industry · quantum risk
Is Gov suppliers Quantum Proof? Industry Quantum Risk
Verdict
Government suppliers are not quantum-proof by contract boilerplate. RFPs need algorithm-level requirements and evidence, not “encryption in transit” alone.
Overview
Public sector digital transformation is mostly bought. Quantum residual risk often lives in SaaS and equipment vendors.
Use questionnaire and RFP patterns from Wave 7c.
Cryptographic profile
- Signatures: Supplier product TLS and signing, Cloud services used by agencies
- Hash: Contract deliverable integrity
- Public-key exposure: Agencies inherit supplier classical crypto at scale.
- Vertical: government
What breaks
- Checkbox security schedules
- No re-competition trigger for crypto debt
- Accepting AES-only answers for handshake questions
Mitigations
- Standard PQC schedule in RFPs
- Annual crypto evidence refresh
- Tier suppliers by data shelf life
FAQ
Related?
/guides/rfp-pqc-requirements and vendor-risk-pqc
CISA guidance?
/is-quantum-proof/cisa-quantum
Key concepts (technical dictionary)
Terms used on this page — open a definition: