Is your organisation
quantum-ready?
Adversaries are harvesting your encrypted data today to decrypt once quantum computers mature — the Harvest Now, Decrypt Later threat is active, not hypothetical. NIST estimates a Cryptographically Relevant Quantum Computer (CRQC) arrives between 2029 and 2033.
PQReady gives your CISO a cryptographic bill of materials (CBOM), a Two-Clocks readiness score calibrated to NIST FIPS 203/204/205 and NSA CNSA 2.0, a verifiable public certification, and a targeted remediation pathway — in a single workflow.
Two threats. Different timelines.
One platform to address both.
PQReady's Two-Clocks model is the only methodology that treats confidentiality and trust as separate, independently scored risks — because they are. HNDL attacks are active today. PKI and signature migrations require years of lead time.
Active threat. Adversaries are intercepting and storing encrypted communications today — TLS sessions, VPN tunnels, API calls — to decrypt once a CRQC becomes available. Long-lived data (health records, legal documents, financial transactions) is already at risk.
Digital signatures — PKI certificates, firmware signing, code integrity, authentication — can be retrospectively forged once RSA and ECDSA are broken. A forged firmware certificate from today could be used to compromise millions of devices post-Q-Day.
Google Quantum AI, IBM, and major national labs place a Cryptographically Relevant Quantum Computer — capable of breaking RSA-2048 and ECDSA — within this window. NIST estimates 17 years of migration runway from first FIPS publication (2024) — most organisations have already used a decade.
From assessment to certification
Click any step for detail. The full workflow completes in under 15 minutes.
Everything your CISO needs in one workflow
SemanticRisk™ Adaptive Framework
PQReady is built on the SemanticRisk™ adaptive framework — a continuously evolving risk methodology designed to move with the threat landscape rather than lag behind it. As cryptographic standards, adversarial capabilities, and regulatory obligations change, SemanticRisk recalibrates its weighting model accordingly. Post-quantum cryptography is one of several threat dimensions it addresses today; it is built to address whatever comes next.
At its core, SemanticRisk applies a multi-dimensional, context-aware scoring model that accounts for systemic importance, supply chain position, data longevity, and cryptographic dependency depth. The result is a readiness score that reflects operational reality — not checkbox compliance. This is what underpins PQReady's Two-Clocks model: the practitioner understanding that confidentiality and trust are genuinely different risk timelines, each requiring its own measurement, its own remediation pathway, and its own certification gate.
Where PQReady and QDayRisk are in use
The organisations leading on post-quantum readiness are not waiting for mandates to arrive — they are building the capability now, while migration windows are still open and remediation costs are manageable. PQReady and QDayRisk are in active use and structured evaluation across the following sectors and regions.
- ●Financial market infrastructure and payment systems
- ●Transportation and connected infrastructure operators
- ●Federal and provincial government research programmes
- ●Cybersecurity and critical infrastructure consortia
- ●Financial services and fintech organisations
- ●Critical national infrastructure operators
- ●Regulated technology and enterprise software providers
- ●Government-affiliated digital and cyber policy programmes
Organisations that begin their cryptographic inventory today will have 18–36 months of remediation runway before mandatory deadlines close. Those that wait for a regulatory notice or a supply chain incident will face compressed timelines, elevated remediation costs, and the reputational exposure of reactive rather than proactive governance. A free PQReady assessment takes under 15 minutes and produces a board-ready CBOM and Two-Clocks readiness score — the starting point for any defensible PQC programme.
Know your quantum exposure
before your adversaries do.
The CCCS April 2026 migration plan filing deadline has already passed. NIST FIPS 203/204/205 are final law. EU CRA vulnerability reporting begins September 2026. Every week without a CBOM is a week of unquantified exposure.
