Since January 17, 2025, financial entities in the European Union have had to maintain a register of their cryptographic assets under the Digital Operational Resilience Act (DORA): the algorithms, key lengths, certificates, and protocols in use across the estate, including the parts operated by suppliers. Nothing in the same regulation obliges those suppliers to say what they use. The obligation belongs to the entity. The information belongs to the supplier, and no rule compels the supplier to hand it over.
That asymmetry is the practical starting condition for anyone who owns third-party risk in a post-quantum migration. It isn’t unique to Europe. US federal agencies work under a parallel inventory obligation from OMB Memorandum M-23-02, and the same shape appears wherever a regulator has asked for cryptographic visibility: the duty attaches to the accountable organization, and the estate it covers reaches into systems somebody else operates.
A cryptographic inventory, often delivered as a cryptographic bill of materials or CBOM, is a record of every place an organization depends on public-key cryptography, and of which algorithm does the work in each place. For internal systems, discovery tools produce most of it. For hosted platforms, managed services, and embedded appliances, the tool sees a TLS handshake at the boundary and nothing behind it. The rest has to be asked for.
This article sets out how to govern that asked-for half at portfolio scale. It assumes you’ve already accepted the premise that suppliers are participants in your migration rather than substitutes for it.
Why third-party cryptographic risk behaves differently
Third-party risk teams already run supplier registers, due diligence questionnaires, and concentration analysis. Cryptography stresses those instruments in four specific ways, and it’s worth naming them before designing anything.
Visibility is granted, not discovered. A scanner finds algorithms in traffic you terminate and in code you compile. It finds nothing inside a hosted platform’s internal key exchange, nothing in the firmware of a managed appliance, and nothing in a payment processor’s back-office signing chain. Where the tooling stops, the questionnaire starts, and the questionnaire only works if someone answers it honestly.
Control is commercial rather than managerial. Inside the organization, an accountable executive can direct an engineering team to schedule a change window. Outside it, the available moves are asking, paying, escalating, and leaving. Each of those has a cost, and the costs compound across a portfolio.
The timeline belongs to someone else. Your migration dates come from regulatory deadlines and your own data sensitivity. A supplier’s dates come from their engineering capacity, their upstream library dependencies, their certification queue, and the demand signal they receive from every other customer. The UK’s Cross Market Operational Resilience Group made the same point in its 2025 post-quantum guidance: supplier timelines are unlikely to converge on a sector’s timeline unless the sector signals demand clearly.
Failure propagates. One supplier can hold up the migration of every internal system that depends on it. If the certificate authority can’t issue post-quantum certificates, the public key infrastructure work waits. If the hardware security module vendor has no post-quantum firmware, key management waits. Internal progress reports stay green while the dependency underneath them stays classical.
Four artifacts that make the risk governable
We teach this dimension as a set of four artifacts rather than a set of activities, for a plain reason: activities are hard to audit and artifacts are not. Each one has an owner, a review cycle, and a state that can be reported. Together they turn a diffuse concern into something a risk committee can act on.
Artifact one: a supplier register segmented by cryptographic dependency
Most portfolios contain a few hundred technology suppliers. Governing them at equal intensity fails immediately, so the register needs a segmentation that reflects cryptographic exposure rather than spend.
Two questions do the sorting. Does the supplier perform key exchange, signing, or certificate issuance on your behalf? And does your internal migration depend on theirs completing first?
Tier 1, migration-blocking. Both answers are yes. Certificate authorities, hardware security module vendors, cloud key management services, identity providers, payment network processors. These get active governance: named owner, quarterly roadmap review, steering committee visibility.
Tier 2, cryptographically exposed. The supplier handles protected data, but your internal work can proceed while theirs continues. Enterprise resource planning platforms, customer relationship management, managed detection and response, analytics platforms. These get monitoring and an annual readiness assessment, with a route to promote them into Tier 1 if their timeline slips past yours.
Tier 3, minimal exposure. Facilities, logistics, non-digital professional services. Baseline contract language on renewal, nothing more.
Working an example through the test is quicker than reading the definitions. A document e-signature platform issues signatures that must remain verifiable for the statutory retention period of the contracts they cover, so it’s Tier 1, and the deciding factor is the verification lifetime rather than the transport security. A recruitment portal processes candidate data over TLS the provider terminates, and no internal migration waits on it, so it’s Tier 2. A cleaning contractor with a supplier portal login is Tier 3, and it stays Tier 3 even though the portal uses cryptography.
