PQC Readiness Assessment · Singapore

Your encrypted traffic is safe today.
That is the whole problem.

Everything moving across this page is protected by cryptography that works. RSA and elliptic curve are doing their job right now, this second. The difficulty is that "right now" is not the standard your data is held to — the standard is how long it has to stay secret.

The service
QuintessenceLabs PQC Readiness Assessment
The date in front of you
31 March 2027
Brought to Singapore by
Straits Cipher

Harvest now, decrypt later01

Nothing has to be broken today for you to lose it later.

An adversary does not need to defeat your encryption. They only need to keep a copy and wait. Sensitive data intercepted today stays vulnerable long after it was collected, because the key that opens it may not exist yet.

Watch the stream. A share of it is being copied as it passes, and the copy sinks into an archive that never shrinks. Nobody gets an alert. Nothing looks wrong.

Cost to the adversary
Storage
Cost to you
Everything with a long shelf life

Shadow cryptography02

You cannot migrate what you cannot see.

Most organisations cannot answer the basic questions: where is cryptography used across the enterprise, which systems rely on RSA and ECC, which assets carry the greatest exposure, and how complex would a migration actually be.

The lit packets are the ones running vulnerable algorithms. In a real estate they are spread across cloud, on-premises, IoT and HSMs — and almost none of them are on anybody's list. The hard part was never the new algorithm. It is finding what you already run.

The blind spot
Not a future problem
Status
Happening right now

Singapore has put dates on it03

The direction is set, and it is dated.

On 16 July 2026 the Cyber Security Agency published the Quantum-Safe Migration Handbook with GovTech and IMDA. It sets three milestones for Critical Information Infrastructure owners: a quantum-safe migration plan submitted to CSA by 31 March 2027, newly procured CII systems supporting quantum-safe algorithms or quantum-safe ready from 1 January 2028, and migration complete — no vulnerable cryptography in use — by 31 December 2031.

The Handbook is framed as guidance. It states that it is not mandatory or prescriptive, and the milestones use should; binding obligations under the Cybersecurity Act flow through Codes of Practice or written directions. CII designation applies per system, not per organisation. The dates are specific enough that most CII owners are already scoping the inventory work behind them — and the 2027 plan is a document you cannot write without an inventory.

Set your own three dials04

Not all data is equal. Three questions decide the order.

A plan that says migrate everything is not a plan. QuintessenceLabs ranks assets on three properties — and you already know the answers for your most important system.

How long must the data stay secret?

Data longevity. Anything with a multi-year confidentiality requirement is already exposed to harvest-now-decrypt-later.

How vital is the system to operations?

Business criticality. Revenue systems, statutory registers and anything designated critical information infrastructure sit at the top.

How easily can the algorithm be swapped?

Migration complexity. Embedded, vendor-locked and certificate-pinned systems are the ones that need lead time.

How the assessment runs05

Six stages, and then it goes round again.

Discover, inventory, assess, govern, remediate, verify. Verify feeds a re-scan against the same policy or an updated one, and the loop repeats — which is the difference between a migration project that ends and crypto-agility that keeps working the next time the standards move.

Platform
TSF® Sentry
Output
CBOM · risk score · policy

What you actually get06

Four documents you can take to a board.

Audit-ready assessment report

Prioritised vulnerability mapping and threat exposure, in a form a governance body can read.

Cryptographic Bill of Materials

Visibility into cryptographic applications, algorithms and dependencies across the estate.

Remediation plan

An actionable roadmap that shows tangible progress against something.

Crypto-agility strategy

How to make the next transition without the same disruption.

The focus is deliberately not a massively inflated CBOM. It is a prioritised list of what to fix, in what order, that can be automated immediately.

How it is delivered07

Three phases of workshops.

Phase 1 · Discovery & inventory

Full cryptographic discovery, risk scoring and gap analysis, and identification of the high-risk, high-value assets.

Phase 2 · Risk assessment & strategy

A prioritised migration roadmap, selection of NIST-standardised PQC algorithms, and the design of a crypto-agility framework.

Phase 3 · Roadmap & remediation

Phased rollout of PQC protocols, interoperability and performance testing, then final validation and hardening.

What it costs you to find out08

Nothing is installed on your hosts.

Discovery is a network-based scan of a scope you agree in advance. No agents. The inventory it produces is metadata only — algorithms, keys and dependencies, never the data those keys protect.

That matters more in Singapore than almost anywhere, because it is the difference between a short security review and a long one. You can find out how exposed you are without changing anything.

Agents installed
None
Payload captured
None
Scope
Agreed before the scan

Take it to your team

The whole method, in four pages.

The QuintessenceLabs PQC Readiness Assessment brief sets out the six-stage cycle, the deliverables, the workshop phases and the platform behind them — the shape of work the 31 March 2027 plan implies. Tell us where to send it and it downloads immediately.

The milestone
31 March 2027
What it asks for
A migration plan
What that needs first
A cryptographic inventory

Where this lands first

Three ways the same date arrives.

Government & regulated CII

31 March 2027. CSA's Handbook asks CII owners for a quantum-safe migration plan. The plan is a document. The cryptographic inventory behind it is the work, and it is the part with the lead time.

Financial services

One programme, not two. MAS has had quantum risk on the practical agenda since its February 2024 advisory — maintain a cryptographic inventory, assess supply-chain exposure. For an institution running designated CII systems, the CII milestones and the MAS expectations converge. The first useful move is an inventory and a view of key custody, not a QKD purchase.

Telco, OT & long-lived infrastructure

1 January 2028. Newly procured CII systems should support quantum-safe algorithms or be quantum-safe ready. If your OT interconnects, control systems or long-lived key infrastructure sit in that scope, the procurement decisions being made now are the ones that decide 2028.

CII designation applies per system, not per organisation. If you are not sure which of yours are in scope, that uncertainty is itself the finding an inventory removes.

PQC Readiness Assessment

A risk-based blueprint for your PQC transition. Four pages covering the discovery method, the cryptographic bill of materials, risk-based prioritisation and the crypto-agility framework.

  • The six-stage cycle, with the outcome of each stage
  • What the assessment produces, and who it is written for
  • The three workshop phases
  • TSF® Sentry — the discovery and crypto-agility platform behind it

Published by Straits Cipher. QuintessenceLabs®, TSF® and TSF® Sentry are trademarks of QuintessenceLabs Pty Ltd. Your details are recorded so we can follow up, and are not sold or passed to a third party beyond QuintessenceLabs where a referral is needed.

It's yours.

The brief is ready to download. We have your details and will follow up about a scoping conversation.

Download the brief (PDF)

PQC Readiness

Opening the stream