A practical starting point for examining post-quantum preparedness across portfolio businesses and acquisition targets.
How to use this checklist
Review the six areas with the business’s technology and risk owners. Adapt the depth of investigation to its systems, sector and investment context.
For each answer, record the evidence, its date and scope, outstanding questions, and the owner of the next action. This is a discussion guide, not a scoring system.
For competitor research, use lawfully available public information and record what has not been disclosed. A lack of public evidence does not establish a lack of preparedness.
1. Sensitive information
What information needs protection, and for how long?
Which information is commercially sensitive or subject to confidentiality obligations?
How long must it remain confidential, including after an investment exit?
Who owns the assessment of its sensitivity and protection needs?
Evidence to request
Data classification and retention policies; a dated assessment of confidentiality lifetimes; named information owners.
2. Critical systems and products
Which services matter most to business continuity and customer delivery?
Which internal systems and customer products are business-critical?
Where are bespoke, legacy or long-lived systems used?
Which services are operated internally, in the cloud or by third parties?
Evidence to request
A service and system map showing criticality, owners, versions where available, support lifetimes and operational dependencies.
3. Cryptographic dependencies
What does the business know about the cryptography its systems depend on?
Has discovery work identified where cryptography is used?
Does the review cover confidentiality, identity, certificates and software signing where relevant?
Which dependencies remain unknown or require specialist investigation?
Evidence to request
Dated discovery findings, coverage and exclusions; relevant architecture documentation; a record of gaps and their owners.
4. Accountability and planning
Who is responsible for making and delivering migration decisions?
Is there a named business sponsor and technical lead?
Is there an approved plan with priorities, milestones and review dates?
How are uncertainties and outstanding decisions escalated?
Evidence to request
Assigned responsibilities; the current migration plan and risk register; records of management review and approval.
5. Supplier preparedness
What do key suppliers support, and what must the customer do?
Are answers specific to the product, version and deployment?
Are production capabilities distinguished from previews and roadmap plans?
Are exclusions, external dependencies and customer actions documented?
Evidence to request
Dated supplier responses, technical documentation, release notes and product roadmaps, with unresolved questions recorded.