The Indian government has set a December 2027 deadline for Critical Information Infrastructure (CII) sectors which includes BFSI. A PQC risk assessment is the starting point but now the question is: how do you scope it correctly before spending time and budget on one? This can be a stumbling block. Therefore, before commissioning a PQC risk assessment, answer the questions that determine its scope, output format and usefulness. The result is a risk register that is either too broad to act on, or too narrow to satisfy a regulator.
In this blog, we explain five questions. Answer them first, and your assessment will be scoped correctly from day one.
Question 1: How long does your most sensitive data need to stay secret?
This question sets your migration urgency.
Why data shelf-life drives prioritisation
The quantum threat is not uniform across your data. An encrypted session token that expires in 24 hours carries negligible quantum risk. A mortgage record or board communication that must remain confidential for 20 years carries extreme quantum risk under the Harvest Now, Decrypt Later (HNDL) model – where adversaries collect encrypted data today, intending to decrypt it once quantum capability arrives.
The Government of India Task Force report is explicit: for organisations where data longevity exceeds ten years, this threat is active now.
What to do before your assessment
Map your data categories against expected confidentiality periods. Healthcare records, legal documents, financial transaction histories and strategic communications typically require 10–25 years of protection. Session data and operational logs are short-lived. This mapping tells you which systems your assessment must prioritise.
Question 2: Which regulators have cryptographic expectations over your organisation?
Your regulatory exposure determines the output format your assessment must produce, and how soon you need results.
The Indian regulatory picture
SEBI’s CSCRF framework introduced expectations for cryptographic asset inventory and risk-based PQC prioritisation in 2025.
RBI’s cybersecurity directions include cryptographic control requirements for banks and NBFCs.
CERT-In has published CBOM guidelines specifying inventory format and vendor engagement expectations. The Government of India Task Force has directed SEBI and RBI to initiate sector-specific compliance frameworks.
Why this shapes your assessment design
Different regulators require different outputs. Take a look at these examples:
- An assessment for SEBI CSCRF needs a structured cryptographic asset register with risk scoring tied to data sensitivity.
- An assessment for RBI IT governance review needs controls mapped to the master direction framework.
- An assessment for CERT-In CBOM compliance needs CycloneDX-format output.
Running one generic assessment and expecting it to serve all three is the most common scoping error. Identify your regulatory obligations before you scope and build the output requirements in from the start.
Question 3: How much of your cryptographic estate is controlled by third parties?
The third-party problem
In most BFSI organisations, a significant share of cryptographic decisions are made by vendors. Your core banking platform decides cipher suite support. Payment gateway manages its own certificate authority relationships and cloud provider controls encryption libraries in managed services.
These dependencies carry real quantum risk but sit outside your direct control – and are often excluded from assessment scope because you cannot inspect them directly. An RSA-2048 key managed by a payment gateway you depend on is still a vulnerability in your cryptographic estate, even if it sits outside your perimeter.
What to do before your assessment
Conduct a vendor cryptographic dependency mapping exercise before scoping. For each critical third-party system, identify what cryptographic functions it provides, whether it has a published PQC migration roadmap and what your contractual position is for demanding a CBOM submission.
The Government of India Task Force has recommended mandatory CBOM submissions from vendors starting FY 2027–28. The CBOM checklist covers the twelve questions to ask before you can claim full cryptographic visibility.
Question 4: What is the PQC readiness of your HSMs and key management infrastructure?
Hardware Security Modules (HSMs) and Key Management Systems (KMS) are the highest-complexity component of any PQC migration. They are also the most excluded from initial assessment scopes.
Why HSMs are the rate-limiting step
HSMs are certified hardware. Updating their cryptographic capabilities is not a software patch – it requires firmware updates, FIPS 140-3 re-certification and, in many cases, physical hardware replacement. The Government of India Task Force roadmap lists upgrading PKI, HSMs and KMS as a Milestone 2 requirement for CII sectors, with a 2028 deadline.
You cannot plan that migration without first knowing which HSMs you have, which PQC algorithms they support and what your vendor’s roadmap looks like. In practice, this discovery takes longer than expected because HSMs are often managed outside standard IT asset inventories.
Contact your HSM vendors before scoping. Ask specifically which NIST FIPS 203, 204 and 205 algorithms are supported and at what timeline. If hardware replacement is required, your assessment scope and your capital planning both need to reflect it.
Question 5: Who owns quantum risk governance in your organisation?
This is the question that determines whether your assessment leads to action – or sits in a shared drive.
Why governance must come before assessment
A PQC risk assessment produces a risk register, a prioritised asset list and remediation recommendations. Without a named governance owner who has board-level visibility and budget authority, these outputs have nowhere to go.
The Government of India Task Force is explicit: establishing leadership and governance for quantum risk is a Milestone 1 requirement for CII organisations, due by 2027. Governance is a foundations deliverable, not a later-stage outcome. Commissioning an assessment before governance is in place means findings land with no one empowered to act on them.
Before scoping, answer three questions. Who is the named PQC migration owner? Does that person have board or audit committee access? Is there a dedicated budget line for cryptographic migration?
If any answer is unclear, establishing that structure is the most valuable output of your pre-assessment work. The CBOM vs PQC readiness assessment guide explains how governance ownership changes what the assessment itself needs to produce.
Scope it right the first time
Each question addresses a different failure mode. Answer all five before you scope – and your PQC risk assessment becomes the first step in a migration programme. CyberNX’s PQC readiness solutions help BFSI and enterprise organisations work through this pre-assessment framework, build a quantum-risk-scored and produce regulatory-ready output aligned to SEBI CSCRF, RBI master directions and CERT-In CBOM guidelines. Talk to our team before you scope – it changes what you ask for and what you get back.
PQC risk assessment FAQs
What is the difference between a PQC risk assessment and a CBOM?
A CBOM is a structured inventory of your cryptographic assets. A PQC risk assessment uses that inventory as its input and layers risk analysis on top – identifying which assets protect long-lived data, which algorithms are quantum-vulnerable and which systems carry the highest migration urgency. You need a CBOM before a meaningful PQC risk assessment can begin. They are sequential, not interchangeable.
How long does scoping a PQC risk assessment take?
For a mid-size BFSI organisation, answering these five questions thoroughly takes two to four weeks – assuming HSM vendor conversations, regulatory mapping and third-party dependency reviews run in parallel. Organisations that skip this step typically spend the same time reworking scope mid-engagement when gaps surface.



