Why cryptographic inventory is the most overlooked project in post-quantum security
When security teams begin thinking about the transition to post-quantum cryptography, the conversation moves quickly to algorithms: which NIST standards to adopt, how to update TLS stacks and certificate chains, how to build a migration roadmap.. These are the right questions. Just not yet. The questions do all share a common assumption that most organizations have not yet tested: you already know where your cryptography lives. In most large organizations, that assumption is unlikely to survive first contact with the actual infrastructure.
The practical obstacle most security programs will hit first is not the complexity of new algorithms. It’s the discovery that they lack a reliable picture of what cryptographic mechanisms are running across their environment, where those mechanisms sit, what systems depend on them, who controls the update schedule, and how long each component will remain in service. Without that picture, a migration roadmap is guesswork because you cannot prioritize what you cannot see, and you cannot sequence a transition without knowing what you are transitioning from.
The reason that gap exists is that cryptographic sprawl is one of the most invisible problems in enterprise environments. Libraries are updated in one system and forgotten in another, protocols are negotiated at the network edge and ignored deeper in the stack, keys may remain in circulation for years, and certificates, authentication mechanisms, and key-management infrastructure often span multiple owners and technologies. This becomes even more important as organizations move toward quantum-safe architectures combining post-quantum cryptography with technologies such as quantum key distribution. QKD can provide exceptionally strong key establishment and distribution, but it still operates within a broader security architecture involving authentication, key management, endpoints, applications, and classical cryptography. Without an inventory of that complete environment, even advanced quantum-secure infrastructure cannot be migrated and managed systematically.
But it isn’t somebody else’s problem. It is the foundation that every other part of the migration depends on.
The urgency here is real, and the trajectory is not linear. Google’s Willow result was important because it demonstrated below-threshold quantum error correction experimentally, showing that increasing code distance can make encoded information progressively more reliable rather than less. On the algorithmic and architectural side, the resource estimates are moving just as quickly. A widely cited 2021 estimate placed the requirement for factoring RSA-2048 at around 20 million noisy physical qubits. Craig Gidney’s 2025 work reduced that to fewer than one million. In 2026, newer fault-tolerant architectures have explored regimes below 100,000 physical qubits and, under specialized reconfigurable neutral-atom assumptions, close to 10,000. These are theoretical resource estimates under different assumptions, not demonstrations of RSA being broken, but the direction is unmistakable: hardware capability is advancing while the resource requirement is falling.
More immediately, under the harvest-now-decrypt-later model, the clock starts before a cryptographically relevant machine exists. Encrypted data captured today can be stored and decrypted once sufficiently capable quantum systems become available. For security leaders protecting information with a long shelf life, including contracts, health records, identity infrastructure, intellectual property, and national-security data, this is not simply a future risk.
NIST finalized its first three PQC standards in August 2024 and has encouraged organizations to begin transitioning. The UK’s NCSC has structured its migration guidance around concrete milestones in 2028, 2031, and 2035. The destination is increasingly clear. What many organizations still lack is an accurate map of the starting point.
A thorough cryptographic inventory does several things that no amount of algorithm selection can substitute for. It reveals the actual scope of migration, which is almost always larger than initial estimates. It identifies the highest-priority systems: those handling long-lived, sensitive data on long replacement cycles, where the combination of data sensitivity and replacement timelines creates genuine risk. This is particularly acute in sectors like defense, autonomous vehicles, and industrial systems, where components are designed for multi-decade service lifetimes. Our recent work integrating NIST-standardized PQC into software-defined vehicle environments with Apex.AI makes the point concretely: cryptographic decisions embedded in those systems today will still be in operation long after the threat landscape has changed. The same principle applies to quantum key distribution. Record-setting long-distance QKD demonstrates how rapidly quantum-secure communications are advancing, but deploying QKD at scale still requires a clear understanding of the authentication, key-management, network, and application infrastructure into which it is integrated. Inventory is what makes it possible to find those exposures before they become liabilities.
Beyond risk prioritization, inventory is what makes crypto-agility real rather than aspirational. The ability to swap cryptographic primitives efficiently as standards evolve, resource estimates change, and new algorithmic results emerge, depends entirely on having a current, structured view of where cryptography is deployed. An organization without that view cannot be crypto-agile in practice. It can only react to each transition as a surprise.
The organizations that handle the post-quantum transition well will not be those with the largest budgets or the earliest awareness of the threat. They will be those that understood their own cryptographic environment in time to act on it. That means starting the inventory now. Not because Q-day is certain on a fixed date, but because the inventory itself takes time, the findings consistently surface more work than anticipated, and the migration clock for some categories of data is already running.
Post-quantum cryptography is not a future program waiting for Q-day to trigger it. The migration has already started. For any organization holding long-lived, high-value data, the first step is not choosing an algorithm. It is finding out exactly what cryptography they have, where it is running, what depends on it, and how quickly it can be replaced. You cannot migrate what you cannot see.
