RBI’s 2024 IT risk advisory, SEBI’s CSCRF post-quantum planning FAQs and CERT-In’s CBOM guidelines each create specific expectations for PQC. A generic checklist, therefore, leaves your compliance team to figure out which items map to which obligation. This 15-step PQC readiness checklist below are grouped by regulatory priority. Each item notes the regulatory framework it satisfies so your team knows exactly what each step proves to an auditor.
Section 1: Cryptographic asset visibility (CERT-In CBOM requirement)
Step 1: Generate a Cryptographic Bill of Materials (CBOM) for all regulated systems
Identify every cryptographic algorithm, key, certificate and library across applications that handle regulated data. This is the foundational CERT-In CBOM requirement and the starting point for every other item on this list.
Step 2: Map cryptographic assets to the applications and business functions they protect
A bare inventory is not sufficient. Each asset must be connected to the system it secures and the type of data that system handles. This contextualisation is what allows risk prioritisation in the steps that follow.
Step 3: Identify all uses of quantum-vulnerable algorithms
Flag every instance of RSA, ECC, Diffie-Hellman and related protocols across your environment. Include implementations in third-party libraries, cloud services and embedded systems – not just in-house code.
Step 4: Classify data by sensitivity and required confidentiality period
Determine which data assets must remain confidential for five or more years. These are your highest-priority targets for immediate PQC migration because they are exposed to harvest-now-decrypt-later risk right now.
Section 2: Governance and accountability (RBI IT risk advisory)
Step 5: Assign executive ownership of PQC risk
Someone at the CISO or IT Head level must be formally accountable for post-quantum risk management. Document this in your governance structure. RBI’s IT governance expectations require named accountability for emerging technology risks.
Step 6: Add quantum risk to your enterprise risk register
PQC risk should appear as a named entry in your risk register with an owner, a current rating and a review date. This creates the documented governance trail that RBI inspections and SEBI audits expect to see.
Step 7: Brief the board or risk committee on quantum exposure
Board-level awareness of quantum risk is increasingly expected under RBI’s IT risk framework. Document the briefing, the date and the board’s response. This does not require the board to approve a full migration plan – it requires evidence that the conversation has happened.
Section 3: Third-party and supply chain risk (RBI outsourcing guidelines)
Step 8: Identify all vendors and cloud providers that perform cryptographic functions on your behalf
This includes core banking solution vendors, payment gateway providers, cloud infrastructure partners and SaaS platforms that handle customer data. Every third party that encrypts or decrypts regulated data on your behalf is within scope.
Step 9: Request PQC roadmap documentation from critical vendors
Issue formal requests to your top-tier vendors asking for their post-quantum cryptography migration plan and timeline. Document responses – and non-responses. RBI’s outsourcing guidelines require active third-party risk management, which includes emerging technology risks.
Step 10: Include PQC readiness checklist requirements in new vendor contracts
For any new contract or renewal involving cryptographic services, add a requirement that the vendor maintain a documented PQC migration plan aligned to NIST standards. This is a forward-looking governance action that closes future supply chain risk.
Section 4: Migration planning (SEBI CSCRF PQC planning requirement)
Step 11: Develop a phased PQC migration roadmap with named owners and target dates
SEBI’s CSCRF PQC planning guidance expects regulated entities to have a documented migration intent. This does not need to be a complete technical implementation plan – it needs to demonstrate that your organisation has analysed its exposure and set a directional path.
Step 12: Identify systems with the lowest crypto-agility and flag them for early-phase migration
Crypto-agility refers to how easily a system can swap cryptographic algorithms without major re-engineering. Systems with hard-coded algorithms, embedded devices with fixed firmware or legacy protocols with no upgrade path represent your highest-effort migration items. Identify them now so they do not become last-minute crises.
Step 13: Test hybrid encryption approaches for your highest-risk systems
Hybrid encryption combines a classical algorithm with a NIST-approved PQC algorithm. It provides quantum protection today while maintaining backward compatibility. For your most sensitive systems, piloting a hybrid approach is a practical interim step that reduces risk before full migration is complete.
Section 5: Ongoing monitoring and audit readiness (all three frameworks)
Step 14: Establish a continuous CBOM monitoring process
Your cryptographic environment changes every time a system is updated, a new application is deployed or a vendor changes their infrastructure. A one-time CBOM generation becomes stale within months. Continuous monitoring – ideally through an automated platform – ensures your inventory stays current and your audit evidence remains valid.
Step 15: Schedule a post-quantum readiness review as part of your annual audit cycle
Integrate PQC readiness into your existing cybersecurity audit calendar. This review should assess progress against your migration roadmap, update the risk register, review third-party compliance status and identify any new exposures introduced since the last review.
Conclusion
A PQC readiness checklist is only useful if it tells you not just what to do but why it matters to the regulators who will eventually ask you for evidence. These 15 steps are structured precisely to give Indian BFSI entities that dual utility – a practical action plan and a compliance evidence trail.
CyberNX automates CBOM generation and continuous monitoring that underpin Steps 1 to 4 and Step 14 – the items that carry the most regulatory weight. If you are working through this checklist and want to move faster on the foundational items, speak with our team to see how our PQC readiness solutions can fit your environment.
PQC readiness checklist FAQs
Which of these 15 steps should an NBFC prioritise if it is starting from scratch?
Start with Steps 1 to 4 – the CBOM and data classification items. These are the foundation for everything else and the most likely items an auditor will examine first. Steps 5 to 7 (governance) should follow immediately because they are low-effort but high-visibility from a regulatory perspective. Steps 8 to 10 (third-party) can run in parallel once internal visibility is established.
Does completing this PQC readiness checklist mean we are quantum-safe?
No. This checklist establishes readiness – it creates the visibility, governance and planning foundation your migration programme needs. Actual quantum safety requires migrating your systems to NIST-approved PQC algorithms, which is a multi-year implementation effort. This checklist is how you start that journey with credibility and in compliance with Indian regulatory expectations.



