For Windows administrators, PKI teams, security architects, and application owners, the relevant change is not a new public post-quantum certificate service. Quantum Ready is a discovery and planning layer: it is intended to locate cryptographic assets and their dependencies, assess exposure, and help organizations decide what to migrate first. Sectigo says availability is currently limited to qualified early-access participants, so this is not yet a generally available platform rollout.
The immediate problem is cryptographic visibility
Post-quantum cryptography migration is often described as an algorithm-replacement exercise: move away from quantum-vulnerable public-key cryptography such as RSA and elliptic-curve cryptography toward NIST-standardized alternatives. In practice, the first hurdle is more basic. An organization cannot safely replace cryptography it has not located, assigned to an owner, and connected to the application or service that relies on it.
That cryptography is spread much more widely than a central certificate authority console. A Windows-based estate can contain TLS certificates on IIS servers and reverse proxies; code-signing certificates in build pipelines; smart-card and certificate-based authentication systems; VPN and remote-access infrastructure; device management tooling; SQL or file-encryption dependencies; third-party appliances; and applications that bundle their own cryptographic libraries.
NIST’s migration guidance identifies cryptographic discovery and inventory as a starting point for post-quantum preparation. Its definition of a cryptographic inventory includes algorithms, protocols, keys, certificates, systems, components, dependencies, and the data flows protected by them. The inventory should identify metadata about keys and certificates, rather than collect sensitive private-key material itself.
Sectigo’s pitch is that Quantum Ready can turn that work into an ongoing operational process rather than a spreadsheet or a one-off assessment.
What Sectigo Quantum Ready is designed to do
According to Sectigo’s launch material, Quantum Ready builds a Cryptographic Bill of Materials, or CBOM. In this context, a CBOM is an inventory that associates cryptographic assets with the systems, applications, services, and business dependencies that use them.
The product is organized around three stages:
- It discovers cryptographic assets, dependencies, and areas of post-quantum exposure across an environment.
- It assesses and prioritizes the findings based on factors including business criticality, data sensitivity, migration complexity, and dependencies.
- It connects the resulting plan to Sectigo Certificate Manager, its existing certificate lifecycle management platform, for the management and orchestration portion of cryptographic change.
The distinction between the first two stages and the last one is important. A scanner can identify certificates and exposed TLS services, but replacing a certificate or algorithm inside a production application can involve vendor support, protocol compatibility, hardware restrictions, service downtime, and rollback planning. Sectigo Certificate Manager may automate certificate lifecycle work where it is already integrated, but it does not make every cryptographic dependency immediately replaceable.
Sectigo’s stated goal is crypto agility: the ability to identify cryptographic dependencies, alter them in a controlled way, and continue adapting as standards and threats change. That is a broader operational capability than issuing a different kind of certificate.
QSPM is a framework, not a new cryptographic standard
Quantum Security Posture Management is an emerging product-category label rather than a standard defined by NIST or a regulatory requirement in its own right. Sectigo uses the term to group continuous discovery, risk prioritization, migration planning, governance, and lifecycle automation into one operating model.
The underlying work is well established. NIST’s National Cybersecurity Center of Excellence has a Migration to Post-Quantum Cryptography project with a cryptographic-discovery workstream specifically focused on helping organizations understand where and how they use cryptography. NIST has also encouraged organizations to start inventorying encrypted systems and planning their transitions now.
NIST finalized its first three PQC standards in 2024: ML-KEM for key establishment, plus ML-DSA and SLH-DSA for digital signatures. Those standards give vendors and organizations standardized targets, but adopting them still requires product support and interoperability testing. A certificate inventory is therefore useful only if it helps a team establish the next facts: which systems use vulnerable public-key cryptography, whether their suppliers support PQC, what protocol and application changes are necessary, and how each change can be validated.
That makes Sectigo Quantum Ready potentially useful as a visibility and prioritization product. It should not be interpreted as evidence that a company’s environment has already become quantum-safe.
What early access does and does not include
Sectigo’s early-access FAQ places several boundaries around the offering:
- Early access is for qualified customers that want to evaluate Quantum Ready in their own environment and provide product feedback.
- The expected outputs are a cryptographic inventory, dependency context, exposure assessment, and prioritized readiness plan.
- The program does not include production-ready public post-quantum certificates.
- Controlled testing of post-quantum certificates may be available separately through Sectigo’s private PQC offerings.
Those limits are material for enterprises preparing Windows and hybrid-cloud infrastructure. A discovery platform can help determine where certificates, keys, and vulnerable algorithms are used. It cannot on its own guarantee that an older Windows application, network appliance, hardware security module, SaaS connector, or third-party library can accept new post-quantum algorithms.
Organizations evaluating the early-access program should ask Sectigo which data sources and protocols the discovery engine covers, how it identifies application-level cryptography that may not be externally visible, how results are updated, and how the service handles credentials and sensitive inventory information. They should also clarify whether integration with Sectigo Certificate Manager is required for remediation workflows, and which certificate types or environments can be managed through that integration.
A sensible evaluation checklist
For enterprises that already use Sectigo Certificate Manager or need to start a PQC inventory, an evaluation should be framed as a discovery project rather than an immediate migration commitment.
- Define the scope before scanning. Include Windows Server PKI, Active Directory Certificate Services where applicable, IIS and API endpoints, VPNs, code-signing workflows, endpoint-management infrastructure, cloud workloads, and business-critical third-party products.
- Identify the data that needs long-term protection. “Harvest now, decrypt later” risk is most relevant where encrypted data could retain value years into the future. Prioritization should account for data sensitivity and retention, not merely the number of certificates found.
- Assign owners to findings. A CBOM is more useful when each system, certificate, protocol, or cryptographic library has an accountable application or infrastructure owner. Otherwise, discovery simply creates a larger queue of unassigned work.
- Separate certificate automation from application remediation. Rotating a certificate can be comparatively straightforward. Replacing a cryptographic protocol or embedded library may require software upgrades, testing, vendor commitments, and coordinated change windows.
- Test interoperability before making production changes. PQC introduces new key sizes, signature behavior, protocol support questions, and performance considerations. Sectigo’s private PQC testing options may be relevant here, but organizations should treat any sandbox or proof of concept as distinct from a production deployment.
- Keep the inventory alive. New applications, certificate renewals, acquisitions, cloud services, and vendor updates continually change an organization’s cryptographic footprint. The value proposition of a QSPM-style service rests on maintaining and acting on that inventory over time.
The practical takeaway
Sectigo Quantum Ready addresses a real part of the post-quantum transition: finding cryptography, understanding what depends on it, and converting a technical inventory into an ordered migration plan. NIST’s own migration work supports the importance of that discovery phase, especially for organizations with mixed Windows, cloud, network, and third-party environments.
The immediate limitation is availability and scope. Quantum Ready is a limited early-access product, and Sectigo has not positioned it as a production public-PQC certificate offering. Enterprises should view it as a possible way to accelerate cryptographic discovery and prioritization—particularly if they already operate Sectigo Certificate Manager—not as a shortcut around the compatibility testing and application modernization that a full PQC migration will still require.