Quantum computing may feel distant from day-to-day risk management, but the transition away from vulnerable cryptography is a present planning problem. Large organisations do not know every place cryptography is used, and critical protocols, devices, archives and supplier products can take years to replace.
Practical situation: A financial group begins a cryptographic inventory and discovers that long-lived customer records, payment interfaces, hardware devices and archived legal documents use different algorithms managed by dozens of vendors. Several systems cannot be upgraded without major replacement.
Quantum readiness should begin with visibility and prioritisation, not predictions about the exact arrival date of a capable quantum computer. ERM can govern the transition by identifying long-lived sensitive data, critical cryptographic dependencies, supplier roadmaps and migration lead times.
Why this belongs on the ERM agenda now#
Sensitive data may need protection for many years#
Information intercepted today may still be valuable in the future, creating concern about store-now-decrypt-later attacks for long-lived confidential data. This changes the risk conversation in a very concrete way. Management should be able to see what would trigger escalation, who can act and how quickly the organisation can change course.
Cryptography is deeply embedded#
Certificates, identity, payments, APIs, devices, backups, databases and signed software may use different algorithms and libraries that are not centrally inventoried. For risk teams, the implication is operational rather than theoretical. The test is whether the issue changes a real decision on resources, controls, suppliers, customers or strategy.
Migration depends on suppliers and interoperability#
An organisation cannot change one endpoint in isolation. Partners, market infrastructure, devices and vendors need compatible standards and coordinated testing. That matters because traditional controls often react after the exposure has already moved. The ERM response should therefore define an owner, a decision trigger and evidence showing whether the organisation’s approach to quantum readiness for ERM is improving or deteriorating.
What good looks like#
A strong approach to quantum readiness for ERM is visible in everyday decisions, not only in an annual workshop. Business owners understand the exposure, control owners know what they must operate and senior management can see when conditions move outside the agreed range. The design should remain proportionate: apply deeper evidence and testing where impact is material, while using lighter controls with clear review triggers for lower-risk activity. A useful starting expectation is: The organisation has a risk-based inventory of cryptographic use and ownership.
The target state has five practical characteristics:
-
The organisation has a risk-based inventory of cryptographic use and ownership.
-
Data is prioritised by sensitivity and required confidentiality period.
-
Critical systems and suppliers have migration and agility roadmaps.
-
New architecture and procurement require cryptographic agility.
-
Migration waves are tested for performance, interoperability and rollback.
A practical quantum-readiness roadmap#
1. Establish governance and risk ownership#
Design the step around the exception that management would need to understand quickly. Treat quantum-safe transition as a cross-enterprise programme involving security, architecture, data, procurement, operations, legal, risk and business owners. Define decision rights and reporting before launching technical discovery.
A reviewer should be able to find executive sponsor, programme owner, scope, risk statement, decision forums, funding approach and external dependencies. This allows challenge to focus on the quality of the decision rather than on reconstructing the history of quantum readiness for ERM.
2. Inventory cryptographic use#
Start by making the decision explicit. Start with critical services and sensitive data. Record algorithms, protocols, libraries, certificates, keys, devices, software, vendors and interfaces. Accept that the first inventory will be incomplete and create discovery processes.
The practical output is asset and service link, cryptographic function, algorithm, key length, owner, provider, upgrade path and unknown status. Clear evidence also makes it easier to distinguish a genuine change in quantum readiness for ERM from a change in wording or presentation.
3. Prioritise by data longevity and service impact#
Keep this step deliberately simple. Assess how long confidentiality or authenticity must be protected and how severe disruption would be during migration or cryptographic failure. Prioritise long-lived sensitive data and critical trust functions.
Do not close the step without data classification, protection horizon, service criticality, exposure window, substitutability and priority tier. The record should enable another qualified person to understand the decision, test it and continue the work without relying on personal memory.
4. Assess supplier and ecosystem readiness#
Treat this as an operating requirement, not a documentation exercise. Request provider roadmaps, supported algorithms, update dependencies and end-of-life dates. Identify products that cannot support change and external interfaces requiring coordinated migration.
The control record should show supplier response, contract commitment, product version, dependency, target date, unresolved gap and exit option. Recording those elements shows how the Assess supplier and ecosystem readiness step supports the wider approach to quantum readiness for ERM and gives the next reviewer a usable starting point.
