PQCPrep

Investment teams · Readiness checklist

Start with questions. Build an evidence trail.

A practical starting point for examining post-quantum preparedness across portfolio businesses and acquisition targets.

How to use this checklist

Review the six areas with the business’s technology and risk owners. Adapt the depth of investigation to its systems, sector and investment context.

For each answer, record the evidence, its date and scope, outstanding questions, and the owner of the next action. This is a discussion guide, not a scoring system.

For competitor research, use lawfully available public information and record what has not been disclosed. A lack of public evidence does not establish a lack of preparedness.

1. Sensitive information

What information needs protection, and for how long?

  • Which information is commercially sensitive or subject to confidentiality obligations?
  • How long must it remain confidential, including after an investment exit?
  • Who owns the assessment of its sensitivity and protection needs?
Evidence to request

Data classification and retention policies; a dated assessment of confidentiality lifetimes; named information owners.

2. Critical systems and products

Which services matter most to business continuity and customer delivery?

  • Which internal systems and customer products are business-critical?
  • Where are bespoke, legacy or long-lived systems used?
  • Which services are operated internally, in the cloud or by third parties?
Evidence to request

A service and system map showing criticality, owners, versions where available, support lifetimes and operational dependencies.

3. Cryptographic dependencies

What does the business know about the cryptography its systems depend on?

  • Has discovery work identified where cryptography is used?
  • Does the review cover confidentiality, identity, certificates and software signing where relevant?
  • Which dependencies remain unknown or require specialist investigation?
Evidence to request

Dated discovery findings, coverage and exclusions; relevant architecture documentation; a record of gaps and their owners.

4. Accountability and planning

Who is responsible for making and delivering migration decisions?

  • Is there a named business sponsor and technical lead?
  • Is there an approved plan with priorities, milestones and review dates?
  • How are uncertainties and outstanding decisions escalated?
Evidence to request

Assigned responsibilities; the current migration plan and risk register; records of management review and approval.

5. Supplier preparedness

What do key suppliers support, and what must the customer do?

  • Are answers specific to the product, version and deployment?
  • Are production capabilities distinguished from previews and roadmap plans?
  • Are exclusions, external dependencies and customer actions documented?
Evidence to request

Dated supplier responses, technical documentation, release notes and product roadmaps, with unresolved questions recorded.

Start with the supplier email templates →

6. Costs and delivery

What resources and operational changes will the plan require?

  • What costs are expected, and which estimates remain uncertain?
  • Who will carry out implementation and technical review?
  • What testing, compatibility checks and continuity arrangements are planned?
Evidence to request

A cost estimate with assumptions; resource and dependency plans; testing, rollout and recovery arrangements; owners for unresolved delivery risks.

Turn findings into next actions

For each review area, keep a record of:

Distinguish supplier statements from independently reviewed evidence. Avoid turning unanswered questions into unsupported conclusions about overall readiness.

Supplier email templates

1. Initial enquiry — establish responsibility, capability and plans.

2. Evidence request — ask for documentation supporting the response.

3. Follow-up — clarify broad claims and outstanding questions.

Supporting guidance

This checklist is an original PQCPrep resource for investment-team discussions. It is not issued or endorsed by the NCSC.

Checklist version 1.0 · 7 October 2026