CTO checklist

PQC Migration Checklist for CTOs

A board-ready post-quantum cryptography checklist for moving from awareness to action: external readiness, cryptographic inventory, supplier evidence, pilot systems, digital signatures and governance.

Updated: 19 June 2026|13 min read
0-30 days

Create the baseline

  • -Run external scans for public websites, APIs, VPN portals and customer login endpoints.
  • -Identify which teams and suppliers operate TLS, certificates, gateways, identity and signing keys.
  • -Agree who owns the cryptographic inventory and migration backlog.
30-90 days

Build the inventory

  • -Record public-key cryptography across TLS, mTLS, VPNs, SSH, certificates, SSO, code signing and document signing.
  • -Rank systems by data lifetime, capture exposure, customer impact and regulatory relevance.
  • -Ask strategic suppliers for NIST FIPS 203, 204 and 205 roadmaps.
90-180 days

Choose pilots

  • -Pilot hybrid ML-KEM transport where CDN, gateway or TLS stack support is mature.
  • -Test ML-DSA or SLH-DSA in non-production signing workflows.
  • -Measure compatibility, monitoring, certificate lifecycle and incident-response impact.
6-18 months

Scale governance

  • -Update architecture review, procurement and supplier due-diligence templates.
  • -Add crypto-agility requirements to new systems and major renewals.
  • -Track migration progress with board-level metrics and named owners.

The CTO Decision Problem

The hard part of PQC migration is not knowing that RSA and elliptic-curve cryptography are exposed to future quantum computers. The hard part is finding where those algorithms sit across products, suppliers, customer paths and signing systems.

A CTO needs a migration programme that survives budget cycles: visible evidence, a maintained inventory, supplier commitments, pilot results and governance rules that stop new systems from adding fresh migration debt.

The external website scan is the fastest first signal. The inventory is the control point. Supplier evidence and pilots turn the inventory into a roadmap.

Board Metrics That Work

Inventory coverage

Percentage of priority systems with known cryptographic dependencies.

Long-lived data coverage

Percentage of sensitive data flows ranked by confidentiality lifetime.

Supplier evidence

Critical suppliers with documented PQC roadmap and algorithm support.

Pilot progress

Systems tested with hybrid key exchange or post-quantum signatures.

Blocked systems

Systems blocked by client compatibility, legacy hardware, firmware or contracts.

External readiness

Public endpoints with current TLS baseline and saved scan evidence.

Where to Pilot First

Start where rollback is possible and measurement is clear. Public TLS behind a CDN or gateway is often a better pilot than a high-volume signing workflow because compatibility issues can be detected quickly.

Treat digital signatures separately. Code signing, firmware signing, legal documents, certificates and audit archives can have long verification lifetimes. Those workflows need non-production testing before any production commitment.

Primary References

CTO PQC FAQ

What should a CTO do first for PQC migration?

Start with externally visible systems and a cryptographic inventory. The first objective is not algorithm replacement; it is knowing where quantum-vulnerable public-key cryptography is used and who owns each dependency.

Which PQC workstream should start first?

Transport pilots are often the easiest first workstream because CDNs, browsers and TLS vendors are already testing hybrid ML-KEM. Digital signatures should be planned separately because verification and archive lifetimes are harder.

How should CTOs report PQC progress to the board?

Use simple operational metrics: inventory coverage, supplier evidence, long-lived data coverage, pilot progress, blocked systems and externally visible readiness.

Start With Evidence, Not Theory

Run the external scan, save the result in a free account and use the inventory template to turn that evidence into a migration backlog.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.