All resources
Third-Party and Ecosystem Post-Quantum Risk
Assessing third-party readiness without system access
Direct audits of suppliers are often impossible or disproportionate. Assessment relies on vendor roadmaps, public statements, contractual commitments, questionnaires. Dimensions: awareness of PQC risk, roadmap existence, crypto agility, dependency transparency. Goal is informed risk classification, not certification.