Readiness roadmap
Find out where you are — and what to do next
Every organization moves through the same stages on the way to post-quantum readiness: knowing what cryptography you run, fixing what's actually at risk, and proving it. Pick a stage below to see what's typical there and the next concrete step.
How to use this model
Don't skip stages
Buying enterprise-grade verification tooling before you have a cryptographic inventory is like installing a vault door before you know which rooms need one. Start with Assess to see what you actually run, then add Monitor and Convert once you know where the risk is. The fastest path is usually the next stage up — not the top of the model.
Which one sounds like you?
CISO / VP Security
Your board or leadership are asking how much of your traffic still relies on RSA or ECDSA before 2030.
Run a scan and bring a real inventory to that conversation.
Start with Assess →Compliance / GRC lead
You're preparing for a CMMC, PCI-DSS 4.0, or HIPAA audit and need evidence, not a spreadsheet.
Generate a signed compliance pack auditors can verify independently.
See compliance packs →VP Engineering
You've been handed the PQC migration and need to know what to fix first — and prove it stuck.
Turn your CBOM into a prioritized remediation board, then re-scan to confirm the fix held.
Explore Convert →Common questions
How long does it take to move from Stage 0 to Stage 3?
Most teams complete their first inventory (Stage 1) within a day of running a scan. Prioritizing the backlog and scheduling re-scans (Stages 2-3) typically takes two to six weeks, depending on how distributed your infrastructure is.
Do I need Monitor and Convert right away?
No — start with Assess. Monitor and Convert matter once you have a baseline and need to catch drift or prove remediation, which is usually a few weeks in, not day one.
What if I don't know my crypto inventory at all?
That's Stage 0, and it's the normal starting point. Run a free mini-assessment or a full scan — you don't need existing documentation to begin.
What actually counts as "verified" readiness?
Stage 6 means you have portfolio-wide evidence, a transparency log, and auditor-ready packs — not just that migrations happened, but that you can prove it to a third party.