On 16 July 2026, the Australian Signals Directorate (ASD) released a new publication, Post-quantum questions to ask your vendors — a structured, vendor-neutral set of questions organisations can use to assess how prepared their third-party suppliers are for the transition to post-quantum cryptography (PQC).

It is a deceptively practical document. Behind the question format sits a simple point — for many organisations, the pace of the post-quantum transition depends heavily on their vendors. ASD puts it plainly: vendor readiness may be one of the biggest factors influencing an organisation's ability to transition to PQC within recommended timeframes.

This article summarises the guidance for two audiences: organisations choosing or reviewing vendors, and software vendors who will increasingly find these questions landing in their inbox.

Why this matters — the short version

What the guidance contains

The publication (with a companion quick-reference PDF, both free on cyber.gov.au) sets out 31 questions across five phases, aligned to ASD's LATICE framework from its Planning for post-quantum cryptography guidance:

PhaseQuestionsFocus
Locate8Where cryptography lives — inventories (CBOMs), hardcoded or hardware-bound crypto, third-party dependencies, firmware and roots of trust
Assess6Which data flows and trust decisions rely on traditional asymmetric cryptography, data lifetimes, documented CRQC risk assessments
Triage5Whether vendor transition plans and sequencing align with your risk priorities and the end-of-2030 milestone
Implement6Standards-based algorithms, production readiness, library validation, key and certificate changes, licensing
Communicate & educate6Change notification, transition guides, deprecation of traditional cryptography, trained support teams

Each question comes with an explanation of why it matters and what a good answer looks like. The guidance is intended for cyber security leaders, procurement and vendor-management teams, and technical stakeholders — and it is written to be used in procurement, contract renewals and ongoing vendor assurance, not as a one-off audit.

Importantly, ASD notes cryptographic exposure extends well beyond cloud and SaaS: it is often embedded and hard to update in on-premises systems, legacy systems, operational technology, Internet of Things devices, building management systems, and physical access and security systems.

Summary for organisations reviewing or choosing a vendor

You are not expected to ask every question of every vendor. ASD is explicit: apply the questions based on the risk level of the product or service, how much cryptographic control the vendor exercises, the sensitivity and longevity of the data involved, and where you are in your own PQC transition.

If you only have time for a handful, these (adapted from the guidance) reveal the most:

  1. "Do you maintain a current inventory of cryptographic dependencies — a cryptographic bill of materials (CBOM) or equivalent?" A vendor that can't say where its cryptography is can't credibly plan to replace it.
  2. "Which products or services will be PQC-ready early enough to support our rollout before the end of 2030?" Look for product-specific, versioned commitments — not general assurances.
  3. "Is PQC included in base licensing?" ASD's rationale: including PQC in base licensing avoids security controls being paywalled, which could delay adoption and lead to uneven risk across customers.
  4. "If you support post-quantum/traditional (PQ/T) hybrid modes, when and how will you move to PQC-only?" Hybrid is a legitimate transitional measure — but only with a documented de-hybridisation plan and timeline.
  5. "What internal governance oversees your PQC transition?" Executive ownership, documented decision forums and regular review cycles are what separate a roadmap from a press release.

Watch for these red flags. ASD lists seven common concerns in vendor responses: limited visibility of cryptographic use; reliance on general assurances; unclear or deferred transition timelines; use of proprietary or opaque cryptography; treatment of PQC as an optional or premium function; over-reliance on compensating controls; and lack of governance or ownership. None is an automatic disqualifier — but each may warrant follow-up, depending on the vendor's risk level and what they supply, and ASD makes the point that a vendor's willingness to engage transparently is itself a signal of maturity, in PQC and in cyber security generally.

Build it into process, not projects. The guidance recommends engaging vendors early — before long-term contracts or cloud agreements lock in cryptographic choices that are difficult to change — and incorporating PQC considerations into procurement, contract renewal and vendor assurance as standing agenda items. Early, structured engagement is what prevents the late-stage surprise of discovering a critical product cannot support PQC within required timeframes.

Summary for software vendors

Read from the other side of the table, the publication is effectively a preview of your customers' next security questionnaire. ASD says as much: the guidance can also help vendors understand customer expectations for PQC preparedness — and assess their own suppliers, because your customers' questions about your third-party dependencies become your questions to your vendors.

What good looks like, distilled from ASD's "key response considerations":

Vendors who can answer these questions well won't just pass procurement gates — they'll shorten their customers' transitions.

A note for aged-care and health providers

Our commentary, beyond the ASD text: two aspects of this guidance land particularly heavily in care settings. First, data longevity — clinical and care records carry confidentiality obligations that span decades, exactly the profile 'harvest now, decrypt later' targets, which argues for asking the data-lifetime questions of any vendor holding care records. Second, embedded systems — ASD's list of hard-to-update environments (building management, physical access and security systems, IoT, legacy platforms) describes much of a modern care facility. These are long-lifecycle assets where cryptography may be fixed in hardware; the time to ask about PQC is before the next procurement, not after.

Reporting cyber culture to your board? Get our free Security Awareness & Culture Board Dashboard — an editable, board-ready dashboard structured on the SANS Security Awareness & Culture Maturity Model™. It runs in your browser, your figures never leave your device, and it prints a one-page board pack.

Sources

This article is general information and decision support, not legal, technical or professional advice. Assess the guidance against your own circumstances, and rely on the current ASD publications as the authoritative source.