PQC Readiness Assessment · Singapore
Your encrypted traffic is safe today.
That is the whole problem.
Everything moving across this page is protected by cryptography that works. RSA and elliptic curve are doing their job right now, this second. The difficulty is that "right now" is not the standard your data is held to — the standard is how long it has to stay secret.
Harvest now, decrypt later01
Nothing has to be broken today for you to lose it later.
An adversary does not need to defeat your encryption. They only need to keep a copy and wait. Sensitive data intercepted today stays vulnerable long after it was collected, because the key that opens it may not exist yet.
Watch the stream. A share of it is being copied as it passes, and the copy sinks into an archive that never shrinks. Nobody gets an alert. Nothing looks wrong.
Shadow cryptography02
You cannot migrate what you cannot see.
Most organisations cannot answer the basic questions: where is cryptography used across the enterprise, which systems rely on RSA and ECC, which assets carry the greatest exposure, and how complex would a migration actually be.
The lit packets are the ones running vulnerable algorithms. In a real estate they are spread across cloud, on-premises, IoT and HSMs — and almost none of them are on anybody's list. The hard part was never the new algorithm. It is finding what you already run.
Singapore has put dates on it03
The direction is set, and it is dated.
On 16 July 2026 the Cyber Security Agency published the Quantum-Safe Migration Handbook with GovTech and IMDA. It sets three milestones for Critical Information Infrastructure owners: a quantum-safe migration plan submitted to CSA by 31 March 2027, newly procured CII systems supporting quantum-safe algorithms or quantum-safe ready from 1 January 2028, and migration complete — no vulnerable cryptography in use — by 31 December 2031.
The Handbook is framed as guidance. It states that it is not mandatory or prescriptive, and the milestones use should; binding obligations under the Cybersecurity Act flow through Codes of Practice or written directions. CII designation applies per system, not per organisation. The dates are specific enough that most CII owners are already scoping the inventory work behind them — and the 2027 plan is a document you cannot write without an inventory.
Set your own three dials04
Not all data is equal. Three questions decide the order.
A plan that says migrate everything is not a plan. QuintessenceLabs ranks assets on three properties — and you already know the answers for your most important system.
How long must the data stay secret?
Data longevity. Anything with a multi-year confidentiality requirement is already exposed to harvest-now-decrypt-later.
How vital is the system to operations?
Business criticality. Revenue systems, statutory registers and anything designated critical information infrastructure sit at the top.
How easily can the algorithm be swapped?
Migration complexity. Embedded, vendor-locked and certificate-pinned systems are the ones that need lead time.
How the assessment runs05
Six stages, and then it goes round again.
Discover, inventory, assess, govern, remediate, verify. Verify feeds a re-scan against the same policy or an updated one, and the loop repeats — which is the difference between a migration project that ends and crypto-agility that keeps working the next time the standards move.
What you actually get06
Four documents you can take to a board.
Prioritised vulnerability mapping and threat exposure, in a form a governance body can read.
Visibility into cryptographic applications, algorithms and dependencies across the estate.
An actionable roadmap that shows tangible progress against something.
How to make the next transition without the same disruption.
The focus is deliberately not a massively inflated CBOM. It is a prioritised list of what to fix, in what order, that can be automated immediately.
How it is delivered07
Three phases of workshops.
Full cryptographic discovery, risk scoring and gap analysis, and identification of the high-risk, high-value assets.
A prioritised migration roadmap, selection of NIST-standardised PQC algorithms, and the design of a crypto-agility framework.
Phased rollout of PQC protocols, interoperability and performance testing, then final validation and hardening.
What it costs you to find out08
Nothing is installed on your hosts.
Discovery is a network-based scan of a scope you agree in advance. No agents. The inventory it produces is metadata only — algorithms, keys and dependencies, never the data those keys protect.
That matters more in Singapore than almost anywhere, because it is the difference between a short security review and a long one. You can find out how exposed you are without changing anything.
Take it to your team
The whole method, in four pages.
The QuintessenceLabs PQC Readiness Assessment brief sets out the six-stage cycle, the deliverables, the workshop phases and the platform behind them — the shape of work the 31 March 2027 plan implies. Tell us where to send it and it downloads immediately.