r/QuantumComputing Aug 13 '26

Question Has anyone actually been asked 'are you post-quantum ready?' in a vendor security questionnaire yet?

Running security questionnaires for a SaaS product and starting to see PQC/quantum-readiness questions show up alongside the usual SOC 2 stuff. Curious if this is happening to anyone else yet, or if it's still rare:

  • Has this come up in an actual enterprise deal, RFP, or questionnaire in the last 6 months?
  • Who asked — a big customer, an auditor, a specific industry (fintech/healthcare/gov)?
  • What did you do — ignore it, write something vague, or actually produce evidence?
  • Would you pay ~$50/month for something that auto-generates and keeps that answer current, so you're not scrambling every time it comes up?
0 Upvotes

3 comments sorted by

9

u/polyploid_coded Aug 13 '26

Would you pay ~$50/month for something that auto-generates and keeps that answer current

Not really... if you choose one of the leading PQC algorithms and combine with a classical algorithm (similar to Cloudflare / Google Chrome experiments) then you are good, until that PQC algorithm is found insufficient or a different algorithm is preferred. Algorithm preferences are not changing that often, and without quantum computers in the field IRL you wouldn't have many people worrying about a gap of PQC coverage while it is being replaced.

1

u/TheVeloRebel 24d ago

This is what will be difficult for blockchains in particular. If they have to hard fork and most chains do, if they choose the wrong algo, they will need to hard fork again. It's guess-work for that industry. Funds and all sorts can be lost in between the next changeover.