What Customer Trust Will Look Like in the Post-Quantum Era?

For years, organisations have demonstrated cyber trust through familiar evidence: security certifications, penetration tests, privacy policies, audit reports, incident-response plans and contractual commitments.

 

Post-quantum cryptography is about to add another category.

 

Not immediately. And not because customers will suddenly expect every supplier to have replaced every cryptographic system.

 

The change is more subtle — and potentially more important.

 

Customers will increasingly want evidence that their suppliers understand their exposure to quantum-vulnerable cryptography and have a credible plan for dealing with it.

 

That turns post-quantum readiness from a specialist cryptography problem into a customer-assurance issue.

 

And for organisations handling sensitive, long-lived or regulated information, that shift has already begun.

 

 

The question is changing from “Are you secure?” to “Show us how you are preparing.”

 

In July 2026, the Australian Signals Directorate published guidance specifically titled Post-quantum questions to ask your vendors.

Its audience does not consist only of cryptographers.

 

It explicitly includes cyber leaders, procurement teams, vendor-management teams and technical stakeholders assessing third-party suppliers.

 

ASD recommends incorporating PQC considerations into procurement, contract renewal and vendor-assurance activities.

 

That is an important signal.

A customer assessing a strategic supplier may increasingly ask questions such as:

  • Do you know where public-key cryptography is used across your products and services?
  • Do you maintain an inventory of cryptographic dependencies, such as a cryptographic bill of materials?
  • Which customer data flows depend on quantum-vulnerable asymmetric cryptography?
  • Have you assessed the lifetime and sensitivity of the information you protect?
  • Which third-party products could constrain your migration?
  • Is any cryptography hard-coded, hardware-bound or difficult to replace?
  • Which post-quantum standards do you intend to support?
  • What is your transition roadmap?
  • Who owns the risk at management level?
  • How will customers be notified when cryptographic changes affect them?

 

These are remarkably different questions from:

 

“Are you quantum safe?”

 

The latter encourages a yes/no marketing answer.

 

The former requires evidence.

 

And that distinction is likely to define trust during the transition.

Customers do not need you to have finished. They need you to understand the problem.

 

There is an important message here for boards and executive teams.

 

PQC readiness should not be confused with completing a wholesale migration today.

The major cybersecurity authorities themselves describe migration as a multi-year process.

 

NIST finalised its first three principal post-quantum cryptography standards — FIPS 203, 204 and 205 — in August 2024.

 

The UK’s National Cyber Security Centre recommends that organisations complete discovery, assessment and an initial migration plan by 2028, migrate their highest-priority systems by 2031, and aim to complete migration by 2035.

 

Australia’s ASD recommends ceasing the use of traditional asymmetric cryptography by the end of 2030 in the environments covered by its guidance.

 

These are not instructions to rip and replace cryptography overnight.

 

They are instructions to know your estate, understand your risk, establish priorities and prepare a controlled transition.

 

That is also what a sophisticated customer should want to see from a supplier.

PQC readiness will become part of supplier assurance

Consider what happens when two suppliers compete for a long-term contract involving sensitive customer information.

 

Both have ISO certifications.

 

Both run penetration tests.

 

Both have security policies.

 

Both claim strong encryption.

 

But one can also provide:

  • a documented cryptographic inventory;
  • an assessment of quantum-vulnerable dependencies;
  • identification of systems protecting long-lived sensitive information;
  • a documented PQC transition strategy;
  • named executive ownership;
  • supplier and technology dependencies;
  • a testing programme;
  • and a roadmap aligned with recognised standards.

 

The other says:

“Our technology vendors will deal with quantum when necessary.”

 

Which supplier creates more confidence?

 

That is why PQC readiness could become commercially significant well before quantum computers become capable of breaking today’s widely deployed public-key cryptography.

 

The competitive issue is not only when quantum computers arrive. It is when your customers begin asking about your preparation.

 

For some sectors, that date may come considerably earlier.

Procurement could become the forcing function

Security requirements often move through markets in a predictable way.

 

A risk first appears on the radar of security specialists.

 

It moves into regulatory guidance.

 

Large organisations incorporate it into supplier questionnaires.

 

Procurement teams begin asking about it during tenders.

 

Contract clauses follow.

Eventually, what was once considered specialist practice becomes an expected element of doing business.

PQC appears to be entering that progression.

Australia’s 2026 supplier guidance is particularly significant because it recommends questions about cryptographic inventories, risk assessments, hardware dependencies, implementation plans, standards, governance and supplier communications.

 

For a supplier, waiting until these questions appear in a major tender is not an ideal way to discover that nobody inside the organisation can answer them.

The better position is to prepare the evidence before the customer asks.

Cyber insurance may follow the same logic

Cyber insurers already care about the controls and dependencies that materially affect an organisation’s exposure.

