PQC supplier questions after G7 call
Practical perspective from an IT leader working across operations, security, automation, and change.
5 minute read with practical, decision-oriented guidance.
Leaders and operators looking for concise, actionable takeaways.
Topics covered
Retrospective covering 7 September 2026, written on 9 September 2026.
PQC supplier questions should now be part of renewal planning for services that protect important information. My recommendation is to ask suppliers for a product-specific transition plan and evidence of its scope. A general promise about quantum readiness does not show whether your organisation's actual connections and applications are covered.
The G7 Cybersecurity Working Group's call to action, described on a Canadian Cyber Centre page dated 3 September and covered by ITPro on 7 September, urged a phased transition to post-quantum cryptography. It highlighted uncertainty about the arrival of relevant quantum computers and the risk of encrypted information being collected for later decryption. Official publication, 7 September coverage.
Turn the warning into a procurement question
The official call includes integrating PQC into cybersecurity requirements and identifying cryptographic assets and dependencies. That makes a supplier conversation a concrete first step, rather than waiting for a complete internal migration programme. Canadian Cyber Centre summary.
Start with the services your organisation actually buys. Ask which ones protect information that needs to remain confidential for a long time, which support important authentication and which would be difficult to change quickly. Your business owners should help determine those priorities.
Use the existing post-quantum implementation checklist for the wider programme. This article concentrates on obtaining usable supplier answers at procurement and renewal, rather than repeating that technical checklist.
Ask what the roadmap covers
A useful supplier answer names the relevant product, version and configuration. Ask whether the statement concerns a released capability, a preview or future work. Keep those categories separate in your review so an aspiration does not become an assumed control.
Ask the supplier to draw the paths through the service. Which connections, interfaces and supporting components are included? Which depend on another vendor? Have them mark any part that has not yet been assessed.
Do not prescribe an answer before understanding the architecture. Your goal is to establish scope and responsibility. If the supplier cannot explain its dependencies clearly, record that as a gap in the evidence and agree a follow-up.
| Procurement question | Useful answer | Incomplete answer |
|---|---|---|
| Which product is covered? | Named service, version and configuration | Our platform is quantum ready |
| What must the customer do? | Documented prerequisites and change steps | It will be seamless |
| Which dependencies remain? | Named components and responsible suppliers | We use industry standards |
| How will change be validated? | Test evidence and rollback arrangements | Our engineers are working on it |
Separate the promise from delivery
Request the evidence appropriate to the supplier's current stage. A released feature should have documentation and a way to verify the intended configuration. A roadmap should have ownership, dependencies and an update schedule. Neither needs to be presented as more mature than it is.
Ask how customers will hear about changes. A date in a sales presentation is less useful if the service owner never receives an update when it moves. Name the contact in your own organisation who will track the issue and make sure the supplier has that contact.
Where the next renewal is approaching, include the migration dependency in the commercial review. Ask what happens if a required capability remains unavailable during the contract term. The appropriate contractual response belongs with your procurement and legal advisers; the technical team's job is to explain the dependency accurately.
The ICT supplier risk guide gives you a broader structure for recording those discussions and escalating material gaps.
Make testing part of the answer
Ask the supplier how it expects customers to validate the change in their own environment. Include older clients, external partners, specialist applications and recovery processes where they are relevant. Do not assume the newest demonstration represents every device or integration you operate.
Plan a bounded test with the service owner. Record the configuration, the expected business behaviour and the evidence needed to approve rollout. Include a way to stop or reverse the change if the service cannot complete its normal work.
Treat performance and operational support as acceptance questions. Ask who will investigate an unexplained failure and what diagnostic information they will need. A technically promising change still needs a support process that your organisation can use.
Prioritise the suppliers that matter most
Bring procurement, the application owner and the security lead into the same conversation. A roadmap can be technically credible yet unusable if its delivery depends on a renewal decision that nobody has scheduled.
Do not send an enormous questionnaire to every supplier and count replies as progress. Begin with a small set linked to important information or difficult-to-replace services. Use those conversations to improve the questions before expanding the review.
For each supplier, record the business consequence, the relevant product, the current evidence and the next decision. If the answer is incomplete, decide whether to seek clarification, require a test, adjust the renewal or accept a time-bound uncertainty. Give that decision an owner.
Bring material dependencies into the IT risk register. The entry should explain what could affect the business and what is being done, rather than simply stating that quantum computing exists.
My suggested outcome for the next review is a short list of prioritised services with credible supplier contacts and dated evidence requests. That is a manageable action for an SME and a useful foundation for a longer migration. It replaces an abstract future concern with decisions the organisation can track.
Frequently Asked Questions
What should we ask a supplier about post-quantum cryptography?
- Ask which products and connection paths are covered, what dependencies remain, how customers enable the capability and what evidence supports the roadmap. Request a named owner and a date for the next update. A broad statement that the supplier supports quantum-safe technology is not enough to approve your specific service.
Did the G7 announce that current encryption is already broken?
- No. The official publication describes uncertainty about when cryptographically relevant quantum computers will arrive and urges preparation for that risk. It highlights collection of encrypted information for possible later decryption. The appropriate business response is a prioritised transition plan, rather than claiming every existing encrypted service has already failed.
Should an SME replace all encryption immediately?
- A blanket replacement is not the approach described in the official call. Begin with a risk-based inventory, critical systems and dependencies. For an SME, supplier engagement is a practical early step because many relevant components belong to managed services or commercial products. Changes still need compatibility testing and a recovery route.
Share this post
About the author
Daniel J Glover
IT Leader with experience spanning IT management, compliance, development, automation, AI, and project management. I write about technology, leadership, and building better systems.
Continue exploring
Keep building context around this topic
Jump to closely related posts and topic hubs to deepen understanding and discover connected ideas faster.
Explore topic hubs
Related article
Astra cyber safeguards: buying checks
OpenAI's Astra safety update changes the questions buyers should ask about cyber access, interrupted tasks and evidence before approving deployment.
Related article
Astra cyber risk: set a release gate
OpenAI paused some Astra activities over possible critical cyber capabilities. Here is how IT buyers can turn that signal into better release decisions.
Related article
Post-quantum cryptography migration plan
Build a post-quantum cryptography migration strategy covering crypto inventory, risk priorities, vendor readiness and phased adoption.
Related article
School AI contracts: Microsoft's shift
Microsoft and US teaching unions announced AI privacy protections for schools. Here is how UK buyers can turn similar principles into reviewable evidence.
Ready to Improve Your IT Operations?
Book a free 30-minute consultation to discuss your IT challenges. No commitment required, just a focused conversation about where you want to be.
Book a consultationGet Occasional IT Leadership Insights
IT leadership insights, occasionally. No fluff. Unsubscribe any time.
No spam. Unsubscribe any time.