Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do organisations need a phased approach to…
Governance, Ownership & Risk

Why do organisations need a phased approach to quantum readiness instead of waiting for standards to settle first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

A phased approach is necessary because quantum risk affects long-lived cryptography, governance, and upgrade planning at the same time. Organisations should start by inventorying where encryption is used, updating security policy, and building a transition plan that can adapt as standards mature. Waiting increases the chance that critical systems will remain tied to algorithms that may become obsolete.

Why quantum readiness has to start before the standards are finished

A phased approach works because the risk is already present in the systems and data you use today, while the exact migration path will continue to evolve. The practical issue is not waiting for a perfect final standard, it is reducing exposure now so you can move quickly when guidance hardens. That means building inventory, policy, and migration capacity in parallel rather than in sequence.

What a phased quantum readiness program actually covers

The first phase is usually discovery: where encryption is used, which data has a long confidentiality life, and which services depend on cryptographic assumptions that could be hard to replace later. The second phase is prioritisation: classify systems by exposure, business criticality, and replacement difficulty. The third phase is execution planning: define upgrade windows, dependency owners, testing needs, and decision points that can absorb future standards without restarting the program.

This is why quantum readiness is broader than a cryptography refresh. It touches security policy, asset inventory, architecture, procurement, and change management at the same time. If an organisation waits for the standard to settle before doing any of that work, it creates a longer gap between awareness and action, which is usually the most expensive point in a transition.

Current guidance on long-term cryptographic migration also points to the value of inventory and agility as separate workstreams. The NIST SP 800-53 Rev 5 Security and Privacy Controls supports this kind of planning through configuration management, system integrity, and access controls, which are the control families that make later cryptographic replacement possible without losing operational control. The same logic is reinforced by the NIST Cybersecurity Framework 2.0, because governance, identify, protect, detect, respond, and recover all need to account for the transition.

Why delay creates avoidable cryptographic and operational drag

Waiting for standards to settle first usually pushes organisations into a narrower, more expensive change window. By then, the work is no longer just “choose an algorithm”, it becomes “replace dependencies, test integrations, reissue keys or certificates where needed, and prove the new design still meets uptime and compliance expectations”. That is why phased readiness is an operational resilience issue as much as a cryptography issue.

The main failure mode is path dependency. Systems built today with weak inventory, undocumented cryptographic use, or hard-coded assumptions become harder to update later, even if the eventual standard is straightforward. The result is not only technical debt, but also governance debt: no clear owner, no approved migration sequence, and no reliable answer to which environments are exposed first. For organisations with external assurance obligations, that delay can also complicate audit evidence and control testing.

Risk and Threat Considerations

Quantum readiness carries risk because exposure accumulates before standards are final. Long-lived data, infrastructure certificates, embedded libraries, and third-party integrations can all remain tied to cryptographic choices that become difficult to retire on schedule.

Failure mechanism: Organisations defer inventory and transition planning, so critical systems remain anchored to legacy cryptography until replacement becomes urgent and disruptive.

Impact: The result is larger migration cost, more brittle cutovers, and a greater chance that sensitive systems will outlive the cryptographic assumptions they were built on.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyQuantum migration is a risk-managed transition that needs prioritization and planning.
ID.AM-01 — Physical Devices and Systems InventoryA phased quantum plan starts by inventorying where cryptography is used.
GV.PO-01 — PolicyPolicy must evolve before the technical standard is final to guide later upgrades.
Recommendation — Define a risk strategy for cryptographic transition and sequence high-exposure systems first. Inventory cryptographic dependencies so migration scope is visible before standards settle. Update policy to require crypto agility and migration planning now.
NIST SP 800-53 Rev 5CM-2 — Baseline ConfigurationCryptographic agility depends on controlled baselines and managed change.
CM-6 — Configuration SettingsCrypto settings and libraries need reviewable configuration to support later replacement.
SA-10 — Developer Configuration ManagementTransition planning spans software dependencies and future algorithm updates.
Recommendation — Maintain controlled baselines so cryptographic components can be updated predictably. Standardize and document crypto configuration so replacements are tractable. Require developers and vendors to support crypto changeability in delivered systems.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsAsset inventory is the first step in finding long-lived cryptographic exposure.
A.8.24 — Use of cryptographyQuantum readiness directly affects cryptographic control selection and migration.
Recommendation — Maintain an asset inventory that includes cryptographic dependencies and trust anchors. Review cryptographic use so migration paths can be planned before algorithm obsolescence.

Practitioner Guidance

What to prioritise: Start with a cryptographic inventory that identifies where encryption, signing, and trust anchors are used, then rank those dependencies by data lifetime and change difficulty. That gives you a defensible order of attack instead of a generic “post-quantum” project plan.

What to verify: Check whether policy, procurement, and architecture standards already require crypto agility, algorithm substitution, and owner-based remediation tracking. If those controls do not exist, the readiness problem is organisational, not just technical.

Practitioner takeaway: The right question is not whether the final standard is ready today, but whether your environment can absorb the eventual change without a high-risk scramble. Phased readiness is what turns an uncertain future standard into a manageable migration path.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org