Key Takeaways
- Quantum readiness is now a supplier problem, not just an internal one. An organisation’s cryptographic security is only as strong as its weakest vendor, and regulators (NIST, NCSC, the EU, the G7) are increasingly treating third party cryptographic risk as an explicit compliance requirement, not an optional extra.
- The clock is running even though no quantum computer can break encryption yet. “Harvest now, decrypt later” means sensitive data is being copied and stored today for decryption once the technology matures, so waiting until 2030 to start assessing suppliers is already too late for long lived data.
- Procurement and TPRM teams, not just cyber security teams need to own this. Supplier questionnaires, contract clauses, sourcing criteria and vendor risk registers are the practical tools for managing quantum risk, and most existing guidance is written for cryptographers rather than the teams who will actually coordinate supplier readiness.
A supplier readiness questionnaire recently landed on the desks of technology vendors serving a large global insurer. The questions were not about pricing, uptime or data protection in the usual sense. They were about quantum computing: what happens to a supplier’s systems, encryption and services once quantum computers become powerful enough to break today’s standard cryptography.
That insurer is not alone, and insurance is not the point. The same exercise is now running quietly across banking, government, defence, healthcare, telecoms, cloud and SaaS, and any large enterprise holding sensitive data over the long term. What began as a niche cryptography debate inside security teams has become, in practice, a third party risk management (TPRM) and procurement problem.
What Post Quantum Cryptography Actually Means
Post quantum cryptography (PQC) refers to a new generation of encryption algorithms designed to remain secure even against a sufficiently powerful quantum computer. Today’s most common encryption methods, including RSA and elliptic curve cryptography (ECC), rely on mathematical problems that are extremely hard for classical computers to solve but that a large enough quantum computer could, in theory, solve quickly.
No such quantum computer exists yet. But the National Institute of Standards and Technology (NIST) finalised its first three PQC standards in August 2024: FIPS 203 (ML-KEM, for key exchange), FIPS 204 (ML-DSA, for digital signatures) and FIPS 205 (SLH-DSA, a hash-based signature scheme). A fourth algorithm, HQC, was selected as a backup and is expected to be finalised around 2027. These standards mark the point at which PQC moved from academic research to something organisations, and their suppliers, are now expected to implement.
Why the Clock Is Already Running
The most cited reason for urgency is not that quantum computers exist today, but that data can be stolen today and decrypted later, once the technology catches up. This is known as “harvest now, decrypt later.” An attacker who copies encrypted data now, even if they cannot read it immediately, can simply wait. For information with a long confidentiality shelf life, such as health records, government files, intellectual property or financial data, that wait is the risk.
ISACA’s 2025 Quantum Computing Pulse Poll, surveying more than 2,600 digital trust and security professionals, found that 62 percent were worried quantum computing will break today’s internet encryption, yet only 5 percent said their organisation had a defined quantum computing strategy. A separate Trusted Computing Group study published in December 2025 found that 91 percent of businesses had no formal roadmap for migrating to quantum safe algorithms, and 81 percent believed their existing cryptographic libraries and hardware security modules were not ready. The gap between concern and preparedness is exactly where supplier risk lives.
Regulators and standards bodies have started attaching real dates to this. Some of the clearest markers:
- NIST: new use of RSA and ECC discouraged from 2030, disallowed from 2035.
- NSA CNSA 2.0: new US national security system acquisitions must support quantum resistant algorithms from 1 January 2027, with full migration by 2035.
- UK NCSC: discovery and planning by 2028, high priority migration by 2031, full migration by 2035.
- European Union: Member States are expected to publish national roadmaps, including supply chain risk analysis, by the end of 2026, with critical infrastructure migrated by 2030 and full transition by 2035.
- G7 Cyber Expert Group: a January 2026 roadmap for the financial sector, co-chaired by the US Treasury and the Bank of England, sets 2030 to 2032 for critical systems.
None of these deadlines apply only to an organisation’s own systems. Every one of them, explicitly or implicitly, extends to the vendors, cloud providers and technology suppliers that organisation depends on.
Why This Is a Procurement and TPRM Problem
An organisation’s quantum readiness is only as strong as its weakest supplier. A business can spend years upgrading its own systems, but if a cloud ERP vendor or a payment processor still relies on outdated key exchange methods, that dependency undermines the whole effort.
Most organisations do not actually know where cryptography is embedded across their supplier base, which vendors create exposure, who inside those vendors owns the transition, or which contracts and service level agreements need updating. That is not a cryptography question, but a governance, sourcing and third party risk question, and it sits closer to procurement and TPRM teams than to cryptographic engineers.
Citigroup’s own quantum readiness programme illustrates the point well. Its programme leads describe PQC migration as a coordination problem before it is a technology problem, with the algorithm changes themselves representing only a fraction of the total effort. The larger share is stakeholder alignment, dependency mapping and sequencing across thousands of applications and third parties. NIST’s own National Cybersecurity Center of Excellence shares Citi’s vendor survey approach as a model other organisations can adapt for their own supplier base, a strong signal that this is becoming standard TPRM practice rather than a one-off exercise.
CISA, NSA and NIST’s joint quantum readiness guidance makes the same point structurally. Its four recommended steps are to build a migration roadmap, create a cryptographic inventory, discuss quantum safe roadmaps directly with technology vendors, and determine supply chain quantum readiness; work the guidance says should be led by IT and procurement teams together, not security alone.
