Quantum Readiness Assessment
QuantumSmart finds the cryptography your organization depends on, scores how exposed each system is, and turns it into a migration roadmap built around the deadlines Canadian and international regulators have already set.
The rule regulators plan around
X + Y > Z → act now
Mosca's theorem: X is how long your data must stay secret, Y is how long migration takes, and Z is how long until a quantum computer can break today's encryption. If X + Y is greater than Z, data you protect today will still matter when it can be read.
Y · time to migrate
e.g. 5 years
X · data must stay secret
e.g. 7 more years
Z · quantum window
regulators plan for 2030–2035
In this example, data encrypted today stays sensitive well into the quantum window. Ciphertext harvested now could be read then.
The threat
Adversaries can record encrypted traffic and stolen data today and decrypt it once a cryptographically relevant quantum computer is available. This is called harvest now, decrypt later. Anything that must stay confidential for years (health records, intellectual property, M&A files, government data) is exposed now, not in 2030.
RSA, ECDSA, ECDH, Diffie-Hellman
Shor's algorithm on a large quantum computer recovers private keys. Used in TLS, VPNs, PKI, SSH, code signing and JWTs.
AES, SHA-2, SHA-3
Grover's algorithm weakens them but does not break them. CNSA 2.0 specifies AES-256 and SHA-384 or larger.
ML-KEM, ML-DSA, SLH-DSA
NIST FIPS 203, 204 and 205, finalized in August 2024, replace vulnerable key exchange and signatures.
Which encrypted data, if read in 2032, would cause irreversible damage?
Do we know every system that uses RSA, ECC or Diffie-Hellman, and what replacing each would take?
Is a named executive accountable for quantum readiness, with a budget and board visibility?
If any answer is unclear, that is where an assessment starts.
How an assessment works
A QuantumSmart consultant leads the engagement on the QRA platform, so every finding traces back to evidence and every recommendation is reviewed by a person.
01
What do you have?
02
What is at risk, and when?
03
What do you do about it?
Week 1–2
Kickoff
Stakeholder interviews, asset workshops
Week 3–5
Discovery
Cryptographic inventory, dependency mapping
Week 6–8
Analysis
Threat modelling, compliance mapping, Mosca timeline
Week 9–10
Plan & Protect
Roadmap and hybrid deployment plan
Week 11–12
Delivery
Final report and executive presentation
The QRA platform
Each client engagement moves through the same gated stages: draft, discovery, analysis, review, delivered. Nothing reaches a report until a consultant has reviewed it.
Hosted in Canada
Runs in AWS Canada (Central). Your documents, inventory and search index are stored in Canada. AI drafting uses Claude on Amazon Bedrock; prompts may be processed outside Canada under peak load.
Role-based access
Viewer, consultant, admin and owner roles. Each firm only ever sees its own engagements.
Full audit trail
Who did what, and when: uploads, connector changes, finding reviews, report downloads. Kept even after an engagement is deleted.
Credentials stay sealed
Connector keys are held in AWS Secrets Manager and are never shown again once saved.
Regulatory deadlines
The assessment maps every finding and roadmap item to the frameworks that apply to you. For Canadian organizations, those start with CCCS and OSFI.
Canada
ITSM.40.001, June 2025
April 2026
Federal departments deliver an initial PQC migration plan, then report progress every year
End of 2031
High-priority systems migrated
End of 2035
All remaining systems migrated
Canada
Quantum readiness bulletin
Now
Five phases: awareness, inventory (including third parties), risk assessment and plan, transition, validation
2035
Federally regulated financial institutions quantum-ready across all systems
What you receive
A single, board-presentable measure of where you stand, broken down by domain.
A risk-ranked inventory of every algorithm, key and certificate found, exportable as a CBOM.
A 3–5 year migration plan, sequenced by risk and by regulatory deadline.
Where you stand against CCCS, OSFI, NIST and the other frameworks that apply to you.
Named owners, milestones and a board communication template to start immediately.