Appendices & Reference 3 min read

PQC Compliance Checklist

A consolidated timeline and action checklist for PQC-related mandates. Check off items as your organization completes them.

Immediate Actions (Now)#

ActionReference
Cryptographic asset discoveryInventory all algorithms, keys, certs, and protocols. Produce CBOM. (Ch5, NIST SP 1800-38B)
Quantum risk assessmentScore all systems using Appendix D methodology. Identify P0 systems.
Establish CCOECross-functional team per Ch6 model. Assign executive sponsor.
Update cryptographic policiesIncorporate PQC requirements into procurement, development, and security policies.
Enable hybrid TLS key exchangeX25519MLKEM768 on internet-facing load balancers/CDN. (Ch7 bridge architecture)
Verify SSH key exchangeConfirm OpenSSH 10.0+ default (mlkem768x25519). Update if needed.
Begin dual-signing firmwareSign new firmware/SBOMs with both classical + ML-DSA. (CNSA 2.0 “prefer by 2025”)

2026–2027 Actions#

ActionReference
Assess HSM PQC readinessFive questions from Ch6. Plan firmware upgrades or replacements.
Pilot PQC certificatesTest ML-DSA certificates in non-production. Measure handshake performance. (Ch8)
Engage vendors on PQC roadmapsCollect PQC timelines from all critical vendors. (Appendix F template)
Evaluate Merkle Tree CertificatesTrack Chrome/Cloudflare MTC pilot (Phase 1–2). Plan for CQRS if web-facing.
Increase TCP initcwnd to 20On internet-facing VIPs/load balancers to accommodate PQC cert chains. (Ch8)
Deploy IPsec PPKsRFC 8784 post-quantum pre-shared keys on priority VPN tunnels. (Ch7)
Automate certificate lifecycleACME or vendor CLM for 200-day cert validity (CA/B Forum, March 2026).

2028–2030 Actions#

ActionReference
Complete PKI hierarchy migrationNew root/intermediate CAs with ML-DSA. Begin issuing PQC leaf certificates.
Migrate IPsec to native ML-KEMReplace PPK stopgap with CNSA 2.0 IPsec profile (ML-KEM-1024).
Re-sign legacy evidenceRe-sign critical audit logs, contracts, and firmware archives with PQC. (Ch9 Pattern 2/3)
Automate 47-day cert renewalPrepare for CA/B Forum 47-day maximum validity by March 2029.
Transition high-confidence systems to pure PQCDrop classical-only where ML-KEM/ML-DSA have 6+ years post-standardization scrutiny.

2030–2035 Actions#

ActionReference
NIST deprecation deadline (2030)All 112-bit classical algorithms deprecated. No new deployments. (NIST IR 8547)
CNSA 2.0 full compliance (2030)NSS: exclusive use of ML-KEM-1024 / ML-DSA-87 for networking.
Complete hybrid → pure PQC transitionRemove classical component from hybrid deployments where no longer needed.
NIST disallow deadline (2035)All quantum-vulnerable public-key algorithms disallowed. NSM-10 full compliance.
Validate crypto-agilityConfirm ability to swap algorithms within 30 days across the environment. (Appendix E Dim 7)

Federal Sector Additions#

Federal agencies and federal service integrators should apply the following items in addition to the timeline-based actions above. These align PQC migration activities with the existing Risk Management Framework (NIST SP 800-37 Rev 2) rather than creating a parallel compliance track.

ActionReference
Include PQC in System Security Plans (SSPs)Document PQC control selection, implementation timeline, and residual risk per NIST SP 800-37 Rev 2.
Track PQC migration in POA&MsRecord quantum-vulnerable systems and their migration milestones in the Plan of Action and Milestones for continuous monitoring.
Submit annual quantum-vulnerable IT system inventoryRequired by NSM-10 for federal agencies. (Ch 5 Note 1)
M-23-02 cryptographic inventory reportingFCEB agencies submit annual cryptographic inventory to CISA per OMB Memorandum M-23-02. (Ch 5 Note 1)
FedRAMP continuous monitoring for cloud offeringsInclude PQC posture and migration progress in FedRAMP ConMon deliverables.
Reauthorize systems after PQC migrationTreat hybrid/PQC deployment as a significant change triggering ATO reauthorization per NIST SP 800-37 Rev 2 Monitor step.
Embed PQC in procurement languageApply PQC readiness requirements to acquisition clauses. USDA/AGAR provides a model. (Ch 9 Note 9)

Appendix F#