When do we need to move to post-quantum crypto?
Inventory now, migrate long-lived secrets by 2028, everything else on the ASD timeline (2030). Do not sell a 'quantum readiness audit' as a product; it is a crypto inventory and clients can do it themselves.
Tier is not strength
Tier says how much we know. Strength says how hard we are telling you to act. Scored independently.
Machine-readable target
{
"taskType": "crypto-migration",
"configKey": "assurance.pqc.deadline"
}Nothing consumes it yet. Day two: findings ship as defaults into the gateway, routing config and skill library.
Body
As of 1 August 2026: three dates. Start the cryptographic inventory now, because it takes a year in any organisation with more than one legacy system. Migrate anything whose confidentiality must hold past 2035 — long-lived keys, archived records, signed documents — to NIST's standardised post-quantum algorithms by 2028, on the harvest-now-decrypt-later argument. Everything else follows the ASD ISM timeline, which currently says 2030 for traditional asymmetric crypto in government systems (c-quantum-encryption-1).
Evidence: two validation runs on the quantum-encryption field, reading ASD, NIST and the major cloud providers' migration schedules. Nothing in the quantum-compute field moved the date closer this year; the cryptographically relevant machine is still a 4yr+ timeline on our scoring (c-quantum-encryption-3). g-quantum-readiness-audit is the graveyard entry: the audit product was priced, pitched twice, and rejected both times because the inventory is the whole job and clients' own security teams own it.
Caveat: the ISM timeline is reviewed annually and the next revision is expected before year end. If the quantum-compute dependency trigger fires — a demonstrated logical-qubit count above the threshold on the field's depends-on edge — this answer is wrong and will be resurfaced automatically.
What it rests on
The PQC migration case is independent of when a cryptographically relevant quantum computer arrives; harvest-now-decrypt-later and dated regulation make it current.
A standalone 'quantum readiness audit' does not sell repeatably; the inventory sells only when embedded in existing governance work.
Field
Quantum EncryptionGraveyard · rejected
Sell a quantum-readiness audit this year “Right question, wrong decade, wrong department.”