A post-quantum cryptography (PQC) readiness assessment reviews what your organisation currently uses to protect data, identifies where those protections will break under a quantum-capable attack and maps a path to fix things before that moment arrives.
The Reserve Bank of India’s 2024 advisory on cryptographic risk, SEBI’s CSCRF post-quantum planning requirements and CERT-In’s CBOM guidelines are all pointing in the same direction.
Indian regulated entities are expected to know their exposure and to document it. This blog explains what a PQC readiness assessment covers, what makes it different from a standard security audit and what Indian banks and NBFCs specifically need to include in scope.
What is PQC readiness assessment?
PQC readiness assessment is a structured review of your organisation’s readiness to withstand or respond to the threat posed by cryptographically relevant quantum computers (CRQCs). It is focused specifically on your cryptographic infrastructure – the algorithms, keys, certificates, protocols and libraries your systems depend on – and whether those will remain secure when quantum computing advances.
At its core, the assessment asks one question: if a quantum computer capable of breaking RSA and ECC encryption existed today, where would your organisation be exposed?
The output is a prioritised list of gaps, mapped to business risk and regulatory consequence. It is the starting point for any credible post-quantum migration programme.
Why Indian regulators are raising the bar
Indian financial regulators have moved from awareness to expectation.
- RBI’s 2024 advisory on IT risk and cyber resilience specifically calls for institutions to inventory cryptographic assets and assess vulnerability to emerging threats – quantum computing included.
- SEBI’s CSCRF PQC planning guidance, issued through FAQs in mid-2025, expects regulated entities to have a baseline understanding of their cryptographic exposure and a documented migration intent.
- CERT-In’s CBOM framework, which mandates a Cryptographic Bill of Materials for regulated entities, creates a legal basis for auditors to ask for documented evidence of your cryptographic landscape.
Together, these three frameworks mean that a PQC readiness assessment is becoming a compliance obligation.
The five domains your assessment must cover
Most assessments fail not because of lack of intent but because organisations scope too narrowly. A credible PQC readiness assessment covers five areas.
1. Cryptographic inventory and vulnerability identification
This is the foundation and means documenting every algorithm, protocol, library and certificate in use – from TLS configurations and VPN settings to application-level signing keys and HSM-stored root certificates. The goal is a complete Cryptographic Bill of Materials (CBOM) that maps each asset to the system it protects.
2. Data sensitivity and retention risk
It overlays business context onto the technical inventory. Not all data carries the same quantum risk. Long-lived sensitive records – customer identity data, transaction histories, loan agreements – are targets for “harvest now, decrypt later” attacks today, even before quantum computers exist. The assessment must identify which data falls into this category and flag it for priority action.
3. Governance and accountability
It examines who owns the PQC risk within your organisation. A valid assessment looks for an executive owner, a documented risk register entry and evidence that the board or risk committee has discussed the issue. Regulators are increasingly looking for this governance trail.
4. Third-party and supply chain exposure
This is where most assessments fall short. Your vendors, cloud providers and core banking solution partners all use cryptography on your behalf. If they have no PQC roadmap, their vulnerability becomes your liability. Your assessment scope must extend to key third parties.
5. Migration planning and crypto-agility
It reviews whether your systems can adopt new algorithms without major re-engineering. Systems with hard-coded algorithms, legacy embedded devices or outdated protocol stacks score poorly on agility – and represent the most difficult migration work ahead.
Read our blog on PQC readiness tools to find key evaluation criteria before opting for an enterprise-wide tool/platform.
What separates a regulatory-ready assessment from a basic review
A basic cryptographic review tells you what algorithms you use. A regulatory-ready PQC readiness assessment connects findings to compliance obligations.
For Indian BFSI entities, this means your assessment report should map each finding to a specific regulatory expectation. A gap in your CBOM is not just a technical debt item – it is a potential CERT-In audit finding. A third-party vendor with no PQC roadmap is a supply chain gap that RBI’s outsourcing guidelines require you to manage.
CISOs who treat the assessment as a compliance exercise produce a report their auditors can work with. CISOs who treat it as a security exercise build a roadmap their technical teams can execute. The best assessments do both. Read our PQC readiness best practices blog to know more.
How often should you run a PQC readiness assessment?
An initial assessment should happen as soon as possible. The value of starting now is that it creates a baseline – a documented state of your cryptographic environment against which progress can be measured.
After the initial assessment, most Indian regulated entities will benefit from an annual review cycle, aligned to their existing audit calendar. The threat landscape is not static. Quantum computing is advancing, new algorithms are being standardised by NIST and your own IT environment changes continuously. An assessment that was accurate 18 months ago may miss new exposures introduced through system upgrades, vendor changes or new product launches.
What the assessment output should include
A well-structured PQC readiness assessment delivers four things.
A cryptographic asset inventory (your CBOM) that is comprehensive, organised by system and tied to business function. A risk-ranked gap list that separates high-priority findings (long-lived sensitive data using RSA, public-facing TLS with no hybrid fallback plan) from lower-priority items. A third-party exposure summary that identifies which vendors are quantum-ready and which are not. And a migration readiness score that gives leadership a single-page view of where the organisation stands.
These outputs serve both the security team and the auditor. That dual utility is what makes the assessment worthwhile.
Conclusion
A PQC readiness assessment is the starting point for every credible post-quantum programme. Without it, your migration planning is guesswork and your regulatory conversations are reactive. With it, you have a documented baseline, a prioritised action list and the evidence base your auditors will eventually ask to see.
CyberNX’s PQC readiness solutions give your organisation the cryptographic visibility that underpins a credible assessment. If you are not sure where your cryptographic exposure sits, that is exactly where we start. Speak with our team to understand what a PQC readiness assessment looks like for your organisation specifically.
PQC-Readiness Assessment FAQs
Is a PQC readiness assessment the same as a CBOM?
No. A CBOM is one output of a PQC readiness assessment – specifically the cryptographic asset inventory component. The assessment itself is broader: it covers governance, data risk, third-party exposure and migration planning. CERT-In mandates the CBOM; RBI and SEBI expect the broader assessment.
Do smaller NBFCs need a PQC readiness assessment?
Yes. Quantum risk does not scale with organisation size – it scales with the sensitivity and longevity of the data you hold. A mid-size NBFC holding 10 years of borrower records is exposed to harvest-now-decrypt-later risk regardless of how large or small it is. The scope of the assessment can be proportionate to your complexity, but the exercise itself is not optional.


