← Back to Blog

HNDL Threat Modeling for Enterprise Security Teams: Post Quantum Cryptography Roadmap

HNDL Threat Modeling for Enterprise Security Teams: Post Quantum Cryptography Roadmap - QNSQY post-quantum encryption guide

Framing HNDL for the Board

Enterprise security teams need to explain Harvest Now Decrypt Later to non-technical leadership. The frame: encrypted data transmitted today is at risk of future decryption by a Cryptographically Relevant Quantum Computer (CRQC). The risk is non-zero now and grows each day migration is delayed.

Asset-Class Risk Matrix

Asset classConfidentiality lifetime (X)CRQC horizon (Z)X + Y > Z if Y=3 yrs?
Customer PII7-25 yrs (varies)10-20 yrsUsually yes
Financial records7+ yrs10-20 yrsBorderline
IP/trade secrets10-30+ yrs10-20 yrsYes
Health records50+ yrs10-20 yrsClearly yes
Source code5-15 yrs10-20 yrsBorderline
Legal/privilegedIndefinite10-20 yrsYes
Strategy docs5-10 yrs10-20 yrsSometimes

The CISO Playbook

  1. Appoint a PQC lead reporting to CISO.
  2. Inventory: identify where classical KEM/signature/KDF are used.
  3. Classify data by confidentiality lifetime and Mosca score.
  4. Prioritize: long-lived data first.
  5. Pilot: deploy hybrid ML-KEM in one production system (new TLS, new backups).
  6. Scale: expand via PQC-aware tooling and vendor agreements.
  7. Measure: track PQC coverage as a KPI. Report quarterly.

Vendor Risk

Ask every vendor:

  • Do you use NIST FIPS 203/204/205 algorithms?
  • Is your default TLS hybrid?
  • Do you offer PQC KMS options?
  • What is your target date for full PQC coverage?

Alignment with NIST IR 8547

NIST IR 8547 (November 2024 draft) proposes deprecating classical algorithms by 2035 and disallowing them thereafter for federal use. Private-sector operators can treat this as a de facto industry timeline.

Frequently Asked Questions

How should a CISO prioritize PQC migration?

By data-confidentiality lifetime. Start with the longest-lived, highest-value data assets (IP, healthcare, financial, legal). Deploy hybrid ML-KEM on those systems first.

How long should migration take?

For a typical enterprise, 3-5 years including inventory, pilot, scale, and validation. Very large enterprises may need 5-10 years.

What is the risk if we do nothing?

Every day of classical traffic continues to populate adversary archives. When CRQC arrives, retroactive decryption of that archive is not preventable. The defense must be in place before traffic transits.

Should we require PQC from vendors?

Yes, through contractual PQC roadmap requirements. Target end-to-end PQC coverage across the vendor stack by 2030-2032, with CNSA 2.0-aligned deadlines for NSS-adjacent work.

Sources

  1. NIST IR 8547
  2. NSA/CISA/NIST Factsheet

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY

Originally published at quantumsequrity.com/blog/hndl-enterprise-threat-model.