PQC Intelligence Center
The quantum threat is already reshaping enterprise risk.
We’re here to share our research, intelligence, and real-world data, along with practical guidance to help you identify Post-Quantum Cryptography (PQC) exposures, prioritize risk, and develop a step-by-step transition plan.
Today’s Public Keys Are Tomorrow’s Liability
To establish trust, current encryption technologies like RSA, Elliptic Curve Cryptography, and Diffie Hellman are built on computationally difficult math problems that classic computers can’t break.
One day soon, a sufficiently powerful quantum computer will be able to break the public key encryptions in use today. That milestone, commonly referred to as Q Day, will have significant consequences to network security as we know it.
Read the Countdown to Q Day blog.
See, Understand, Prioritize, Act
Assessing the PQC Problem
To get ready for Q Day, the biggest challenge is to understand where cryptography is used, followed by assessing the impact of replacing it.
The quantum threat touches every organization that handles sensitive data, operates critical infrastructure, or relies on long-lived encryptions.
Industries most at risk
| Sector | PQC Exposure Risk | Key Concern |
|---|---|---|
| Government & Defense | Critical — hard mandates | National secrets with 20+ year sensitivity windows |
| Healthcare / IoMT | Critical — 2% PQC adoption | PHI, medical device firmware, patient safety |
| Manufacturing / OT | High — 11% PQC adoption | Firmware overhauls required; long equipment cycles |
| Financial Services | High — transaction data | Credentials and transactions harvested today |
| Energy & Utilities | High — infrastructure | Decades-long equipment cycles; 2030 mandates loom |
| Enterprise IT | Moderate — 42% OpenSSH | TLS migration significantly lags SSH adoption |
Where Things Stand Today
Data from Forescout Research – Vedere Labs based on analysis of more than 186 million SSH servers and global TLS traffic:
| Device / Protocol Type | PQC Support | Notes |
|---|---|---|
| IT devices (OpenSSH) | 42% | Easiest to upgrade; leads all sectors |
| All SSH servers | 8.5% | Includes all SSH server types globally |
| IoT devices | 20% | 20% of IoT run PQC-capable OpenSSH |
| OT / network equipment | 11% | Often exposed online; high-value for attackers |
| IoMT (medical) devices | 2% | Lowest adoption; firmware overhauls may be needed |
| TLS 1.3 traffic (PQC-ready) | 19% | Only TLS version with PQC algorithm support |
To get started with PQC transition, identify core cryptographic vulnerabilities. Then, understand them in context, including IOT and OT networks where risk is concentrated and remediation is slow. Next, define PQC remediation priority for the highest-risk assets. Then, develop a roadmap for replacing the most vulnerable cryptographic systems.
The PQC Lifecycle
See
Find the assets that use PQC-vulnerable protocols like TLS and SSH.
Understand
Understand asset context like location, traffic flow, data sensitivity criticality.
Prioritize
Apply network context to identify and prioritize the risks that matter most.
Act
Systematically reduce exposure thru targeted actions. Repeat.
Current PQC migration roadmaps from governments worldwide mandate transitioning to PQC for critical assets between 2030 and 2035. The migration window is open — but narrowing. And replacing cryptographic systems is slow work.
There are thousands of cryptographic algorithms buried inside firmware, embedded devices, VPN appliances, certificates, databases, authentication systems, applications, and more. Delaying the planning phase increases both cost and risk.
The G7 and NIST have published PQC guidelines and standards that define a starting point along with a roadmap that can help plan your transition to PQC readiness.
G7 and NIST Are Clear: Prepare Now.
Discovery / Inventory
- Build an inventory of cryptographic algorithms and systems.
- Identify where non PQC-safe algorithms are used
- Map this into risk frameworks (CSF 2.0, SP 800 53)
Risk Assessment & Planning
- Evaluate ALL systems, protocols, and dependencies and classify data by longevity and sensitivity
- Assess risk and prioritize remediation based on exposure
Migration
- Tie migration timelines to broader system upgrades
- Approach PQC as a program, not a one-off project
Continuous Calidation & Monitoring
- Monitor and validate PQC risk constantly (new assets, configs, traffic)
- Maintain continuous visibility into cryptographic posture
Resources

Webinar: From Quantum Visibility to Quantum Readiness: Prioritizing Cyber Risk Before Q-Day
Learn how to identify quantum-vulnerable cryptography, prioritize cyber risk based on business impact, and build a post-quantum readiness strategy before Q-Day.
Let's Talk Security: The Quantum Threat & Migration to Post-Quantum Cryptography (PQC)
Forescout CEO Barry Mainz is joined by Forescout’s Robert McNutt, Chief Strategy Officer, and Daniel dos Santos, Sr. Director of Research at Vedere Labs, to discuss the adoption of post-quantum cryptography (PQC) and how to overcome hurdles.

G7 Sets Quantum Deadline: Roadmap Signals Industry Urgency for All
The G7’s new roadmap details the protection journey for post-quantum cryptography. Forescout’s CSO breaks down what it means and what to do.

Before Q‑Day, Visibility Is the First PQC Move
Waiting for PQC migration to start? That’s a blind spot. Learn why visibility into quantum-unsafe cryptography can’t wait for Q-Day.
Forescout’s Patented PQC Detection Technology
Forescout holds a patent for technology that identifies non-PQC-safe algorithms and systems in real time — across managed and unmanaged devices, in IT, OT, IoT, and IoMT environments. Positioned at the network layer, it detects non-PQC-safe algorithms even when devices attempt to hide their identity or posture.
Forescout’s patented technology analyzes the cryptographic algorithms every connected device supports, scores them against post-quantum cryptography safety standards, and surfaces encryption risks across the entire network — regardless of whether a device is managed, unmanaged, compliant, or evasive.
The Forescout Vistaro™ platform delivers a four-pronged quantum-safe strategy:
- Discover: Patented technology identifies PQC-safe and non-PQC-safe assets in real time, delivering cryptographic posture visibility across hybrid networks.
- Enforce: Network segmentation isolates critical systems and secure communication pathways.
- Mitigate: Identify rogue actors or assets and misconfigurations to rapidly target policy enforcement.
- Create: Workflows that orchestrate remediation.
Building the Business Case for PQC Readiness Investment
Quantum risk won’t be defined by a single breakthrough moment. It will be the cumulative effect of sustained technical progress, investment, and nation-state-level coordination that continues to compress the timeline between the theoretical capability of quantum computers and real-world threat.
The moment a quantum computer can break today’s public key cryptographic systems, the integrity of digital signatures will be at risk. We’re here to help you build your business case for PQC readiness sooner rather than later.
Start with scope and visibility to unlock investment
Start by developing a cryptographic inventory and be prepared for:
- Unknown dependencies
- Legacy cryptographic exposure
- Gaps in vendor and system readiness
These variables make it obvious that it’s going to take time and planning to migrate to quantum-safe cryptographic systems. This can be the the leverage you need to shift PQC readiness from future awareness and concern to an operational priority. It can be helpful to quantify details like:
- Where does cryptography exist across our environment?
- Which of these exposures actually matter to the business?
- What actions reduce risk now, before full PQC migration?
Translate PQC readiness into a defensible PQC business case
Develop a business case that measures PQC readiness by the reduction in cryptographic risk, not just by migration progress.
- Quantify exposure: where does quantum risk exist today
- Prioritize action: which risks matter most and why
- Measure outcomes: how will exposure be reduced over time
Align investment with regulatory accountability
Build your PQC business case with regulatory and standards bodies guidance:
- Standards bodies such as NIST
- G7 roadmap guidance
- Regulatory expectations for risk visibility and mitigation

