Siam Thanat Hack Co., Ltd.

NCSA Guidelines for Post-Quantum Readiness

A source-based guide to NCSA's Guidelines for Post-Quantum Readiness for government agencies and critical information infrastructure organizations that process confidential information, focusing on risk assessment, asset inventories, and cryptographic transition planning.

Scope and the quantum risk to assess first

The document is practical guidance rather than a binding notification. It targets government agencies and CII organizations that collect, use, exchange, or disclose confidential information through information systems.

Thai infographic explaining: Scope and the quantum risk to assess first
Visual guide: Scope and the quantum risk to assess first
  • Large-scale quantum computing threatens public-key cryptography such as RSA, Diffie-Hellman, and ECC, which underpin key exchange, digital signatures, and authentication in today's systems.
  • Assess Harvest Now, Decrypt Later: an attacker can collect encrypted data now and wait to decrypt it in the future.
  • Data that must remain confidential for a long time, including personal, financial, and health data, should be prioritized for assessment.

Use the Mosca model to prioritize transition

The guidance assesses risk through the relationship between the time an organization needs to migrate, the required secrecy lifetime of data, and the time until a capable quantum threat emerges.

Thai infographic explaining: Use the Mosca model to prioritize transition
Visual guide: Use the Mosca model to prioritize transition
  • Migration Time covers the time needed to change systems and supporting infrastructure, including PKI, applications, devices, and technical partners.
  • Security Shelf Life is how long data must remain confidential and trustworthy after storage or transmission.
  • Threat Timeline is the expected time until an attacker has sufficient quantum capability. When migration time plus security shelf life exceeds that timeline, planning should begin immediately.

PQC, QKD, and transition design

The guidance discusses Post-Quantum Cryptography (PQC), Quantum Key Distribution (QKD), and hybrid approaches so each system can be assessed against its own risk and constraints.

Thai infographic explaining: PQC, QKD, and transition design
Visual guide: PQC, QKD, and transition design
  • PQC uses algorithms designed to resist quantum-computing attacks and should be tested for compatibility with real systems before broad adoption.
  • QKD has key-exchange-rate, hardware, authentication, and device-security limitations, so it may suit specific uses rather than serving as a universal answer.
  • A hybrid approach can combine existing cryptography with PQC during transition, with assessment of performance, network, hardware, and operational effects.

A seven-step roadmap and the evidence to start collecting

The guidance sets out seven readiness steps that executives, managers, and operational teams must advance together rather than treating the work as a one-point algorithm replacement.

Thai infographic explaining: A seven-step roadmap and the evidence to start collecting
Visual guide: A seven-step roadmap and the evidence to start collecting
  • 1. Create a roadmap: assign capable staff to plan the organization's quantum-readiness work. Starting early supports a smoother transition and a more credible investment estimate; the planner does not need to be a quantum specialist at the outset.
  • 2. Build awareness: help every relevant function understand the technology and quantum threat, including procurement teams so software and hardware choices consider resistance to quantum-computing attacks.
  • 3. Define responsibilities: assign readiness responsibilities across the relevant functions and ensure staff understand the cryptographic technologies the organization uses, even when it does not build its own software.
  • 4. Inventory information assets: create an IT Asset Inventory of cryptography-relevant software and hardware so the organization understands how keys are created, stored, and used.
  • 5. Assess technology options: assess suitability, performance, advantages, and limitations of PQC or QKD for each system component, including the feasibility of a hybrid approach.
  • 6. Pilot and test: begin testing relevant systems and technologies before standards are fully mature to learn about compatibility, impact, and issues caused by cryptographic change.
  • 7. Track progress continuously: monitor organizational readiness and periodically reassess risk and the threat timeline so the plan remains current.

PQC BY STH

Check a website's PQC readiness for free

Start with internet-facing assets: PQC by STH inspects the TLS configuration a website presents, helping teams identify algorithms and readiness signals for a Post-Quantum Cryptography transition.

This result is a starting point for a Crypto Assets Inventory, not a security certification or a complete assessment of internal systems.

Check a website with PQC by STH

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofNCSA Guidelines for Post-Quantum Readiness

NCSA Guidelines for Post-Quantum Readiness

By NCSA

Open document (PDF) Source