Your organization's encryption systems have a shelf life, and the clock is ticking. The G7's September 3 call to action, signed by cybersecurity agencies across Canada, France, Germany, Italy, Japan, the UK, the US, and supported by ENISA, makes this clear: quantum-safe encryption isn't a distant concern. It's a near-term risk that demands methodical preparation.
The challenge isn't just technical. It's operational. Before transitioning to post-quantum cryptography, you need to know what you're protecting, where it lives, and which systems pose the greatest risk if they fail. This requires an inventory structure your team can actually use.
This template provides a framework for cataloging cryptographic assets and prioritizing them for PQC transition. It's designed to support the risk-based, phased approach the G7 document recommends.
What This Template Is For
This inventory captures three critical dimensions:
- Asset identification: What systems, applications, and data repositories rely on public-key cryptography.
- Dependency mapping: Which business processes, third parties, or infrastructure components depend on each cryptographic asset.
- Risk prioritization: Which assets hold the most critical data and warrant early transition.
You'll use this inventory to build your transition roadmap and justify budget allocation. It also serves as documentation for auditors and regulators who will eventually ask how you're managing quantum risk.
Prerequisites
Before you populate this template, gather the following:
- Network diagrams and architecture documentation showing where encryption occurs (TLS endpoints, VPN gateways, certificate authorities, key management systems).
- Data classification schema defining what constitutes critical data in your environment (customer PII, financial records, intellectual property, regulated data).
- System renewal schedules so you can align PQC upgrades with standard replacement cycles and minimize transition costs.
- Vendor product roadmaps indicating when quantum-safe versions of your current tools will be available.
You'll also need stakeholder input from IT operations, application owners, and business unit leaders who understand which systems support mission-critical processes.
The Template
Create a spreadsheet or database with these columns:
Asset Identification
- Asset ID (unique identifier)
- Asset Name (system or application name)
- Asset Type (certificate authority, VPN gateway, database encryption, API authentication, code signing, email encryption, etc.)
- Current Cryptographic Algorithm (RSA-2048, ECDSA P-256, etc.)
- Vendor/Product (commercial product or internally developed)
Dependency Mapping
- Business Process Supported (payment processing, customer authentication, regulatory reporting, etc.)
- Data Classification (public, internal, confidential, restricted)
- Upstream Dependencies (systems that feed data to this asset)
- Downstream Dependencies (systems that consume data from this asset)
- Third-Party Integrations (external partners or service providers that interact with this asset)
Risk Assessment
- Data Criticality (high/medium/low based on impact if compromised)
- Harvest Now, Decrypt Later Risk (high if long-term confidentiality is required)
- Regulatory Exposure (identify applicable frameworks: GDPR, HIPAA, PCI DSS, etc.)
- Business Impact of Failure (revenue loss, operational disruption, regulatory penalties)
Transition Planning
- Priority Tier (1 = transition first, 2 = transition second wave, 3 = transition with standard refresh)
- Standard Refresh Date (when the system is scheduled for replacement or upgrade)
- Estimated Transition Date (when PQC upgrade should occur)
- Vendor PQC Roadmap Status (available now, planned release date, no roadmap published)
- Transition Owner (person responsible for coordinating the upgrade)
- Notes/Blockers (technical constraints, budget limitations, vendor dependencies)
How to Customize It
Start with your highest-risk assets. The G7 document emphasizes prioritizing systems holding the most critical data. Don't try to inventory everything at once.
Phase 1: Critical infrastructure Focus on certificate authorities, key management systems, and any cryptographic infrastructure that, if compromised, would cascade across your environment. These are force multipliers for quantum risk.
Phase 2: Long-lived secrets Identify systems where encrypted data must remain confidential for years or decades. Medical records, financial archives, and intellectual property face "harvest now, decrypt later" attacks where adversaries collect encrypted data today and decrypt it once quantum computers become available.
Phase 3: Regulatory and customer-facing systems Map assets that process regulated data or support customer authentication. These carry both compliance risk and reputational risk.
Adjust the Priority Tier logic to match your organization's risk appetite. Some teams use a scoring model that weights data criticality, regulatory exposure, and business impact. Others rely on qualitative judgment from cross-functional review sessions.
Add columns for your environment's specific needs. If you operate in multiple jurisdictions, add a Geographic Location column to track regional regulatory requirements. If you're subject to sector-specific standards, add a Compliance Framework column listing applicable controls (NIST CSF, ISO 27001, CIS Controls, etc.).
For the Vendor PQC Roadmap Status column, document what you learn from vendor briefings. ANSSI announced it will stop vetting products lacking quantum-safe encryption starting in 2027, with PQC mandatory for some security product procurement by 2030. Your vendors face the same pressure. Track their timelines and hold them accountable.
Validation Steps
Once you've populated the inventory, validate it with these checks:
Completeness audit Cross-reference your inventory against network scans, certificate management tools, and configuration management databases. Missing assets create blind spots in your transition plan.
Dependency verification Schedule review sessions with application owners to confirm the upstream and downstream dependencies you've documented. Incorrect dependency maps lead to failed upgrades and unplanned downtime.
Priority calibration Present your Priority Tier assignments to business stakeholders and risk leadership. Make sure your technical risk assessment aligns with their understanding of business criticality. Disagreement here signals either a communication gap or a genuine need to reassess.
Vendor roadmap confirmation Don't rely on marketing materials. Request written commitments from vendors on PQC availability timelines. If a vendor can't provide a roadmap, that's a signal to evaluate alternatives before your transition deadline.
Regulatory alignment Map your Priority 1 and Priority 2 assets to specific regulatory obligations in your compliance program. This creates traceability between your PQC transition plan and your regulatory risk register, which auditors will expect to see.
Run this validation quarterly as you expand the inventory. New systems come online, vendors update roadmaps, and regulatory guidance evolves. The G7's call to action frames this as a near-term threat demanding action across all sectors. Your inventory is the foundation for that action. Keep it current.



