Talk To Your Vendors About Quantum Security Readiness
Last month, CISA and the G7 Cyber Security Working Group put out a call to action for post quantum readiness, listing five priorities to help with migration. It’s particularly welcome to see CISA and the working group highlight, “Integrating PQC into cybersecurity requirements and procurement processes,” as one of the priorities. At the beginning of this year, in Technology Leaders Must Work Together To Prepare For Q-Day, we emphasized the importance of adding procurement to your PQC team to engage with vendors about quantum security plans and add quantum security questions to RFPs. The sheer number of third-party dependencies in an enterprise environment means that organizations must understand how their cloud and infrastructure providers, SaaS providers, software vendors, and device vendors will help or hinder their own quantum security migration timeframes.
I am delighted to share our latest report, Assess Your Technology Vendors’ Quantum Security Readiness, that accelerates this work by mapping out key questions that organizations must ask their vendors to gain a clear picture of how far along vendors are in their own quantum security journeys. The questions cover areas such as PQC roadmap, architectural readiness, and operational impact.
A quantum security initiative’s success depends not just on vendor capability, but your adoption. Even well-designed PQC implementations will fail if PQC ready vendor products introduce excessive operational complexity, require significant infrastructure changes, or lack adequate testing and validation support. Security leaders must:
- Ask about operational impact. Learn how to enable PQC capabilities in the vendor’s products, whether hardware replacements are necessary, and whether the vendor offers any joint testing or staged rollouts.
- Measure against what good looks like. Look for vendors with a low-friction enablement plans (seamless transition or minimal configuration), strong customer control, and structured migration support.
- Watch for red flags. Vendors that have hidden hardware dependencies, make configuration difficult, or don’t support collaborative testing should be flagged for additional discussions.
For a breakdown of the different areas of focus and key questions, you can read the full report now. Also, please join me in Washington DC on November 9-10 for Forrester’s Security & Risk Forum. On the afternoon of the 9th, I will be leading a deep dive, Kick Off Your Quantum Security Migration Journey, with a discussion around building your team, overcoming objections, and assessing vendor readiness.