PQC Risk Assessment

Answer a few questions to get a personalized quantum risk score, migration priorities, and actionable recommendations for your organization.

What this means for you

Executive / Business Leader
The Fast track (6 questions, ~3 min) is the recommended route for you; the chooser card lists exactly what "Your report includes" and how many sections stay locked until the Full track.
GRC / Risk & Compliance
The Full track is your recommended route; the "Compliance" step asks which frameworks apply, and every step states "In your report:" what that answer changes before you answer it.
Developer / Engineer
On the "Crypto in use" step, "Have a CBOM? Import it instead of answering by hand." reads a CycloneDX 1.6 file in your browser and fills that question — nothing is uploaded.
Security Architect
The "Infrastructure" step flags HSMs and on-prem as hardest to migrate and its "Synced" toggle pulls your Migrate product selections in; "Crypto agility" decides whether the roadmap recommends a one-off swap or the ability to swap again.
Researcher / Academic
"No estate to describe? Use a reference one" — "Mid-size retail bank" or "Hospital group" — answers every question and jumps straight to "Review your answers"; the report then says it came from a reference estate.
Certification & Validation Engineer
The Full track is recommended for your role, and the first step asks which sector the product is sold into — answer for the product line; every step states "In your report:" what the answer changes.
IT Ops / DevOps
The "Data retention" and "Credential lifetime" steps set the HNDL and HNFL windows; "Timeline pressure" asks whether you have a migration deadline; "Save link" copies a link to resume from the step you are on.
Curious Explorer
The Fast track is recommended for you; each step has a "Why we ask" disclosure, optional steps show "Skip", and the flow ends with "Review your answers" then "Generate my report".
Fast track
6 Q · ~3 min

The essentials — industry, crypto stack, data sensitivity, infrastructure and migration status. Best for a first read or a quick board-ready snapshot.

Your report includes
Risk score & verdict
Key findings & threat landscape
Assessment profile
HNDL exposure window
Compliance impact
Recommended actions
2 sections stay locked
Most complete
Full track
13 Q · ~5 min

Everything in fast track plus use cases, retention, credential lifetimes, scale, crypto agility and vendor dependencies — for a credible migration plan.

Unlocks everything, including
Per-domain risk breakdown
Progress over time
No estate to describe? Use a reference one

Assess a documented example organisation instead of your own. Every question is pre-answered, so you can see what the report does with a complete set of inputs — and the report says on its face that it came from a reference estate, so it can never be mistaken for a finding about a real one.

Mid-size retail bank

A regional retail bank: card payments, long-lived customer records, a regulator with a published date, and a large vendor-supplied core.

Shaped from publicly stated finance-sector characteristics — PCI DSS 4.0 and DORA applicability, the sector’s typical multi-decade record retention, and the well-documented dependence on vendor core-banking platforms. Not modelled on any named institution.

Hospital group

A multi-site healthcare provider: patient records that stay sensitive for a lifetime, connected medical devices nobody can patch quickly.

Shaped from publicly stated healthcare characteristics — HIPAA applicability, lifetime-of-patient record sensitivity, and the documented difficulty of updating certified medical devices. Not modelled on any named provider.

Next step

Read your readiness report

The report turns your answers into a score, priorities and recommended actions, section by section.