ASD issues advice on assessing vendor PQC readiness
The Australian Signals Directorate (ASD) has released new guidance to help organisations assess vendor readiness for post-quantum cryptography, saying vendor readiness may be one of the biggest factors influencing an organisation’s ability to transition to post-quantum cryptography (PQC) within recommended timeframes.
The publication Post-quantum questions to ask your vendors is designed to help organisations assess the readiness of third-party suppliers of products or services for the transition to PQC.
Future advances in quantum computing are expected to undermine widely used traditional public-key cryptographic algorithms. PQC includes cryptographic algorithms that are designed to remain secure against attacks from both classical and quantum computers.
As organisations prepare for this transition, third-party products and services will play a critical role in supporting the adoption of quantum-resistant cryptography within recommended timeframes.
ASD says the publication provides practical, vendor-neutral questions that organisations can use during procurement activities, contract renewals and vendor assurance processes. The guidance helps organisations:
- identify cryptographic dependencies
- assess quantum-related risks
- prioritise transition activities
- evaluate PQC implementation plans
- maintain effective vendor engagement throughout the transition.
The resource is intended for cybersecurity leaders, procurement and vendor management teams, and technical stakeholders responsible for assessing third-party readiness for PQC. It supports a risk-based approach to understanding supply chain dependencies and preparing for the adoption of PQC.
The publication can also help vendors understand customer expectations for PQC preparedness, and to assess their own product and service providers.
Learn more through the Post-quantum questions to ask your vendors publication.
ASD recommends improving router hygiene to counter Russian threat
Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly...
ACSC releases cybersecurity video training for privileged users
A series of training videos offers a practical, engaging way for privileged information and...
ACSC critical alert for Fortinet Firewalls and VPN Gateways
The Australian Cyber Security Centre has raised an alert that it is aware a widespread malicious...