Expect the Tier 1 list to come out shorter than the team predicts, and the Tier 2 list to come out considerably longer. Both surprises are useful. The short Tier 1 list is what makes active governance affordable.
Artifact two: a readiness record built on evidence
The second artifact is a per-supplier record of what has actually been established, kept separate from what has been claimed. “Quantum-safe” now appears in product marketing well ahead of implementation, and a readiness record that accepts marketing language as an input will report a readiness the estate does not have.
Four kinds of evidence carry weight. A published roadmap with dates attached and a named owner. A FIPS 140-3 validation certificate, meaning the cryptographic module has been tested and certified against the federal standard, covering an implementation of ML-KEM (FIPS 203, formerly Kyber) or ML-DSA (FIPS 204, formerly Dilithium). A named service with hybrid key exchange available, which means the connection is protected by a classical algorithm and a post-quantum one at the same time, so it holds if either survives. And results from a test you ran jointly, in your configuration.
Sequence matters here more than most teams expect. Sending a 40-question cryptographic assessment to a supplier who has never discussed post-quantum cryptography internally produces a defensive non-answer, and it burns the relationship you’ll need later. A short awareness briefing first, covering your program, your regulatory drivers, and what you’ll eventually need, changes the reception of the questionnaire that follows. It also gives you an early read on which suppliers are engaged, which is information a questionnaire can’t provide.
For suppliers who serve an entire sector, individual pressure moves little. Coordination through a sector body, a payments scheme, or an information sharing group moves considerably more, and it costs you nothing beyond attendance.
Artifact three: a substitution option for every Tier 1 dependency
This is the artifact programs defer, and the deferral is expensive.
Substitution planning doesn’t mean replacing suppliers. It means holding the option to replace them, so that if the option is ever exercised, it’s exercised from preparation rather than from crisis. A Tier 1 evaluation started after a supplier misses its commitments adds a year or more of vendor selection, procurement, integration, and cutover to a timeline that already has a regulatory date on it, and it happens under time pressure with no negotiating position.
Three questions, answered once and refreshed annually, produce the file.
Who are the credible alternatives, and what’s their post-quantum position relative to the incumbent? This is desk research your procurement team can complete in a fortnight across the whole Tier 1 list.
What would switching cost, to an order of magnitude, in money and in months? Data migration, integration rework, retraining, parallel running through cutover. The output is a range, not a project plan. Its purpose is to let the steering committee answer “what happens if we move?” with a number rather than a shrug.
What triggers a formal evaluation? Two consecutive missed roadmap milestones. Refusal to engage. A published timeline more than eighteen months behind your own. Write the triggers into the committee’s terms of reference while nobody is under pressure, because the alternative is negotiating the definition of failure with the person who has to declare it.
The file has a second effect that’s easy to underestimate. A supplier who knows you have no alternative prioritizes accordingly. A supplier who learns, through ordinary commercial conversation, that alternatives have been assessed and switching costs estimated, prioritizes differently.
Artifact four: a reporting line the risk committee will read
The fourth artifact is the number that travels upward. A key risk indicator, or KRI, is a measure the risk committee tracks over time to see whether exposure is improving or degrading.
The one that works here is coverage: the percentage of Tier 1 and Tier 2 suppliers with a documented post-quantum roadmap or demonstrated capability, measured against evidence rather than assertion.
Underneath it, management needs four decompositions: Tier 1 status supplier by supplier, an aggregate Tier 2 score, the specific dependencies currently blocked and which internal workstreams they block, and the contract amendment completion rate. When a Tier 1 supplier moves from green to amber, the accountable executive needs three options on the same page: escalate commercially, accept the exposure with compensating controls and a review date, or open the substitution evaluation.
Coverage that stalls across the portfolio is also an early signal on cost and schedule. If half your Tier 1 suppliers have no dated roadmap eighteen months in, the program’s own dates are optimistic, and the committee should hear that before the board does.
Contract language as the enforcement layer
Collaboration builds the information flow. Contracts make it durable. Five provisions cover the minimum, and none of them requires the supplier to be ready today.
- Cryptographic disclosure. The supplier identifies the public-key algorithms used in the service and notifies you within a fixed window of any change.
- Migration commitment. The supplier provides a written post-quantum roadmap on request, with target dates for the NIST-standardized algorithms and for hybrid deployment modes.