5. Design for cryptographic agility#
The strongest programmes begin with a narrow, testable definition. New and changed systems should separate algorithms from business logic where possible, support versioning and allow controlled replacement. Avoid creating new hard-coded dependencies that extend migration.
The decision file should retain architecture standard, approved libraries, key management, configuration controls, compatibility and change-testing evidence. That evidence keeps the judgement on quantum readiness for ERM traceable when ownership, assumptions or operating conditions change.
6. Pilot migration waves#
This is where ownership becomes visible. Test post-quantum or hybrid approaches in controlled environments, including performance, message size, interoperability, certificate handling, operational support and rollback. Use results to refine sequencing and funding.
Minimum evidence should include pilot scope, test results, exceptions, capacity impact, partner coordination, rollback and lessons applied to the roadmap. The result should be reusable in monitoring and reporting, not a one-off document that disappears after the Pilot migration waves step is complete.
Ownership and decision rights#
Effective governance of quantum readiness for ERM requires more than a name in the risk register. The operating chain should connect the business decision, the controls and data used to support it, independent challenge and the forum that can accept or change the exposure. Five responsibilities deserve explicit treatment.
- Executive sponsor: owns the outcome and approves trade-offs that exceed a function’s authority. The sponsor should understand how quantum readiness for ERM affects the wider Operational and Technology Resilience agenda and what delay would mean for customers, services, strategy or legal entities.
- First-line owner: runs the activity that creates or manages the exposure. This person should lead the work to establish governance and risk ownership, keep the conclusion current and translate it into operating choices.
- Control and data owners: operate the controls and produce the evidence behind measures such as Critical services with cryptographic inventory coverage. For quantum readiness for ERM, they should explain lineage, exceptions, manual intervention and the response when a control or feed fails.
- Second-line challenge: tests scope, assumptions, rating, appetite interpretation and proposed action. It should challenge the risk of waiting for a precise threat date, document disagreement and confirm when higher authority is required.
- Assurance and governance forums: assess whether the process works in practice and whether material conclusions reach the right committee. They should test whether the organisation can pilot migration waves, whether open weaknesses are visible and whether prior decisions produced the expected result.
For quantum readiness for ERM, a responsibility matrix is only the beginning. The workflow should preserve who submitted, reviewed, challenged, approved, changed and closed each material record, together with the date and rationale. That history protects continuity when teams, suppliers or legal-entity leadership change.
A realistic maturity path#
A staged path is usually more effective than trying to build the final form of quantum readiness for ERM immediately. Each level should solve a visible management problem before additional data, workflow or analytics are introduced.
Level 1: establish visibility#
Establish a complete inventory and accountable ownership for quantum readiness for ERM. Use Critical services with cryptographic inventory coverage as an initial coverage measure, and make missing or disputed records visible rather than filling gaps with assumptions.
Level 2: connect decisions and controls#
Move from inventory to management by connecting quantum readiness for ERM with evidence, approvals and remediation. Measures such as Long-lived sensitive data using vulnerable cryptography and Suppliers without a credible migration roadmap should trigger challenge before the formal reporting cycle.
Level 3: anticipate and optimise#
Optimisation means learning from movement in quantum readiness for ERM: incidents, overrides, failed controls and scenario results should refine thresholds and decisions. Technology asset, service, data and supplier inventory with cryptographic attributes is valuable when it turns that learning into timely, reviewable action.
Progress in quantum readiness for ERM should therefore be evidenced through timeliness, consistency, challenge and business outcomes—not through the number of fields in a template.
Measures that are useful in management meetings#
A management measure is useful only when it changes a conversation about quantum readiness for ERM. Critical services with cryptographic inventory coverage provides a practical starting point, but it should be shown with trend, materiality and the population to which it relates. Avoid dashboards that present activity counts without explaining what has moved beyond appetite or requires action.
-
Critical services with cryptographic inventory coverage: Measures visibility.
-
Long-lived sensitive data using vulnerable cryptography: Prioritises exposure.
-
Suppliers without a credible migration roadmap: Shows ecosystem dependency.
-
New systems meeting agility standard: Prevents additional debt.
-
Migration pilots completed by priority tier: Tests practical readiness.
-
Unknown cryptographic dependencies: Makes uncertainty visible.
