Organizations must transition to post-quantum cryptography. But it’s complicated – most businesses and governments rely on third-party vendors, cloud platforms, managed service providers and external tools, meaning the risk is in the dependency on third-parties. No organization is an island, and if your vendor is slow to transition, or lacks visibility into their own systems, your data is likely to remain exposed. So how do you proactively find out what’s going in the supply chain?
The Australian Signals Directorate (ASD) has published a practical, forward looking guide that addresses the challenge. The guidance aligns to the ASD’s LATICE framework, breaking down vendor assessment into five key phases:
1. Locate and inventory Cryptographic Dependencies – it’s important to know where your cryptography is.
2. Assess risk to individual systems – prioritize high-impact, high-sensitivity data that must transition first.
3. Triage and prioritize systems for transition – ask vendors how they are prioritizing updates and prioritize critical systems.
4. Implement PQC algorithms – vendors should be migrating to internationally recognized standards, maintaining compliance.
5. Communicate with vendors and Educate stakeholders – encourage vendors to be transparent, showing willingness to discuss constraints and support well-defined roadmaps.
PQShield’s mission is to protect the global supply chain. It’s encouraging to see governments providing toolkits to aid the transition – especially for organizations who need a start-point. Our expertise and range of quantum-secure IP are designed to help vendors and operators close those cryptographic gaps smoothly and securely.

