Quantum Risk Is Already Here: What Buyers Must Demand and Vendors Must Build

IDC ·

Quantum Risk Is Already Here: What Buyers Must Demand and Vendors Must Build

The quantum threat to enterprise third-party risk is not a future planning item. It is a present, compounding liability accumulating across vendor portfolios today. NIST finalized three PQC standards in August 2024 (FIPS 203, 204, 205), added a fourth HQC-based standard in March 2025, and CISA issued federal procurement guidance in January 2026 designating product […] The post Quantum Risk Is Already Here: What Buyers Must Demand and Vendors Must Build appeared first on IDC .

The quantum threat to enterprise third-party risk is not a future planning item. It is a present, compounding liability accumulating across vendor portfolios today. NIST finalized three PQC standards in August 2024 (FIPS 203, 204, 205), added a fourth HQC-based standard in March 2025, and CISA issued federal procurement guidance in January 2026 designating product categories where PQC support is non-optional. NSA’s CNSA 2.0 mandates National Security System migration by 2030 and code-signing infrastructure migration to hash-based schemes by 2025. NIST IR 8547 proposes deprecating quantum-vulnerable asymmetric algorithms after 2030 and disallowing them entirely after 2035. Migration timelines are no longer a matter of organizational preference. They are a matter of regulatory alignment.

Yet no TPRM platform has deployed a production-ready quantum encryption readiness module as of May 2026. The gap is structural. Passive external scanning tools detect classically weak cipher suites but cannot assess whether a vendor’s internal data stores, key management infrastructure, or API layers have adopted NIST PQC-compliant algorithms. The 2025 and 2026 SIG releases added DORA, NIS2, AI governance, and operational resilience domains, but neither introduced a PQC-specific domain. Enterprise buyers are already filling this void through ad hoc custom questionnaire additions, and they can’t afford to wait for vendors to catch up. TPRM platform vendors must close this gap now.

No TPRM platform has deployed a production-ready quantum encryption readiness module as of May 2026. Platform vendors must build this capability now. Buyers cannot wait — the threat is accumulating today.

The quantum threat operates on a retroactive timeline across two distinct dimensions. Both are active today and require separate treatment in any assessment program.

Nation-state adversaries are collecting encrypted data traversing public infrastructure today, including vendor API traffic, VPN sessions, and TLS-protected data flows, for retroactive decryption once quantum computers reach sufficient capability. A 2025 Federal Reserve Board research paper on this exact dynamic, focused on blockchain and distributed-ledger data, found the risk is already active rather than theoretical; the same logic extends to any data with a multi-year confidentiality requirement, encrypted or not. Any sensitive data a vendor transmits or stores under quantum-vulnerable algorithms is already at risk and cannot be re-encrypted retroactively. Mosca’s inequality makes this concrete: if the confidentiality lifetime of the data plus the vendor’s migration time exceeds the time to a capable quantum computer, the exposure window is already open.

TNFL, introduced by IDC as the authentication-layer counterpart to HNDL, describes adversaries harvesting signed vendor artifacts today: software releases, firmware images, certificates, and audit logs. Once quantum computers can break RSA and ECDSA signing keys, those adversaries will retroactively forge provenance records that organizations and regulators cannot distinguish from authentic ones. Every artifact signed under a quantum-vulnerable key today extends the attack surface. TNFL risk compounds in real time. NSA CNSA 2.0 treats authentication migration as a separate and earlier obligation than encryption, with code-signing infrastructure preferring LMS or XMSS by 2025, five years ahead of the 2030 encryption deadline. Any assessment program that addresses only encryption is leaving the TNFL attack surface entirely unexamined.

Two clocks are running simultaneously. The first is the HNDL clock: data encrypted today is potentially readable within a decade and can’t be re-encrypted after the fact. The second is the TNFL clock: every artifact signed under a quantum-vulnerable key today extends the attack surface adversaries will exploit once quantum computing reaches cryptographic relevance. Most programs are only watching one of the two.

Fewer than 10% of vendors will produce documentary evidence for most of the 48 assessment questions in IDC’s Third-Party Quantum Encryption Readiness Assessment Framework. That gap is a market-wide signal of genuine program immaturity. Four structural gaps define where it shows up:

The most important function of the assessment questionnaire is not as a pass/fail gate but as the accountability structure that converts vendor awareness into program initiation. Deploying this framework now, accepting low initial evidence rates, and tracking year-over-year improvement is the most defensible posture available, given what regulators and threat actors have already made clear.

IDC’s 48-question framework spans 11 domains covering the full cryptographic life cycle from program governance and cryptographic inventory through incident response and regulatory alignment. Every question is tagged by evidence collection method (questionnaire, external scan, document review, or technical verification) and vendor tier applicability. Table 1 summarizes all 11 domains.

TABLE 1: The 11 Assessment Domains, IDC Third-Party Quantum Encryption Readiness Assessment Framework

Source: IDC, 2026

Scale assessment depth to vendor risk profile. Build to Tier 1 requirements first; every lower tier is just a lighter version of that same baseline.

Score each vendor across all 11 domains against Table 2. A maturity level supported by domain-level evidence is materially more informative than 48 individual answers, and it’s what produces the year-over-year improvement signal boards want to see.

TABLE 2: Five-Level Vendor Quantum Readiness Maturity Model

Source: IDC, 2026

Quantum readiness is positioned to become the first TPRM domain that is born continuous. Hybrid KEM deployment on production TLS endpoints is externally observable without vendor participation, meaning ratings platforms will convert it into a continuously monitored control once adoption reaches detectable scale. Cryptographic inventories also go stale within months, making an annual questionnaire a poor instrument for this domain. Three converging capabilities define the direction:

Your most exposed vendor relationships are accumulating quantum risk today . The following actions are immediate:

The structural tooling gap in the TPRM market is not a warning signal . It is a market opportunity with a closing window. The following priorities are immediate for both TPRM platform vendors and technology and service providers:

Q-Day is not a risk event. The risk event is the moment your board asks what your vendors’ quantum exposure is across your critical data flows, and there’s no answer ready. For vendors, it’s the same moment from the other side: a customer asks, and there’s nothing to hand them.

The post Quantum Risk Is Already Here: What Buyers Must Demand and Vendors Must Build appeared first on IDC .

Источник: IDC