A structured, auditable checklist mapped to NIST IR 8547, NSM-10, and the QCI-QS1 standard. Use it for board reporting, vendor due diligence, and pre-audit preparation.
Establish board-level ownership of post-quantum risk before any technical work begins.
You cannot migrate what you cannot see. A complete CBOM is a hard ceiling on the Q-Risk Score.
The operational capacity to swap algorithms without rebuilding infrastructure.
Alignment with NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA).
Third-party cryptography is your cryptography. Contracts must enforce migration timelines.
Plan for the day a cryptographic primitive is broken — not the day after.
Defensible board attestation. Continue quarterly CBOM refresh and vendor enforcement.
Foundational controls exist. Close CBOM and crypto-agility gaps before the next audit cycle.
Material exposure. Likely audit finding under NIST IR 8547 alignment in 2025–2026.
Board attestation is not defensible. Commission a formal Q-Risk Assessment immediately.
The full Q-Risk Assessment produces a benchmarked score, a 36-month roadmap, and a board-ready attestation document mapped to QCI-QS1 Clauses 4–8.
The formula and hard ceilings behind every score.
How to build the inventory that anchors every checklist item.
The 2025–2035 timeline your checklist must align to.
Why agility is a hard-ceiling dimension in QCI-QS1.
The full clause-by-clause standard this checklist maps to.
The threat model that makes this checklist urgent.