Many organisations we engage with have not started PQC Readiness yet. Not because they are unaware of the risk, but because the starting point is unclear, the technical complexity feels daunting and the regulatory deadline – while approaching – has not yet triggered the urgency of, say, a SEBI CSCRF audit notice or an RBI inspection finding.
If your organisation is in that position, this blog is written for you. Not for the early adopters who have been running cryptographic inventories since 2022. For the IT heads, CISOs and compliance officers at Indian banks, NBFCs and financial intermediaries who know PQC is coming and need a clear, achievable starting point.
The PQC readiness best practices below are structured around a 90-day foundation – the steps that, done well, give you a credible starting position before the regulatory pressure arrives in force.
Best practice 1: Start with visibility
You cannot sequence a transition plan without knowing where your vulnerable cryptographic assets are, what data they protect and how long that data needs to remain secure. Therefore, your first action is a cryptographic inventory. A CBOM that maps every algorithm, key, certificate and library across your regulated systems. This is not a one-time discovery scan but the foundation of your programme, and it needs to be accurate, structured and linked to business context.
Do not underestimate how much your team will learn from this exercise. Most organisations discover cryptographic implementations they were not aware of – in legacy integrations, third-party software components and embedded devices. Visibility first is the right starting point.
Best practice 2: Assign accountability before you assign tasks
Before your team runs a single cryptographic scan, establish who is accountable for PQC risk at the executive level.
This means naming a PQC risk owner. Typically, it is the CISO or a senior IT risk officer. Ensure that ownership is documented in your governance structure. It means adding quantum risk to your enterprise risk register. And it also means briefing your board or risk committee at least once, so that leadership awareness is on record.
Indian regulators are increasingly looking for this governance evidence. An RBI inspection or SEBI audit that finds detailed technical work, but no executive ownership structure will still identify a governance gap. Assign accountability first and the technical work follows from it.
Best practice 3: Prioritise by data longevity, not by system size
Once you have your cryptographic inventory, you need to decide what to fix first. The instinct is to prioritise by system size or business criticality. The correct prioritisation criterion, however, is data longevity.
Any system that holds data which must remain confidential for five or more years is a high-priority target. This is because harvest-now-decrypt-later attacks are already happening. Adversaries are collecting encrypted data today, storing it and waiting for quantum computing to mature so they can decrypt it. Your customer records, loan files, trading histories and identity data are potential targets right now.
Systems with shorter data retention periods carry less quantum risk and can be addressed in later migration phases.
Read our blog: PQC Readiness Assessment Guide
Best practice 4: Extend your scope to third parties immediately
Your cryptographic exposure does not end at your network boundary. Every vendor, cloud platform and SaaS provider that handles your regulated data is part of your quantum risk profile.
Contact your critical vendors now. Ask specifically:
- Do they have a post-quantum cryptography migration roadmap?
- Are they tracking NIST’s finalised PQC standards?
- What is their timeline for supporting quantum-safe algorithms in the products and services you use?
Document the responses and the non-responses. A vendor that cannot answer this question in 2026 is a risk that belongs in your risk register today. RBI’s IT outsourcing guidelines require active management of third-party technology risk. Quantum vulnerability in your vendor chain meets that threshold.
For new contracts and renewals, add a PQC readiness clause. Require vendors to maintain documented migration plans aligned to NIST standards. This closes future supply chain exposure at the point of procurement rather than after the fact.
Best practice 5: Build crypto-agility into new systems from day one
Every system you build or procure today is a system you will need to migrate to post-quantum cryptography eventually. The easiest time to build for that transition is before the system is in production.
Crypto-agility means designing systems so that cryptographic algorithms can be swapped without major re-engineering. This typically involves:
- Centralising cryptographic functions through a shared API or service layer rather than implementing them directly in each application
- Using configurable algorithm parameters rather than hard-coded values and
- Selecting libraries and platforms that already have PQC roadmaps in place.
Systems built with crypto-agility are dramatically cheaper to migrate. Systems built without it (with hard-coded RSA implementations, embedded certificates in firmware or legacy protocols that have no upgrade path) represent the most expensive and time-consuming items in any PQC migration programme.
Read our blog: How to Evaluate PQC Readiness Tools
Best practice 6: Use your first 90 days to build an audit-ready foundation
In the first 30 days, complete your CBOM for regulated systems and assign executive ownership.
In the following 30 days, complete your data longevity classification, run your third-party PQC outreach and add quantum risk to your enterprise risk register.
In the final 30 days of your foundation quarter, document a high-level migration roadmap – even a draft – and schedule your first PQC readiness review as a standing item in your annual audit cycle.
At the end of 90 days, you will have: a documented CBOM, a prioritised risk list, a governance structure, third-party engagement evidence and a migration roadmap. That is a credible foundation that satisfies the baseline expectations of CERT-In, RBI and SEBI – and gives your technical team a clear programme to execute against.
Conclusion
Starting from zero on PQC readiness does not mean starting slowly. It means starting deliberately. The best practices above give your organisation a structured, regulatory-aligned foundation that can be built in 90 days – without waiting for a complete technical migration plan, a formal regulatory deadline or a board mandate.
The organisations that will manage post-quantum risk effectively are not the ones that started with the most resources. They are the ones that started with the clearest programme. CyberNX’s PQC solutions give you the cryptographic visibility to start that programme on solid ground. If you want to understand what a 90-day PQC foundation looks like for your specific environment, speak with our team.
PQC readiness best practices FAQs
Is there a regulatory deadline for PQC readiness in India?
There is no single published deadline. RBI, SEBI and CERT-In have each created expectations through advisories, guidelines and FAQs rather than a single compliance deadline. However, migration to NIST-approved PQC algorithms is becoming embedded in regulatory frameworks globally and in India, and the pace is accelerating. Starting your foundation programme now puts you ahead of formal mandates rather than behind them.
What is the difference between crypto-agility and PQC migration?
Crypto-agility is an architectural property – the ability to change cryptographic algorithms quickly when needed. PQC migration is the act of changing specific algorithms from quantum-vulnerable to quantum-safe alternatives. Crypto-agility makes PQC migration faster and cheaper. An organisation with high crypto-agility can migrate a system in weeks. An organisation without it may take months or years for the same system.