- Assessment right. You, or a third party you appoint, may assess the cryptographic implementation at a frequency set by tier.
- Subcontractor flow-down. The supplier passes disclosure and migration obligations to subcontractors that handle your data.
- Termination trigger. Material failure to meet the agreed migration commitments becomes a named termination event.
New contracts are straightforward once these sit in the procurement templates, which is a one-time change with permanent returns. Existing contracts are the slow part, and the sequencing rule is simple: amend at renewal wherever possible, because reopening a live agreement mid-term costs more and yields less. Build a twelve to eighteen month amendment pipeline ordered by expiry date, and accept that some Tier 1 relationships will run on a questionnaire and goodwill until their renewal arrives.
When a supplier genuinely cannot move
Before treating slow progress as indifference, establish which of two situations you’re in, because the governance response differs completely.
Some suppliers are constrained. Their product depends on an upstream cryptographic library that hasn’t shipped post-quantum support. Their FIPS 140-3 validation is in the queue behind everyone else’s. Their post-quantum work is blocked behind a hardware refresh cycle. For these, the response is collaborative: share your timeline, offer a test environment, join the beta, and put compensating controls in place for the gap. Network segmentation, tighter data classification rules on what may transit that service, and additional monitoring all reduce exposure without requiring the supplier to do anything.
Some suppliers are indifferent. They’ve heard the question, they’ve absorbed the demand signal, and they’ve made a commercial judgment that other work comes first. For these, the response is commercial: the renewal conversation led jointly by procurement and the accountable executive, escalation through sector coordination, and activation of the substitution trigger.
Either way, an unresolved Tier 1 dependency is a program-level exposure, and accepting it is a decision for the committee that owns the program rather than the team that owns the supplier. The reason is harvest now, decrypt later: an adversary can capture encrypted traffic today and store it until a cryptographically relevant quantum computer exists, then decrypt it. Data that crosses a supplier’s infrastructure under classical protection during the gap can’t be protected retroactively once the supplier eventually migrates. For anything with a confidentiality requirement measured in decades, the supplier’s timeline is directly your exposure, and the acceptance should say so in those terms.
Where this sits in the operating model
Cryptographic third-party risk falls between four owners, and none of them is accountable for the whole of it. Security owns the algorithms, procurement owns the contracts, the business owns the relationship, and the migration program owns the deadline.
The arrangement that works puts a named person inside procurement who holds the brief. They attend the steering committee, own the tiering model, run the amendment pipeline, coordinate the questionnaires and briefings, and keep the substitution files current. They don’t need to be a cryptographer. They need to understand the tiering test, the contract provisions, the regulatory drivers, and which internal workstreams each Tier 1 relationship blocks. Cryptographic engineering supplies the technical specification. Procurement turns it into contractual language and manages the relationship. Second-line risk challenges the readiness record and owns the KRI definition.
A sequence that works
For a program that hasn’t started on this dimension, order the work so that each step makes the next one easier.
- Run the tiering exercise. A week with procurement and the cryptographic engineering lead produces the Tier 1 list.
- Brief your Tier 1 suppliers on your program and your drivers, before you ask them for anything.
- Hold informal technical conversations with each Tier 1 supplier. Learn their constraints. Share your dates.
- Build the substitution file for each Tier 1 dependency. Days per supplier, not months.
- Issue the formal readiness questionnaire to Tier 1 and Tier 2, now that it lands as a follow-up rather than a cold demand.
- Get the five provisions into procurement’s templates, and order the amendment pipeline by renewal date.
- Stand up the coverage KRI and its four decompositions, and put Tier 1 status on the quarterly agenda.
Very little of this is technically difficult. Most of it is organizational: getting a register segmented correctly, insisting on evidence where assertion is easier, and keeping an option open before you need it.
Build the capability
Third-party cryptographic risk sits at the intersection of two skill sets that rarely meet in one person. Vendor risk professionals know how to run a portfolio and don’t usually know what a hybrid key exchange is. Cryptographic engineers know the algorithms and don’t usually know how a contract renewal cycle works.
Quantum Academy’s certification programs are built to close that distance, with governance and third-party risk treated as first-class parts of a migration rather than an appendix to the technical work. You can review the current programs and access options at quantumacademy.com/.
For the migration methodology these artifacts plug into, including where vendor assessment falls in the phased lifecycle, see pqcframework.org. For deeper technical background on the standardized algorithms and the threat model behind the deadlines, PostQuantum.com covers both in detail.