Independently of the quantum question, the organisation works towards mature cryptographic management: a full view of all cryptographic assets it holds, insight into the risks attached to them, a cryptographic policy consistent with applicable rules, and continuous monitoring and updating of all three. Diagnosis, risk assessment, policy and the resulting priority list of systems, applications and data to migrate are reassessed periodically, the quantum risk is integrated into existing risk management and linked to core business processes, centralised cryptography management is considered for visibility, and where suppliers manage the cryptography the organisation checks that their timelines match its own, otherwise it changes supplier or takes over the cryptography.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.