With the inventory in hand the organisation assesses, per system or application, the risk that a large quantum computer poses to its cryptography, first judging which attackers are realistic for it (state actors and highly capable attackers initially, others later as capability becomes available as a service). Three scores are combined: quantum weakness (0 safe, 1 needs attention in future such as symmetric algorithms and hashes, 2 must be replaced), taken at application level as the highest score among the algorithms used, or the lowest where algorithms are layered together in a hybrid combination; impact (1 no significant impact, 2 realistic attacker but not in the short term or high-impact authentication, 3 data intercepted now that stays sensitive for ten to twenty years); and migration effort (1 up to two years, 2 up to eight years, 3 more than eight years, judged from management maturity, standardisation and regulatory, supplier and hardware dependencies, hardware limits and in-house skills). The combined score from 0 (no risk) to 4 (acute) is prioritised according to the persona and risk appetite, integrated into existing risk management, and repeated periodically.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.