Quantum Readiness Assessment
Quantum readiness is the state of being prepared for the arrival of cryptographically relevant quantum computers — machines powerful enough to break RSA and ECC, the algorithms that protect most of the internet today. When that day arrives (estimates range from 5 to 15 years), every RSA key, every ECC certificate and every TLS session secured by these algorithms becomes retroactively breakable.
What is quantum readiness?
Quantum readiness means your organisation has:
- A complete cryptographic inventory of every RSA and ECC key in your infrastructure
- A quantum risk score for each asset (based on algorithm, key length and exposure)
- A prioritised PQC migration roadmap — what to replace first, with which post-quantum algorithm, and when
- Compliance evidence for NIS2, DORA and other frameworks that require cryptographic governance
Post-quantum cryptography (PQC) migration
NIST has standardised the first post-quantum algorithms (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA). PQC migration is the process of replacing quantum-vulnerable algorithms (RSA, ECC) with these post-quantum standards. QROS generates PQC-ready certificates (ML-KEM, ML-DSA, hybrid classical+PQC) so you can test migration paths before the quantum threat materialises.
Quantum-safe migration with QROS
QROS scans your entire public surface — every host, every port, every TLS certificate — and for each cryptographic asset it reports:
- Algorithm: RSA, ECC, DH, ECDH — and whether it's quantum-vulnerable (Shor's algorithm)
- Key length: RSA-1024 (broken today), RSA-2048 (broken by quantum), ECC-P256 (broken by quantum)
- Quantum risk score: Grover's advantage (symmetric halving) and Shor's advantage (asymmetric breaking) per asset
- PQC replacement: which NIST post-quantum standard replaces each vulnerable key
The result is a cryptographic risk map that shows exactly where your quantum exposure is concentrated and what to fix first.
Why quantum readiness is urgent now
"Harvest now, decrypt later" attacks mean data encrypted today with RSA/ECC can be stored and broken retroactively when a quantum computer arrives. The longer you wait, the more encrypted data accumulates that will eventually be decryptable. Discover your cryptographic exposure and start your PQC migration today.
FAQ
What is quantum readiness?
Quantum readiness is the state of being prepared for cryptographically relevant quantum computers — having a complete inventory of quantum-vulnerable cryptographic assets (RSA, ECC), a risk score for each, and a prioritised migration plan to post-quantum cryptography (PQC).
When will quantum computers break RSA?
Estimates range from 5 to 15 years for a cryptographically relevant quantum computer (CRQC) capable of running Shor's algorithm at scale. However, 'harvest now, decrypt later' attacks mean data encrypted today can be stored and broken retroactively.
What is PQC migration?
PQC migration is the process of replacing quantum-vulnerable algorithms (RSA, ECC) with NIST-standardised post-quantum algorithms (ML-KEM, ML-DSA, SLH-DSA). QROS helps prioritise which assets to migrate first based on exposure and risk.
How does QROS score quantum risk?
QROS scores each cryptographic asset by its algorithm (RSA/ECC = Shor-vulnerable, AES = Grover-halved), key length (shorter = higher risk), and public exposure (internet-facing = higher risk). The composite score (0–100) reflects the asset's overall quantum vulnerability.
Start your cryptographic risk assessment with QROS
Explore now →