This week’s blog is focused on how many feel about post quantum cryptography – confused! The field is genuinely new and moving fast. There is money on the table right now, and that means marketing departments, not just engineering teams, are shaping how you hear about PQC. When you add the amount of investment dollars going into quantum and PQC, there is a huge pressure to sell and make quotas. I want people to feel educated. So, where do you go?
Here’s my full disclosure, and I’ll say it with a smile: of course I want you to come talk to me about this. I like helping people work through technology problems, especially the hard ones. But I will also say to not stop at me, or at any single source, vendor, or video. I will help you meet your goals by helping you navigate the ecosystem.
Start with what you can verify yourself
Before you evaluate anyone else’s claims, take inventory of what you actually have. This isn’t new advice, it’s the same first step from earlier in this series. But it matters here for a specific reason: once you know your own environment, you can tell the difference between a vendor who’s describing your actual risk and one who’s describing a hypothetical risk that might correlate to their product.
Then have a direct conversation with your current vendors about how they’re implementing PQC. Ask specifics. What algorithms, what timeline, what’s already shipped versus roadmap. That conversation does two things at once: it gives you real information, and it takes work off your plate, because your vendors are already doing implementations you will not need to duplicate.
The claims that should make you walk away
From my years on the offensive side, I learned something that applies directly here: trusting a single entity for your security creates exactly the blind spot an adversary loves! The same logic applies to who you trust for PQC guidance.
So, a few claims that should send you looking elsewhere:
- Anyone who says they can do it all. Nobody can.
- Anyone who says they’ve already solved the whole problem. The standards are still evolving, nobody has this fully solved, and every environment has nuances.
- Anyone who claims full clarity right now on exactly what crypto agility will look like for your organization long term. That clarity doesn’t exist yet for anyone.
The people worth trusting are the ones who stay in the environment with you. Not a single assessment and a handoff, but ongoing engagement as things change, because things will change. I’ve watched crypto modernization efforts before, and the honest lesson from history is that some things get better and some things get worse along the way. You want a partner who solves problems as they come up without running up your budget every time something shifts. That’s a different skill than selling you a solution once.
I’ll say this plainly: I’m willing to help you work through whatever obstacles come up, in whatever way is useful. That offer isn’t the marketing version of the claims above; it’s the actual point of this series.
Where to actually go to learn
A few places I’d point you, beyond any one vendor or any one consultant:
- NIST’s finalized post quantum standards, FIPS 203, 204, and 205, cover key exchange and digital signatures and are the technical foundation everything else builds on.
- The joint CISA, NSA, and NIST guidance, “Quantum Readiness: Migration to Post Quantum Cryptography,” is a solid, vendor neutral starting point for planning.
- NSA’s CNSA 2.0 suite, if you’re anywhere near national security systems, sets the specific algorithm requirements for that space.
And two resources I have a direct hand in, so take them for what that’s worth: I edited “Post-Quantum Leadership: Knowledge and Practical Perspectives on Post-Quantum Readiness,” which brings together practical perspectives from people actually doing this work. And I developed course content on PQC awareness, aimed at building PQC literacy before people are staring down a vendor contract with no way to evaluate it.
Read broadly. Ask hard questions. And if someone tells you they’re your one stop shop for all of it, that’s your cue to ask who else they’d recommend you talk to. The good ones will have an answer.