Quantum Readiness Without a Quantum Strategy
In the last piece, I shared a short list of questions for boards and CEOs: Who owns emerging-technology risk? Does a cryptographic inventory exist? Could anyone answer if a customer or acquirer raised quantum readiness in diligence tomorrow?
For many middle-market companies, these are still unfamiliar questions. Not having every answer today is less important than having a way to find the answer when it becomes material.
The better question is: what would it look like to build that capacity? An organizational structure capable of noticing this kind of shift and responding before it becomes urgent, not a quantum strategy.
The core question underneath all of this is: can the organization identify when quantum becomes material, determine what's exposed, and act before the transition turns into a scramble?
Step 1: Start With a Working Hypothesis
Begin by placing your company on the Quantum Relevance Map.
This is a working hypothesis, not a conclusion. Step 2 will test whether the initial placement holds.
Quantum presents two different questions that are easy to conflate:
How significant is our potential security exposure?
and
How significant could quantum become as a business opportunity?
Those two axes create four possible positions:
Monitor — Neither currently warrants significant action, but conditions should be watched.
Protect — Security exposure warrants attention even if business applications remain limited.
Explore — Potential business applications merit attention even if current security exposure is limited.
Protect + Explore — Both security exposure and potential business opportunity are becoming relevant.
On the security axis, long-lived sensitive data and dependence on quantum-vulnerable cryptography are important indicators of potential exposure. On the opportunity axis, consider whether credible quantum applications are emerging in your industry, products, capabilities, or value chain.
For many middle-market companies, Monitor or Protect may be entirely appropriate positions.
The point is not to move toward the upper-right corner. It is to know why you are where you are.
Step 2: Establish the Current Condition
Now test that initial placement with a short, inventory — not a project:
What information has a long confidentiality life — years, not months?
Where is quantum-vulnerable public-key encryption actually used across the business?
Which vendors — cloud, SaaS, payments, identity, certificates, and others — control portions of the migration path on your behalf?
Where, if at all, might quantum eventually affect the value chain itself?
Who currently owns the answer to any of this?
If no one does, that's the finding.
The purpose isn't to produce a comprehensive technical assessment. It is to know enough about the current condition to confirm or correct where you placed the company on the map.
Step 3: Define What Would Change Your Answer
This is where quantum readiness becomes less about prediction and more about organizational discipline.
Quantum isn't a project with a universally settled deadline. For most companies, it is better understood as a watch condition.
What would move your company from one position on the map to another?
A government or large customer introduces a post-quantum requirement.
A critical vendor announces a migration or end-of-support date.
An acquisition target reveals material cryptographic debt during diligence.
A commercially credible quantum application emerges in your industry.
A regulator, insurer, lender, or investor changes its expectations.
These are different from headlines about quantum breakthroughs, as a headline may be noise. A development relevant to your industry may be a signal. A change that materially affects your exposure, opportunity, obligations, customers, or operating environment is a trigger.
The distinction matters because some of these signals are already appearing. NIST has finalized three post-quantum cryptography standards and encourages organizations to begin transitioning. Government requirements are also becoming more concrete in environments, including National Security Systems.
That does not mean every middle-market company should launch a quantum program. It means the external environment is beginning to provide observable signals against which a company can define its own triggers. Naming those triggers in advance is what keeps the organization from moving between denial and overreaction later.
Step 4: Use SCALE to Test Response Capacity
Once the company knows what it is watching for, the next question is whether the organization could respond if one of those triggers appeared tomorrow. This is where the five SCALE pillars become useful as an organizational stress test:
Strategic Alignment — Has leadership agreed on what would make quantum material to this business?
Capability to Execute — Could the company assess a trigger without starting from zero?
Accountability & Governance — Is there a named management owner and a defined path to the board if the issue escalates?
Leadership & Culture — Can leadership examine an unfamiliar risk without either dismissing it or chasing the hype?
Enterprise Resilience — Does the company know where its cryptographic dependencies and long-lived sensitive data reside?
The five pillars work as an organizational system, not as five independent strengths.
A company may be strong in four and still struggle to respond if the fifth cannot carry the load an emerging issue places on it. Strong strategic alignment, for example, does little if no one owns the signal. Strong governance cannot compensate indefinitely for an organization that cannot assess it.
Quantum provides a useful stress test precisely because it can expose where otherwise strong organizational architecture fails at the seams. And that is the broader point.
Quantum happens to be the signal we're examining here. The organizational capability being tested is whether the company can recognize an unfamiliar issue, determine when it becomes material, assign accountability, and mobilize before urgency makes the decisions for it.
Step 5: Make a Proportionate First Move
None of this requires a quantum program. For many middle-market companies, an appropriate first move is much smaller:
Name an executive owner.
Identify where long-lived sensitive information actually sits.
Determine whether a cryptographic inventory exists at all.
Ask major technology vendors for their post-quantum roadmaps.
Assign important triggers an owner, review cadence, and escalation path.
Revisit the company's position on the map annually — or when a material signal changes.
That's a first step small enough to begin this quarter and specific enough that "we haven't looked at this yet" stops being an acceptable answer the second time it's asked.
The objective is to build an organization capable of recognizing when its answer has changed, and responding before urgency makes the decisions for it.