PQReady
NIST FIPS 203 · ML-KEM NIST FIPS 204 · ML-DSA NIST FIPS 205 · SLH-DSA CCCS ITSM.40.001 · 2031 deadline NSA CNSA 2.0 · 2030–2033 EU CRA 2024/2847 · Dec 2027 NCSC CAF v4.0 OWASP CycloneDX 1.6 CBOM ISO/SAE 21434 · Automotive OSFI B-13 · Jan 2024
NIST FIPS 203/204/205 — Live as of August 2024

Is your organisation
quantum-ready?

Adversaries are harvesting your encrypted data today to decrypt once quantum computers mature — the Harvest Now, Decrypt Later threat is active, not hypothetical. NIST estimates a Cryptographically Relevant Quantum Computer (CRQC) arrives between 2029 and 2033.

PQReady gives your CISO a cryptographic bill of materials (CBOM), a Two-Clocks readiness score calibrated to NIST FIPS 203/204/205 and NSA CNSA 2.0, a verifiable public certification, and a targeted remediation pathway — in a single workflow.

✓ Free assessment — no card required✓ NIST FIPS 203/204/205 aligned✓ CBOM + SBOM ingestion✓ Regulatory mapping for 11 sectors
Two-Clocks Live Demo
Confidentiality
42/100
18 pts needed
Trust / Auth
10/100
50 pts needed
Before PQReady
Live simulation — your actual scores depend on your CBOM
Mapped to regulatory frameworks in 22 jurisdictions
NIST FIPS 203/204/205Aug 2024 · ML-KEM, ML-DSA, SLH-DSA
NSA CNSA 2.02030–2033 · National Security Systems
CCCS ITSM.40.001Canada · 2031 mandatory deadline
EU CRA 2024/2847Dec 2027 · Products with digital elements
OSFI B-13Canada FSI · Jan 2024
NCSC CAF v4.0UK · Critical national infrastructure
OWASP CycloneDX 1.6CBOM standard · OMB M-23-02
ISO/SAE 21434Automotive cybersecurity lifecycle
EU DORAFinancial sector operational resilience
NIS2 DirectiveEU · Critical infrastructure operators
The quantum threat is not a future problem

Two threats. Different timelines.
One platform to address both.

PQReady's Two-Clocks model is the only methodology that treats confidentiality and trust as separate, independently scored risks — because they are. HNDL attacks are active today. PKI and signature migrations require years of lead time.

HNDL
Harvest Now, Decrypt Later

Active threat. Adversaries are intercepting and storing encrypted communications today — TLS sessions, VPN tunnels, API calls — to decrypt once a CRQC becomes available. Long-lived data (health records, legal documents, financial transactions) is already at risk.

Active threat today
Source: CISA SHRINK THE ATTACK SURFACE, 2024; NIST IR 8547
HNFL
Harvest Now, Forge Later

Digital signatures — PKI certificates, firmware signing, code integrity, authentication — can be retrospectively forged once RSA and ECDSA are broken. A forged firmware certificate from today could be used to compromise millions of devices post-Q-Day.

Planning horizon: 2030–2033
Source: NSA CNSA 2.0, 2022; ENISA PQC Report, 2024
CRQC WINDOW
2029–2033 Consensus Window

Google Quantum AI, IBM, and major national labs place a Cryptographically Relevant Quantum Computer — capable of breaking RSA-2048 and ECDSA — within this window. NIST estimates 17 years of migration runway from first FIPS publication (2024) — most organisations have already used a decade.

Migration deadline: 2031 (CCCS)
Source: NIST IR 8547, 2024; CCCS ITSM.40.001, 2025
How it works

From assessment to certification

Click any step for detail. The full workflow completes in under 15 minutes.

Step 1
Cryptographic Asset Discovery
Complete a 6-step organisation profile. Answer questions about your algorithms, deployment environment, supply chain role, and key management maturity.
Step 2
Two-Clocks Readiness Scoring
Your CBOM feeds PQReady's SemanticRisk Two-Clocks engine — separate scores for Confidentiality and Trust/Authentication, calibrated to NIST FIPS 203/204/205 and NSA CNSA 2.0.
Step 3
Regulatory Pathway Mapping
Your scores are mapped against 71 regulations across 22 jurisdictions — automatically identifying your compliance obligations, upcoming deadlines, and migration priorities.
Step 4
Gap Remediation Guidance
PQReady identifies exactly which algorithms are blocking your certification and names the NIST-standardised replacements — with CNSA 2.0 deadline countdowns and QDayRisk integration for deeper migration planning.
Step 5
Verifiable Public Certification
When both clocks clear the threshold, apply for your PQReady badge — a verifiable, public-registry listing that demonstrates your organisation has achieved minimum PQC readiness standards.
2029–2033
Q-Day consensus window
The window in which a Cryptographically Relevant Quantum Computer is expected to break RSA-2048 and ECDSA.
Source: Google Quantum AI; NIST IR 8547, 2024
2031
CCCS mandatory migration deadline
High-priority Canadian government systems must complete PQC migration. April 2026 plan filing deadline has passed.
Source: CCCS ITSM.40.001, June 2025
Dec 2027
EU CRA full compliance
Products with digital elements sold in the EU must comply with Regulation (EU) 2024/2847. Fines up to €15M or 2.5% of global turnover.
Source: EU CRA 2024/2847, Official Journal of the EU
€15M
Maximum EU CRA fine
Or 2.5% of global annual turnover — whichever is higher. Vulnerability reporting obligations begin September 2026.
Source: EU CRA 2024/2847, Art. 64
Platform capabilities