Common failure modes#
-
Waiting for a precise threat date: Inventory and migration lead time justify action regardless of timing uncertainty.
-
Treating migration as algorithm replacement: Performance, protocols, devices, partners and operations all change.
-
Inventorying only internet-facing certificates: Cryptography is embedded throughout data, software and devices.
-
Assuming vendors will solve the problem: Provider timelines may not align with service or data needs.
-
Ignoring new technology debt: Current projects can make future migration harder if agility is not required now.
A 90-day implementation plan#
Days 1–30: establish the facts#
Create governance and select two critical services plus one long-lived sensitive-data domain. Run targeted cryptographic discovery and identify owners, suppliers, unknowns and replacement constraints.
Days 31–60: test the operating model#
Prioritise findings, contact critical suppliers and update architecture and procurement standards for cryptographic agility. Select a low-risk pilot that can test new algorithms or hybrid operation without customer impact.
Days 61–90: embed the management rhythm#
Approve a multi-year roadmap with migration waves, funding assumptions and external dependencies. Add quantum readiness to technology-risk reporting and track unknowns, supplier gaps and new-system compliance.
How technology should support the process#
A technology implementation for quantum readiness for ERM should connect records that already influence one another rather than create another standalone register. Users need to see current evidence, prior decisions, overdue actions and exceptions in context. Start with Technology asset, service, data and supplier inventory with cryptographic attributes, then add the following controls and workflow support:
-
Technology asset, service, data and supplier inventory with cryptographic attributes.
-
Risk assessments and prioritisation by data longevity and service impact.
-
Supplier roadmap, contract gap and remediation tracking.
-
Architecture exceptions and risk acceptance with expiry.
-
Programme milestones, pilot evidence and Board-level readiness reporting.
For quantum readiness for ERM, the closest Vilfora product workspace is /regquanta/it-cyber-resilience/it-asset-register. A useful implementation should connect that workspace to the relevant risks, controls, obligations, incidents, actions and reports rather than treating it as an isolated register.
Global implementation lens#
International implementation of quantum readiness for ERM should distinguish the enterprise minimum from the local overlay. The group can standardise critical services and tolerances, while legal entities document the jurisdiction, language, market structure and delegated authority that change how the control operates.
For this topic, common records should support technology and provider dependencies without forcing local teams to hide legitimate differences. The global view should report Critical services with cryptographic inventory coverage consistently, preserve the source evidence and show where data or terminology cannot be aggregated safely.
Local governance should then specify who will establish governance and risk ownership, which forum owns exceptions and how issues involving testing and recovery evidence are escalated. This produces comparable governance across countries without turning the global framework into identical paperwork everywhere.
Questions senior management should ask#
-
Which data must remain confidential beyond the expected life of current cryptography?
-
Do we know where critical algorithms and libraries are used?
-
Which products cannot be upgraded without replacement?
-
What are our critical suppliers committing to and by when?
-
Are new systems increasing or reducing cryptographic migration debt?
Frequently asked questions#
Why should ERM address quantum risk now?#
Because discovery, procurement and migration can take years, and some sensitive data requires long-term protection. The work is primarily about readiness and technology debt, not predicting an exact date.
What is a cryptographic inventory?#
It records where and why cryptography is used, including algorithms, keys, certificates, protocols, libraries, devices, data, owners, providers and upgrade paths.
What is cryptographic agility?#
It is the ability to replace or update cryptographic methods without redesigning the entire business system. It depends on architecture, configuration, standards and tested change processes.
Should organisations immediately replace all cryptography?#
No. Use a risk-based, standards-aligned migration plan. Prioritise long-lived sensitive data, critical services, vulnerable legacy systems and dependencies with long lead times.
Final takeaway#
Quantum readiness is a governance test: can the organisation identify a deep technology dependency, prioritise it and execute a coordinated transition before urgency removes its options? Mature governance does not remove uncertainty; it makes uncertainty discussable, owned and time-bound. For quantum readiness for ERM, the final measure of quality is whether decisions improve before an avoidable event forces the issue.
Within Vilfora ERM, /regquanta/it-cyber-resilience/it-asset-register can act as the operational entry point for quantum readiness for ERM, while linked controls, issues, evidence and reporting preserve the wider context. The implementation questions in this article can be used during a platform demonstration or process-design workshop.




