Quantum readiness gets discussed as though the hard part were the mathematics. It isn't. The hard part is that almost no enterprise can answer a much duller question: where, exactly, is cryptography used across our interfaces?
Not the laptops and not the disk encryption — the integration estate. Every API gateway policy. Every mutual-TLS link to a partner. Every signed JWT, every SAML assertion, every SFTP key that a supplier rotated in 2019 and nobody has touched since. Every message queue with TLS pinned to a certificate whose owner has left. That inventory is the deliverable that takes months, and everything else waits on it.
The timeline pressure is also widely misread. NIST finalised its first post-quantum standards in 2024 — ML-KEM for key establishment, ML-DSA and SLH-DSA for signatures — so the algorithms are no longer the blocker. But adopting them across a B2B estate means moving counterparties you do not control, on their schedule. That is a programme with a multi-year tail, not a configuration change.
And as the diagram above shows, the clock that matters is not Q-day. It is data lifetime. Traffic copied off the wire today gets read whenever the capability arrives. If something you send this quarter must stay confidential for a decade, its exposure was decided this quarter.