Australian Signals Directorate Publishes Post-Quantum Questions to Evaluate Third-Party Vendor Readiness

Australia Kanagaroo Flag 2000

Key Takeaways

Structured Vendor Tool: The Australian Signals Directorate released a practical set of readiness questions for assessing third-party suppliers on post-quantum cryptography transition.

LATICE Framework Alignment: Questions map directly to Locate, Assess, Triage, Implement, and Communicate phases to support supply-chain visibility.

2030 Transition Support: Guidance enables organisations to identify cryptographic dependencies and plan against the recommended end-2030 timeline for traditional asymmetric algorithms.

The Australian Signals Directorate (ASD) published Post-quantum questions to ask your vendors on July 16, 2026. The guidance supplies organisations with a structured, vendor-neutral set of questions to evaluate how prepared third-party suppliers of products and services are for the transition to post-quantum cryptography (PQC). It targets cyber security leaders, procurement teams and technical stakeholders who must manage cryptographic exposure in cloud services, managed platforms, operational technology, Internet of Things devices and long-lifecycle systems where vendors control the underlying cryptography.

LATICE Framework for Vendor Readiness Assessment

The questions follow the five phases of ASD’s LATICE framework, which structures an organisation’s overall PQC transition and is now applied specifically to third-party evaluation.

Locate: Identify cryptographic dependencies through a current cryptographic bill of materials (CBOM) or equivalent inventory, determine where cryptography is implemented across application, operating system, middleware, firmware and hardware layers, and surface any hardcoded, fixed or hardware-bound algorithms.

Assess: Map customer data flows that rely on traditional asymmetric cryptography, document data-lifetime assumptions that create “harvest now, decrypt later” exposure, and confirm whether the vendor has produced a documented risk assessment of a cryptographically relevant quantum computer (CRQC).

Triage: Establish which products will be PQC-ready early enough to support customer rollout before the end of 2030, identify components requiring hardware replacement or re-architecture, and clarify support for hybrid modes only as a temporary measure.

Implement: Confirm which standards-based, ASD-approved PQC algorithms will be supported, when production-ready implementations become available, and how firmware and boot processes can be updated to accommodate new signature schemes.

Communicate and Educate: Gauge the vendor’s willingness to engage transparently, discuss constraints, and provide governance structures with executive ownership of the transition.

Each question includes an explanation of relevance and key response considerations so organisations can evaluate maturity rather than simply collect answers. Organisations are not expected to pose every question to every supplier; the set is scaled according to risk level, degree of cryptographic control exercised by the vendor, and the sensitivity and longevity of the data involved.

Procurement Integration and Supply-Chain Assurance

Because most organisations depend on vendors for core cryptographic functions, delays or opacity in the supply chain can undermine even well-developed internal PQC plans. The guidance therefore recommends early engagement during procurement, contract renewal and ongoing vendor-assurance activities. By incorporating these questions into existing processes, organisations gain visibility of constraints such as hardware roots of trust, firmware signing schemes and long-lead component replacements that could otherwise force late-stage system redesigns. The publication complements ASD’s broader recommendation to cease use of traditional asymmetric cryptography by the end of 2030 and aligns commercial vendor management with national transition milestones outlined in the Planning for post-quantum cryptography guidance.

Bottom Line

ASD’s vendor-question guidance gives organisations a practical instrument to surface third-party cryptographic dependencies and align supplier roadmaps with the 2030 PQC transition target.

Find out more here.

Further articles, reports, and the latest quantum computing news may be found at The Qubit Report.

Related Articles

Get The Qubit Report delivered straight to your inbox.

Sign up to receive our newsletter and other reports.

We keep your data private and share your data only with third parties that make this service possible. Read our privacy policy for more info.