Everything your CISO needs in one workflow

OWASP CycloneDX 1.6
CBOM Generation
Automated Cryptographic Bill of Materials across your PKI, TLS, firmware signing, and API authentication layers. Exports in CycloneDX 1.6 JSON — the NIST-recommended format per OMB M-23-02.
CycloneDX · SPDX
SBOM & CBOM Ingestion
Upload your existing Software or Cryptographic Bill of Materials. PQReady parses for crypto-library signatures and feeds SBOM maturity into scoring — no need to rebuild what you already have.
NIST FIPS 203/204/205
Two-Clocks Certification
Separate Confidentiality and Trust/Authentication readiness scores. Both must clear 60/100 for certification. Calibrated to NSA CNSA 2.0 deadlines and supply chain role (End User, Integrator, OEM, Critical Vendor).
71 regulations · 22 jurisdictions
Regulatory Mapping
Automated compliance gap analysis across NIST, CCCS, NSA CNSA 2.0, EU CRA, EU DORA, OSFI B-13, NCSC CAF, NIS2, ISO/SAE 21434, NYDFS, and 60+ additional frameworks.
Public registry
Verifiable Certification
Server-side score recomputation — client-submitted scores are never trusted. Your badge appears in the public PQReady Registry, verifiable by regulators, auditors, and supply chain partners.
QDayRisk SSO
QDayRisk Integration
QDayRisk assessment data flows directly into PQReady via Portal SSO. No double data entry. Gap remediation CTAs link back to QDayRisk for algorithm inventory updates — then return here to re-evaluate.
Methodology

SemanticRisk™ Adaptive Framework

PQReady is built on the SemanticRisk™ adaptive framework — a continuously evolving risk methodology designed to move with the threat landscape rather than lag behind it. As cryptographic standards, adversarial capabilities, and regulatory obligations change, SemanticRisk recalibrates its weighting model accordingly. Post-quantum cryptography is one of several threat dimensions it addresses today; it is built to address whatever comes next.

At its core, SemanticRisk applies a multi-dimensional, context-aware scoring model that accounts for systemic importance, supply chain position, data longevity, and cryptographic dependency depth. The result is a readiness score that reflects operational reality — not checkbox compliance. This is what underpins PQReady's Two-Clocks model: the practitioner understanding that confidentiality and trust are genuinely different risk timelines, each requiring its own measurement, its own remediation pathway, and its own certification gate.

Grounded in systems thinking methodologyCalibrated to NIST · CCCS · NSA CNSA 2.0Continuously updated as standards evolveApplicable across sectors and jurisdictions
Regulatory frameworks mapped
71
across 22 jurisdictions
Sector coverage
11
transportation, FSI, energy, defence, health...
SIFI-weighted scoring
Yes
FSB/OSFI systemic importance calibration
Standards alignment
NIST · CCCS · NSA · ENISA · OWASP
Sector & Regional Adoption

Where PQReady and QDayRisk are in use

The organisations leading on post-quantum readiness are not waiting for mandates to arrive — they are building the capability now, while migration windows are still open and remediation costs are manageable. PQReady and QDayRisk are in active use and structured evaluation across the following sectors and regions.

North America
  • Financial market infrastructure and payment systems
  • Transportation and connected infrastructure operators
  • Federal and provincial government research programmes
  • Cybersecurity and critical infrastructure consortia
Driven by CCCS ITSM.40.001 (2031), NSA CNSA 2.0 (2030–2033), OSFI B-13, and SEC Cybersecurity Disclosure Rules.
United Kingdom & Europe
  • Financial services and fintech organisations
  • Critical national infrastructure operators
  • Regulated technology and enterprise software providers
  • Government-affiliated digital and cyber policy programmes
Driven by EU CRA 2024/2847 (Dec 2027), EU DORA, NIS2, and NCSC CAF v4.0 obligations.
Why act now — not when the mandate arrives

Organisations that begin their cryptographic inventory today will have 18–36 months of remediation runway before mandatory deadlines close. Those that wait for a regulatory notice or a supply chain incident will face compressed timelines, elevated remediation costs, and the reputational exposure of reactive rather than proactive governance. A free PQReady assessment takes under 15 minutes and produces a board-ready CBOM and Two-Clocks readiness score — the starting point for any defensible PQC programme.

Sector descriptors only. Organisation names available to verified partners under NDA. Contact customersuccess@netrascale.com for reference access.
Get started — free, no card required

Know your quantum exposure
before your adversaries do.

The CCCS April 2026 migration plan filing deadline has already passed. NIST FIPS 203/204/205 are final law. EU CRA vulnerability reporting begins September 2026. Every week without a CBOM is a week of unquantified exposure.

Get My Free CBOM & Score View Certified Registry
✓ Free assessment  ·  ✓ No card required  ·  ✓ NIST FIPS 203/204/205 aligned  ·  ✓ Results in under 15 minutes