FREE WHITEPAPER

Post-quantum readiness: a 2030 plan for regulated enterprises

A quarter-by-quarter method to inventory, prioritise and migrate your cryptography before the 2030 deadlines, with the four readiness metrics a board can read without a cryptographer in the room.

16
quarters, one deliverable each
4
board-level readiness metrics
2030
ANSSI, BSI and NIST horizon
WHITEPAPER
Post-quantum
readiness:
A 2030 plan

Get the whitepaper

The PDF lands in your inbox within a minute, in the language of your choice.

Why 2030

Two clocks are running, and neither waits for a working quantum computer.

The algorithms are standardised. The deadlines are published. What is not settled, in most organisations, is far more basic: nobody knows where the vulnerable cryptography is, what depends on it, or who owns it.

The regulatory clock

ANSSI, BSI and NIST converge on 2030 for the start of mandatory migration. NIS2 and DORA already make management bodies accountable for cryptographic risk.

The data clock

Anything encrypted today and worth keeping for ten years is already exposed to harvest-now, decrypt-later. The lifetime of the data sets the deadline, not the hardware.

The inventory gap

You cannot migrate what you do not know you run. The whitepaper spends its first year on this one problem, because every later phase depends on it.

Inside

Sixteen quarters, four phases, one checkable deliverable per quarter.

Written for an enterprise starting in Q1 2027. Shift it if you start earlier or later, but keep the order.

2027 · PHASE 1

Inventory

Declare scope, read what runs, merge every source into one governed record per asset with a named owner. Blind spots listed, not hidden.

2028 · PHASE 2

Prioritise

Not everything needs to move first. Weight each asset by data lifetime, exposure and dependencies, then grade it against your own policy.

2029 · PHASE 3

Migrate

Hybrid first, verified in production, one critical system at a time. A fix counts when it is re-observed live, not when the ticket closes.

2030 · PHASE 4

Prove

Four metrics on one page, for the board and the supervisor alike: coverage, quantum exposure, agility, trajectory. Archived every quarter.

Sample page

Four readiness metrics a board can read without a cryptographer in the room.

Boards do not need lattices. They need one page: how exposed are we, is it improving, how fast, what residual risk are we accepting. The same page goes to the regulator.

Coverage: share of declared scope with a governed record
Quantum exposure: RSA/ECC-only assets, weighted by data lifetime
Agility: critical systems swappable by configuration
Trajectory: exposure change versus plan, quarter on quarter
Post-quantum readiness · board view · Q4 2028
NIS2 · DORA
1 · COVERAGE
91%
2 · QUANTUM EXPOSURE
64%
3 · AGILITY
38%
4 · TRAJECTORY
−9 pts
On plan · target −8 / quarter
Quantum exposure · vs plan to 2030
Q1 2027Q4 2028Q4 2029
Who it's for

Written for the people who own the plan.

CISOs and CIOs

A plan with a quarter on every line, and one page of metrics to take to the board and the budget committee.

Security architects

The sequencing: what to inventory first, how to weight exposure, when hybrid is enough and when it is not.

GRC and compliance

How NIS2 Article 20 and DORA Article 5 turn the migration into a governance obligation, and what evidence satisfies the supervisor.

Sixteen quarters. Start with the inventory.

Download the whitepaper in English or French, then put the first deliverable on next quarter's agenda.