 2026