Quantum Readiness Assessment

Know where quantum computing breaks your encryption, and what to fix first.

QuantumSmart finds the cryptography your organization depends on, scores how exposed each system is, and turns it into a migration roadmap built around the deadlines Canadian and international regulators have already set.

phases: discover, analyze, plan
3
phases: discover, analyze, plan
discovery questions across 13 domains
200
discovery questions across 13 domains
typical mid-size engagement
12 wks
typical mid-size engagement

The rule regulators plan around

X + Y > Z → act now

Mosca's theorem: X is how long your data must stay secret, Y is how long migration takes, and Z is how long until a quantum computer can break today's encryption. If X + Y is greater than Z, data you protect today will still matter when it can be read.

Y · time to migrate

e.g. 5 years

X · data must stay secret

e.g. 7 more years

Z · quantum window

regulators plan for 2030–2035

2026203020352040

In this example, data encrypted today stays sensitive well into the quantum window. Ciphertext harvested now could be read then.

The threat

The attack starts before the quantum computer exists.

Adversaries can record encrypted traffic and stolen data today and decrypt it once a cryptographically relevant quantum computer is available. This is called harvest now, decrypt later. Anything that must stay confidential for years (health records, intellectual property, M&A files, government data) is exposed now, not in 2030.

Broken

Public-key encryption & signatures

RSA, ECDSA, ECDH, Diffie-Hellman

Shor's algorithm on a large quantum computer recovers private keys. Used in TLS, VPNs, PKI, SSH, code signing and JWTs.

Use larger sizes

Symmetric encryption & hashing

AES, SHA-2, SHA-3

Grover's algorithm weakens them but does not break them. CNSA 2.0 specifies AES-256 and SHA-384 or larger.

Replacements

Post-quantum standards

ML-KEM, ML-DSA, SLH-DSA

NIST FIPS 203, 204 and 205, finalized in August 2024, replace vulnerable key exchange and signatures.

01

Which encrypted data, if read in 2032, would cause irreversible damage?

02

Do we know every system that uses RSA, ECC or Diffie-Hellman, and what replacing each would take?

03

Is a named executive accountable for quantum readiness, with a budget and board visibility?

If any answer is unclear, that is where an assessment starts.

How an assessment works

Three phases, from inventory to a roadmap your board can approve.

A QuantumSmart consultant leads the engagement on the QRA platform, so every finding traces back to evidence and every recommendation is reviewed by a person.

  1. 01

    Discovery

    What do you have?

    • Identify critical assets and data
    • Inventory cryptography in use
    • Map system and vendor dependencies
  2. 02

    Analysis

    What is at risk, and when?

    • Apply Mosca's theorem to each data lifecycle
    • Score risk per algorithm, asset and domain
    • Assess business and compliance impact
  3. 03

    Plan & Protect

    What do you do about it?

    • Prioritized 3–5 year roadmap
    • Hybrid and crypto-agile architecture
    • Key management, monitoring and response plans

A typical 12-week engagement

  1. Week 1–2

    Kickoff

    Stakeholder interviews, asset workshops

  2. Week 3–5

    Discovery

    Cryptographic inventory, dependency mapping

  3. Week 6–8

    Analysis

    Threat modelling, compliance mapping, Mosca timeline

  4. Week 9–10

    Plan & Protect

    Roadmap and hybrid deployment plan

  5. Week 11–12

    Delivery

    Final report and executive presentation

The QRA platform

One workspace from first connector to final report.

Each client engagement moves through the same gated stages: draft, discovery, analysis, review, delivered. Nothing reaches a report until a consultant has reviewed it.

1. Discover

Build the inventory

  • Connectors scan GitHub repositories and AWS accounts (KMS, ACM, IAM, S3, RDS, EC2)
  • Upload architecture documents and configs, or import a CycloneDX CBOM
  • 200-question discovery across 13 domains, drafted by AI from your evidence and accepted by a consultant
2. Analyze

Score the exposure

  • Mosca X/Y/Z timeline for every cryptographic use
  • Risk tiers rolled up from algorithm to asset to business domain, with indicative loss ranges
  • Findings cite the published text of NIST, CCCS, OSFI, UK NCSC and G7 documents, plus CISA and NVD feeds checked every 15 minutes
3. Plan

Sequence the migration

  • Roadmap across governance, discovery, crypto-agility and migration workstreams
  • Three horizons: 0–12 months, 12–36 months, 36+ months
  • Every AI-drafted finding and roadmap item is accepted, edited or rejected by a consultant
4. Deliver

Hand over the evidence

  • Executive and technical PDF reports carrying your logo, built only from reviewed findings
  • Cryptographic bill of materials (CycloneDX CBOM) export
  • An assistant that answers questions from the engagement's own data, with citations

Hosted in Canada

Runs in AWS Canada (Central). Your documents, inventory and search index are stored in Canada. AI drafting uses Claude on Amazon Bedrock; prompts may be processed outside Canada under peak load.

Role-based access

Viewer, consultant, admin and owner roles. Each firm only ever sees its own engagements.

Full audit trail

Who did what, and when: uploads, connector changes, finding reviews, report downloads. Kept even after an engagement is deleted.

Credentials stay sealed

Connector keys are held in AWS Secrets Manager and are never shown again once saved.

Regulatory deadlines

The dates are set, and the first one has already passed.

The assessment maps every finding and roadmap item to the frameworks that apply to you. For Canadian organizations, those start with CCCS and OSFI.

Canada

Canadian Centre for Cyber Security

ITSM.40.001, June 2025

  1. April 2026

    Federal departments deliver an initial PQC migration plan, then report progress every year

  2. End of 2031

    High-priority systems migrated

  3. End of 2035

    All remaining systems migrated

Canada

OSFI

Quantum readiness bulletin

  1. Now

    Five phases: awareness, inventory (including third parties), risk assessment and plan, transition, validation

  2. 2035

    Federally regulated financial institutions quantum-ready across all systems

Internationally

NIST
FIPS 203/204/205 finalized August 2024. IR 8547 (draft): quantum-vulnerable algorithms deprecated after 2030, disallowed after 2035.
UK NCSC
Discovery and initial plan by 2028, priority migrations by 2031, full migration by 2035.
G7 Cyber Expert Group
Financial sector target of 2035, with critical systems in the 2030–2032 window.

What you receive

Five deliverables, all backed by the evidence in the platform.

01

Quantum readiness score

A single, board-presentable measure of where you stand, broken down by domain.

02

Cryptographic asset register

A risk-ranked inventory of every algorithm, key and certificate found, exportable as a CBOM.

03

Quantum-safe roadmap

A 3–5 year migration plan, sequenced by risk and by regulatory deadline.

04

Compliance gap analysis

Where you stand against CCCS, OSFI, NIST and the other frameworks that apply to you.

05

90-day executive action plan

Named owners, milestones and a board communication template to start immediately.