Five Ways Procurement and TPRM Teams Can Take Ownership
1. Supplier Readiness Assessments
A useful PQC vendor questionnaire goes well beyond “do you support post quantum cryptography.” It should probe whether the supplier maintains a cryptographic inventory, how mature its crypto agility is (its ability to swap algorithms without a system rebuild), its exposure through fourth parties such as its own cloud or infrastructure providers, and its progress toward FIPS 140-3 validation, a process that typically takes 12 to 24 months, meaning suppliers who have not started by 2026 or 2027 are unlikely to meet 2030 deadlines. Crucially, it should establish who inside the supplier actually owns the answer, since many vendors are still working that out internally.
2. PQC Vendor Governance Programmes
A one-off questionnaire is just a snapshot. Organisations increasingly need ongoing supplier tracking: annual reassessment of quantum roadmaps, tiering of suppliers by criticality and data sensitivity, and clear escalation and reporting lines into the CIO or CISO. This is closer to programme governance than deep cyber engineering, and it fits naturally within existing vendor management functions.
3. Contract and Commercial Review
Most current supplier contracts say nothing about post quantum cryptography. They rarely define future cryptographic obligations, migration responsibilities or liability if a supplier’s encryption becomes obsolete. The UK’s Cross Market Operational Resilience Group guidance from April 2025 recommends embedding quantum safe commitments directly into new contracts and service level agreements. Contract renewal points, rather than the full contract lifecycle, are the practical moments to introduce these clauses.
4. Strategic Sourcing Support
New spend should not create new cryptographic debt. Building PQC and crypto agility requirements into RFPs and vendor selection criteria helps ensure that organisations are not locking themselves into another decade of non-compliant infrastructure. Comparing vendors’ published roadmaps, several major cloud providers already support hybrid post-quantum key exchange, gives sourcing teams a concrete and evidence based way to differentiate “migration ready” suppliers from those merely making empty promises.
5. TPRM and Intake Integration
Quantum readiness questions belong in standard supplier onboarding and periodic due diligence, not as a separate parallel exercise. Adding PQC exposure to intake questionnaires and risk registers aligns naturally with existing obligations under frameworks such as the EU’s Digital Operational Resilience Act and NIS2, both of which already require organisations to manage cryptographic and third party risk formally.
A Simple Starting Point
Organisations do not need to become cryptography experts to start this work. A short internal starting checklist can be enough to open the conversation with suppliers and stakeholders:
- Do we have a cryptographic inventory covering our critical third party dependencies?
- Which suppliers hold or process data with a long confidentiality shelf life?
- Have we asked our top tier suppliers for their quantum safe roadmap and timeline?
- Do our current contracts include any obligation for suppliers to maintain current cryptographic standards?
- Who inside our organisation, and inside each key supplier, actually owns this issue?
- Are PQC and crypto agility requirements included in our current RFP and sourcing criteria?
Where the Real Opportunity Lies
Most existing PQC guidance is written by cryptographers, for cryptographers. It is technically complex and largely inaccessible to the procurement, sourcing and third party risk professionals who will end up doing much of the coordination work.
The organisations that get ahead on this will not necessarily be the ones with the deepest cryptographic expertise, but the ones that treat quantum readiness the way they already treat other cross cutting third party risks: with a clear inventory, structured supplier engagement, updated contracts, smarter sourcing decisions and integration into existing TPRM processes. The technology change is coming regardless. How well it is coordinated across the supplier ecosystem is still, for the most part, an open question.
Related reading
The sourcing argument in this article, that new spend should not create new cryptographic debt and that PQC readiness should be a vendor selection criterion, sits within a broader challenge that many procurement teams are already navigating: how to regain genuine commercial control over technology suppliers who have grown more concentrated, more complex and harder to hold to account. Our article on IT procurement strategy in 2026 addresses exactly that, covering how leading organisations are structuring vendor relationships, managing renewal cycles and building the leverage needed to introduce requirements like quantum readiness into contracts where suppliers would otherwise push back.
How Procurato can help
The five ownership steps this article sets out are clear, but most organisations do not have a complete picture of which suppliers hold sensitive data, which of those suppliers have a credible quantum safe roadmap, or what their contracts currently say about cryptographic obligations. Our Supplier Due Diligence service provides that baseline: a structured, evidence-based assessment of your supplier base against financial, operational, regulatory and now cryptographic risk dimensions, identifying where PQC exposure is concentrated, which vendors are and are not migration ready, and where contract terms need updating before the 2027 to 2030 regulatory windows close. If you want to understand your current third party quantum risk position before regulators start asking the same question, we are happy to start that conversation.
Stay ahead of the game with our latest insights
Frequently Asked Questions
Is post quantum cryptography only relevant to large technology companies?
No. Any organisation that depends on suppliers handling sensitive or long lived data, including financial services, healthcare, government, telecoms and insurance, has exposure through its supply chain, regardless of its own technical capability.
Do we need to migrate our systems immediately?
Most regulatory timelines point to 2030 for high priority systems and 2035 for full migration, but discovery work, building a cryptographic inventory and engaging suppliers, is recommended well before then, with several frameworks suggesting 2026 to 2028 as the planning window.
What is the single most useful first step?
Building a cryptographic inventory that extends to critical third party suppliers, then using it to prioritise which vendor conversations matter most.
References
- NIST, Post-Quantum Cryptography Standards Finalisation, August 2024
- NIST FIPS 203, 204 and 205 overview, QNSQY Guide to NIST PQC Standards
- The Quantum Insider, Quantum Security Deadlines: What Happens Next, 2026
- PostQuantum.com, CNSA 2.0: Complete Guide to NSA’s PQC Requirements
- The Quantum Insider, UK Sets Timeline and Roadmap for Post-Quantum Cryptography Migration, March 2025
- European Commission, Recommendation on a Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography
- PostQuantum.com, Payments and the Race to Quantum Safety
- ISACA, Quantum Computing Pulse Poll, 2025
- Trusted Computing Group, State of PQC Readiness Report, December 2025