PQC-specific underwriting requirements are not yet a universal feature of cyber insurance, and organisations should be cautious about claiming otherwise.

But the underlying logic is straightforward.

As quantum-related cryptographic risk becomes better understood, insurers and risk advisers can reasonably become interested in questions such as:

What sensitive information must remain confidential for many years?

Does the organisation understand which cryptographic mechanisms protect it?

Are legacy or unsupported systems creating migration constraints?

Is there a funded and governed transition plan?

The important word is therefore not prediction.

It is evidence.

Organisations that already maintain this evidence will be considerably better positioned to respond as insurer expectations evolve.

Boards will need a different kind of PQC report

Boards do not need presentations about lattice mathematics.

 

They need to understand exposure, dependency, accountability, progress and residual risk.

A useful PQC board report could eventually look surprisingly conventional:

 

Exposure:
Which important systems, communications and data depend on quantum-vulnerable cryptography?

Materiality:
Which information needs confidentiality or authenticity beyond the expected lifetime of existing cryptographic protections?

Dependencies:
Which cloud providers, software vendors, hardware manufacturers and partners control parts of the transition?

Readiness:
How much of the cryptographic estate has been identified and classified?

Plan:
What will be migrated, replaced, upgraded, retired or temporarily accepted?

Ownership:
Who is accountable?

Timeline:
How does the programme align with relevant government, regulatory and industry expectations?

Evidence:

Can these claims be substantiated?

That last question matters.

 

Because the same evidence used for board assurance can support customers, procurement teams, auditors, insurers and regulators.

 

That is where PQC readiness starts becoming commercially valuable rather than simply technically necessary.

What might a PQC readiness evidence pack contain?

Organisations do not need a hundred-page document filled with cryptographic terminology.

 

They need a defensible body of evidence.

 

A useful starting pack might contain:

 

  1. Cryptographic inventory

A current view of where relevant cryptography is used across applications, infrastructure, protocols, certificates, identities, hardware, third-party services and embedded systems.

 

  1. Quantum-risk assessment

An assessment of which systems and information are materially exposed, including information with long confidentiality requirements.

 

  1. Dependency map

Identification of vendors, platforms and hardware whose PQC capabilities affect your own migration.

 

  1. Prioritisation model

Clear criteria explaining why some systems need action sooner than others.

 

  1. Transition roadmap

What will be upgraded, replaced, retired, redesigned or monitored — and approximately when.

 

  1. Cryptographic-agility strategy

Evidence that systems are being designed or modernised so cryptographic algorithms can be changed without another major architectural intervention.

 

  1. Governance

Named ownership, reporting arrangements and decision-making responsibilities.

 

  1. Standards position

The recognised standards and authoritative guidance against which your programme is being developed.

 

  1. Testing and implementation evidence

As migrations begin, records demonstrating that new implementations have been properly tested rather than simply enabled.

 

  1. Customer assurance statement

A concise, carefully worded explanation of your organisation’s PQC position that customer-facing teams can use consistently.

 

Notice what this does.

 

It converts:

“We are looking at quantum risk.”

 

into:

“We understand our exposure, we know our dependencies, we have prioritised the work, and here is the evidence supporting our position.”

 

That is a much stronger trust proposition.

The organisations that prepare first gain something more valuable than compliance

 

There is a danger in treating PQC purely as another deadline.

 

For some organisations it will certainly become a compliance and technology-migration obligation.

 

But there is another opportunity.

 

Companies entrusted with sensitive information are constantly trying to demonstrate that they are safer, more dependable and better governed than alternatives.

 

PQC readiness provides another way to demonstrate that discipline.

 

Not through claims of being “quantum proof.”

 

Not through fear.

 

And not through purchasing an isolated piece of technology labelled quantum-safe.

 

But through evidence that management understands a significant emerging security transition and is handling it methodically.

 

That is what sophisticated customers ultimately buy from trusted suppliers.

 

Not promises.

Assurance.

 

Prepare before the questionnaire arrives

 

The post-quantum transition will take years.

 

Customer expectations can change considerably faster.

 

Your next major customer may not ask whether you have completed your PQC migration.

 

They may simply ask whether you know what needs to migrate.

 

Whether you understand your dependencies.

 

Whether there is an accountable owner.

 

Whether there is a roadmap.

 

And whether you can prove it.

 

Prepare your PQC readiness evidence.

Ariadne Thread Solutions helps organisations identify cryptographic exposure, assess post-quantum risk, map dependencies and turn PQC preparation into a defensible readiness programme — suitable not only for technical teams, but for management, customers and supplier assurance.

Not sure where PQC touches your access-control systems?

Start with visibility.

Ariadne’s PQC Readiness Snapshot helps leadership identify sensitive data, critical systems, vendor dependencies and cryptographic touchpoints before transition decisions become urgent.

 

Was the text too technical?