The Protiviti View  | Insights From Our Experts on Trends, Risks and Opportunities

The Protiviti View

Insights From Our Experts on Trends, Risks and Opportunities
Search

POST

4 mins to read

Three Practical Steps to Prepare for Post-Quantum Cryptography Without Launching a Major Program

Scott Laliberte

Managing Director, CISO Solutions

Views
Larger Font
4 minutes to read

Many organizations still view post-quantum cryptography (PQC) as a future problem. After all, large-scale quantum computers capable of breaking today’s widely used encryption standards have not yet arrived.

The challenge is that preparing for PQC will take significantly longer than many leaders realize.

Every application, certificate, cryptographic library, third-party platform and vendor relationship that relies on public-key cryptography will eventually need to be evaluated. For large enterprises, that effort could span years. Organizations waiting for certainty around quantum timelines may discover they have waited too long. As discussed in Protiviti’s article, “Preparing for Q-Day: What Organizations Need to Know Now,” the focus should be on understanding where cryptography exists across the enterprise before migration deadlines become urgent.

That concern is no longer theoretical. The National Institute of Standards and Technology (NIST) has already finalized its first PQC standards and is encouraging organizations to begin migration planning now. NIST guidance emphasizes identifying vulnerable cryptographic implementations and developing transition plans before a cryptographically relevant quantum computer (CRQC) becomes a reality.

The good news is that organizations do not need to launch a multimillion-dollar quantum program tomorrow. Several practical steps can be taken today with relatively little effort and significant long-term benefit.

1. Start Embedding PQC Requirements Into Contracts

One of the easiest and most valuable actions organizations can take is incorporating PQC readiness requirements into new and renewed contracts. As Protiviti recently noted in “Quantum Readiness Is Becoming a Contract Requirement — Not a Future Technology Discussion,” quantum readiness expectations are increasingly moving from policy discussions into procurement requirements, supplier assessments and contract language.

Most technology service agreements, software licensing arrangements, cloud contracts and outsourcing agreements remain in force for three to five years. Many contracts negotiated today will still be active when quantum-related cryptographic modernization becomes an urgent operational requirement.

If quantum readiness expectations are absent from these agreements, organizations may find themselves facing expensive renegotiations, change orders and support disputes precisely when rapid action is needed.

Instead, organizations should begin incorporating language that addresses:

  • Cryptographic agility requirements
  • Future support for NIST-approved PQC algorithms
  • Vendor cryptography roadmaps
  • Responsibilities for future cryptographic modernization
  • Maintenance and support obligations associated with PQC migration

This is not about requiring vendors to deploy PQC today.

It is about ensuring both parties agree to cooperate in good faith, adapt to evolving security demands, and treat cryptographic modernization and agility as an ongoing operational responsibility. Clear contract language around collaboration, technology upgrades and regulatory alignment now can help prevent significant cost, complexity and delay later.

2. Put a PQC Lens on Existing Certificate Management Initiatives

With SSL/TLS certificate validity periods set to shrink to 47 days by 2029, certificate management modernization is becoming a near-term operational priority — much like Q-Day is for PQC. Organizations that still rely on manual discovery, tracking and renewal processes should use this deadline to accelerate automation, visibility and governance.

Shrinking certificate validity periods are forcing security and infrastructure teams to improve certificate discovery, inventory management, lifecycle automation and governance. Manual certificate management is becoming increasingly difficult to sustain.

Fortunately, the foundational work required for effective certificate management closely mirrors the work required for PQC preparation.

Both initiatives depend on:

  • Certificate inventories
  • Discovery of cryptographic dependencies
  • Identification of critical systems
  • Technology lifecycle planning
  • Automation strategies
  • Governance and ownership models

Rather than treating PQC as a separate future project, organizations can expand ongoing certificate modernization initiatives to include:

  • Identification of quantum-vulnerable cryptography
  • Mapping of cryptographic dependencies
  • Prioritization of critical migration targets
  • Evaluation of future PQC certificate requirements

This approach aligns with guidance from both NIST and CISA, which emphasize cryptographic inventory and visibility as foundational elements of a successful PQC migration strategy. Organizations cannot effectively migrate cryptography they have not identified.

Security leaders rarely get the opportunity to address two future challenges through a single funded initiative. This is one of those opportunities.

3. Build Cryptographic Agility Into Today’s Applications

Perhaps the most overlooked preparation activity is improving cryptographic agility within software development.

Many applications being developed today will remain in use through 2030 and beyond. Yet development teams frequently hard-code cryptographic algorithms and implementations directly into applications, creating long-term migration challenges.

The risk is simple: today’s design decisions can become tomorrow’s migration obstacles.

Even after PQC adoption accelerates, standards and implementation approaches will continue to evolve. New algorithms will emerge. Existing approaches will mature. Some may ultimately be replaced.

Organizations that tightly couple applications to specific cryptographic implementations will have far less flexibility when change becomes necessary.

Cryptographic agility helps address this challenge by enabling algorithms to be updated or replaced without significant application redesign.

Practical steps include:

  • Avoiding hard-coded algorithm dependencies
  • Abstracting cryptographic functions wherever possible
  • Centralizing cryptographic services
  • Supporting flexible algorithm selection
  • Incorporating crypto-agility requirements into software development standards

This philosophy is increasingly reflected in industry migration guidance. NIST’s migration initiatives and related guidance emphasize the importance of crypto agility as organizations prepare for ongoing cryptographic evolution.

Organizations that invest in cryptographic agility today will be better positioned to adapt as standards, technologies and requirements continue to evolve. Protiviti’s Post-Quantum Cryptography Assessment provides a framework for evaluating cryptographic exposure, crypto agility and migration readiness.

Don’t Wait for Q-Day

These recommendations are intentionally pragmatic: They require no dedicated quantum team, major restructuring or significant capital investment — just practical steps taken before the Q-Day timeline compresses.

Yet together they provide a meaningful head start:

  • Update contracts to address future cryptographic expectations.
  • Expand certificate management initiatives to support PQC readiness.
  • Build cryptographic agility into software development practices.

These actions should not be viewed as a complete PQC strategy. Rather, they represent foundational preparations that reduce future risk and complexity.

Post-quantum cryptography will likely become one of the largest cybersecurity and technology transitions organizations face over the coming decade. Encryption underpins nearly every aspect of digital business, from cloud services and customer transactions to software integrity and digital trust.

The challenge is not predicting exactly when quantum disruption arrives.

The challenge is reducing the amount of work required when it does.

Organizations that begin building cryptographic inventories, improving crypto agility and aligning vendors today will be in a far stronger position regardless of whether the transition accelerates in three years, five years or longer.

The objective is not to predict the future.

The objective is to be ready for it.

Organizations seeking to assess their PQC readiness should begin by understanding where cryptography exists across their environment, evaluating crypto agility, updating contracts and developing a practical migration roadmap. Protiviti’s Quantum Computing Services team can help organizations assess risk and prepare for the transition to post-quantum cryptography.

Was this post helpful to you?

Thanks for your feedback!

Subscribe to the Tech Insights Blog

Stay on top of the latest technology trends to keep your business ahead of the pack.

In this Post

Authors

Scott Laliberte

By Scott Laliberte

Verified Expert at Protiviti

Scott Laliberte, Managing Director, CISO Solutions – Consumer Products & Services, enables clients to...

EXPERTISE

No noise.
Just insights.

Subscribe now

Related posts