up:: For Business Leaders MOC

What should I ask my own security team?

Five questions, none of which require you to understand cryptography to evaluate the answer.

They work because each one has a factual answer that either exists or doesn’t. A team that has started this work answers all 5 in a few minutes. A team that hasn’t will produce reassurance, and reassurance is distinguishable from an answer once you know what you’re listening for.

The purpose here is finding out where you stand, and a truthful “we haven’t started” is the most useful outcome you can get. It’s the answer that makes the next decision fundable.

The short version:

  • Question 1 is the inventory. Where does our encryption live, listed by algorithm, and when was that list last updated?
  • Question 2 is the deadline. What’s the earliest date in our own contracts and certifications that requires this, and where’s it written?
  • Question 3 is the data. Which records do we hold that stay sensitive past that date?
  • Question 4 is the vendors. Which suppliers have given us a dated commitment in writing?
  • Question 5 is ownership. Who’s accountable, and what happens if they leave?
  • A useful meeting ends with a date on the calendar to come back with what’s missing, rather than with a reassurance you can’t verify.

What are the 5 questions?

1. Where does our encryption live, and when did we last check?

You’re asking whether an inventory exists at the algorithm level, meaning a list that names which specific encryption each system uses rather than confirming that encryption is present.

A substantive answer names the systems covered, names what’s outside the scope so far, gives a date the list was last refreshed, and says how it was produced.

An answer that means no sounds like “everything is encrypted,” “we use industry-standard encryption,” or “our tools would flag it.” Those describe a posture rather than an inventory, and none of them can be used to plan a migration.

This question comes first for a reason every published migration guide agrees on: prioritizing, pricing, and sequencing all depend on knowing what you have. U.S. federal civilian agencies have been required to submit a prioritized cryptographic inventory every year since May 2023, and the same requirement is what produced the government’s own cost figure.

Source: Office of Management and Budget, “Migrating to Post-Quantum Cryptography,” Memorandum M-23-02, November 18, 2022, OMB M-23-02.

2. What’s our earliest binding date, and where is it written?

You’re asking for a specific date traced to a specific document, which is usually a contract clause, a certification requirement, or a customer’s security addendum rather than a law naming your company.

A substantive answer sounds like a date, an instrument, and a business surface: “December 2027, from the EU product regulation, and it attaches to our connected product line.”

An answer that means no is “2035,” which is the most-quoted date and the softest one. The obligations that bite land years earlier, and they usually arrive through paperwork your company already signed.

The follow-up worth asking when somebody quotes a standard: which approved list does that point at, and what happens to that list after 2030?

3. Which of our records stay sensitive past that date?

You’re asking whether anybody has sorted the data by how long it has to stay confidential. This is the question that decides what moves first, and it’s answerable by business owners rather than engineers.

A substantive answer names data categories with confidentiality lifetimes attached, and identifies which of those categories crosses networks under encryption today.

An answer that means no treats all data as equally urgent, which produces a plan nobody can fund. See What of our company data is at risk.

4. Which vendors have given us a dated commitment in writing?

You’re asking about the share of the estate your own team can’t fix. See What can I not fix myself.

A substantive answer is a short list, because most suppliers haven’t made one yet, and it includes the renewal dates where the question can be raised with leverage.

An answer that means no is “our vendors are handling it.” A roadmap statement is a promise about the future, and only the contract makes it an obligation.

5. Who owns this, and what happens if they leave tomorrow?

You’re asking whether accountability is assigned to a person with the authority to move budget across teams, and whether the work survives their departure.

A substantive answer names 1 person, describes what’s in their objectives, and points at where the exposure is recorded.

An answer that means no describes a committee, or names a person whose actual job is something else and who does this when time allows. Ambiguous ownership is the most common reason a program never starts.

How do we read the answers?

QuestionA yes looks likeA no sounds like
1. InventoryA dated list naming algorithms and scope”Everything’s encrypted”
2. Binding dateA date plus the document it came from”2035”
3. Data lifetimesCategories with years attached”All our data is sensitive”
4. VendorsA short list with renewal dates”Our vendors are handling it”
5. Ownership1 named person with it in their objectivesA committee, or a volunteer

The pattern to watch for across all 5 is the difference between a fact and a posture. Facts have dates, names, and documents attached. Postures describe how seriously the organization takes security, which is a different subject.

What if the answers are mostly “we haven’t done that yet”?

That’s a normal place to be. The replacement standards were only finalized on August 13, 2024, and the U.S. government’s own schedule for migrating federal civilian systems runs from 2025 to 2035, which is the pace of the organization that wrote the requirement.

Source: NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024, nist.gov.

The productive response is 3 decisions rather than a reprimand:

  1. Fund a scoped inventory. Time-boxed, aimed at your most sensitive systems rather than the whole estate. It answers question 1 and produces the inputs to everything else.
  2. Name an accountable owner. One executive, senior enough to move budget across teams, with this written into their objectives.
  3. Set a return date. A specific meeting to come back with the inventory results, the binding date with its source, and a costed plan.

Those 3 decisions are the same thing a board approves in a well-run version of this conversation, and they commit the organization to nothing beyond knowing where it stands. See How do I explain this to my board.

What are we not asking them for?

Three things, because asking for them turns a productive meeting into a defensive one.

  • A prediction of when quantum computers arrive. Nobody credible has that date, and a team pushed to produce one will either guess or dismiss the whole subject.
  • A total program cost before the inventory. The number comes out of discovery, so a figure quoted before it has nothing behind it. See What does this cost.
  • A guarantee that nothing has been copied already. Copying encrypted traffic leaves no trace, so nobody can prove it did or didn’t happen. See Is someone stealing my data right now.

Asking for any of those 3 punishes honesty, and the answers you actually need all depend on the team being willing to say what it doesn’t know.

Questions people ask

Isn’t this the CISO’s job rather than mine? The execution is. The dated obligation, the budget, and the accountability sit at the executive and board level, and directors who ask these 5 questions on a schedule are the reason the program gets resourced.

How often should I ask? Annually is enough for questions 2 through 5. Question 1 has a shorter shelf life, because an inventory goes stale as the estate changes.

What if my security team says this is overhyped? Some of the skepticism is well-founded, and the parts that survive it are the dated obligations and the data lifetimes, neither of which depends on a quantum computer arriving on schedule. See Is this overhyped.

We’re a small company with no security team. Now what? The same 5 questions go to whoever runs your IT, and 3 of them go to your major software vendors instead. A small estate is genuinely easier to inventory, which is an advantage rather than a consolation.

What’s the single most revealing question? Question 1. An organization with a current algorithm-level inventory has almost certainly done the rest, and one without it hasn’t started regardless of what the other answers say.

Should I bring an outside party in? Worth considering when the estate is large, vendor-heavy, or the answer has to satisfy a regulator or an auditor. A capable internal team can run the first inventory without help.

What if the answers are good? Then ask what they need to keep going, and put the return date on the calendar anyway. A program with executive attention on a schedule is measurably different from one without it.

Where to go next

Go deeper into the technical detail

The technical versions are The Binding-Date Questions, Cryptographic Discovery, and The Four Questions.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.