Evaluating third-party readiness for post-quantum cryptography – a guide published by the Australian Signals Directorate here:

From the guidelines:
“This publication provides a structured set of questions organisations can use to assess how prepared their vendors are for the transition to PQC. In this publication, the term ‘vendor’ refers to third-party suppliers of products or services. It covers key areas including cryptographic dependencies, risk assessment, transition planning, implementation approaches, and communication with suppliers throughout the transition process. The guidance helps organisations understand supply chain dependencies and identify factors that could affect their ability to adopt PQC within recommended timeframes. It is intended for cyber security leaders, procurement and vendor management teams, and technical stakeholders responsible for assessing third-party products and services.

Key actions to take:

  • Understand your organisation’s cryptographic dependencies and vendor-related risks.
  • Assess vendor readiness for PQC using the recommended questions.
  • Engage suppliers and service providers early to support PQC transition planning.
  • Incorporate PQC considerations into procurement, contract renewal and vendor assurance activities.”