Development and Preliminary Validation of PQC-ORI: A Public-Sector Readiness Assessment Instrument for Post-Quantum Cryptography

Authors

  • Fadlilah Izzatus Sabila Nasional University image/svg+xml Author
  • Fauziah Author

DOI:

https://doi.org/10.35760/ik.2026.v31i1.325

Keywords:

Post-Quantum Cryptography, Organizational Readiness Framework, Readiness Assessment Instrument, Design Science Research, Public Sector

Abstract

The emergence of quantum computing technologies poses significant risks to conventional public-key cryptographic systems and creating an urgent need for organizational preparation toward Post-Quantum Cryptography (PQC) migration. Although various PQC migration frameworks and quantum-readiness initiatives have been proposed, existing approaches primarily focus on technical migration guidance and provide limited operational mechanisms for assessing organizational readiness, particularly within public-sector environments. This study develops and conducts a preliminary validation of a Post-Quantum Cryptography Organizational Readiness Instrument (PQC-ORI) for Indonesian public-sector organizations using a Design Science Research approach integrating Systematic Literature Review (SLR), Qualitative Content Analysis (QCA), and Framework Alignment Matrix (FAM) techniques to synthesize recurring organizational readiness constructs from PQC migration literature, governance frameworks, and cybersecurity readiness studies. The resulting framework comprises six organizational readiness dimensions: Cryptographic Awareness, Governance and Policy, Migration Management, Technical Capability, Cryptographic Agility, and Operational Resilience. The framework additionally operationalizes these dimensions into structured assessment indicators and a five-level maturity model intended to support organizational self-assessment and migration planning activities. Preliminary validation by three domain experts using structured expert judgment yielded an overall mean score of 3.69/4.00, indicating high relevance, conceptual consistency, and applicability for assessing organizational readiness for PQC migration in public-sector organizations.

References

[1] P. W. Shor, “Algorithms for quantum computation: Discrete logarithms and factoring,” Proceedings - Annual IEEE Symposium on Foundations of Computer Science, FOCS, pp. 124–134, 1994, doi: 10.1109/SFCS.1994.365700.

[2] M. Mosca and M. Piani, “Quantum Threat Timeline Report 2024,” 2024. Accessed: Nov. 28, 2025. [Online]. Available: https://globalriskinstitute.org/publication/2024-quantum-threat-timeline-report/

[3] ETSI, “Cyber Security (CYBER); Quantum-Safe Cryptography (QSC); Efficient Quantum-Safe Hybrid Key Exchanges with Hidden Access Policies ,” Valbonne, Feb. 2025.

[4] NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” USA, Aug. 2023. Accessed: Nov. 28, 2025. [Online]. Available: https://media.defense.gov/2023/Aug/21/2003284212/-1/-1/0/CSI-QUANTUM-READINESS.PDF

[5] World Economic Forum and Deloitte, “Quantum Readiness Toolkit: Building a Quantum-Secure Economy,” Jun. 2023.

[6] CSA, “Quantum-Safe Handbook and Quantum Readiness Index | Cyber Security Agency of Singapore,” 2025. Accessed: Nov. 28, 2025. [Online]. Available: https://www.csa.gov.sg/resources/publications/quantum-safe-handbook-and-quantum-readiness-index/

[7] QRWG of CFDIR, “Canadian National Quantum-Readiness,” Canada, Jul. 2024.

[8] BSSN, “Panduan Migrasi Ke Post-Quantum Cryptography Versi 1.0,” Bogorm West Java, Jan. 2026.

[9] ETDA, “PQC Migration Handbook for Thai Organizations,” 2026, [Online]. Available: https://qtft.github.io/pq-readiness-handbook/

[10] AIVD, CWI, and TNO, “The PQC Migration Handbook Guidelines for MIgrating to Post-Quantum Cryptography,” Dec. 2024.

[11] CERT-In and SISA, “Transitioning to Quantum Cyber Readiness.”

[12] Ward. Beullens et al., Post-quantum Cryptography : Current State and Quantum Mitigation. [Publications Office of the European Union], 2021.

[13] I. Kong, M. Janssen, and N. Bharosa, “Navigating Through the Unknowns-Organizational Readiness Assessment Model for Quantum-Safe Transition,” in Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), Springer Science and Business Media Deutschland GmbH, 2024, pp. 438–453. doi: 10.1007/978-3-031-70274-7_27.

[14] J. Hohm, A. Heinemann, and A. Wiesmaier, “Towards a Maturity Model for Crypto-Agility Assessment,” in Foundations and Practice of Security, L. and A. C. and S. F. and G.-A. J. Jourdan Guy-Vincent and Mounier, Ed., Cham: Springer Nature Switzerland, 2023, pp. 104–119.

[15] A. I. Weinberg, “Preparing for the Post Quantum Era: Quantum Ready Architecture for Security and Risk Management (QUASAR) - A Strategic Framework for Cybersecurity,” May 2025, [Online]. Available: http://arxiv.org/abs/2505.17034

[16] B. H. H. Al-Dulaimi, “TQSDRM: Towards Quantum Software Development Readiness Model (RMQuantum),” 2024.

[17] M. Teitsma, I. Ahmed, and J. van Velzen, “Quantum Organisational Readiness Levels,” Feb. 2025, Accessed: Nov. 26, 2025. [Online]. Available: https://arxiv.org/pdf/2502.16489

[18] T. Hardiana and S. Suhardi, “Design of a Cybersecurity Maturity Measurement Instrument for the Government Sector,” Jurnal Pendidikan dan Teknologi Indonesia, vol. 5, no. 11, pp. 3393–3310, Nov. 2025, doi: 10.52436/1.jpti.1124.

[19] US Department of Energy, “Cybersecurity Capability Maturity Model (C2M2),” Jun. 2022.

[20] Š. Grigaliūnas and R. Brūzgienė, “Towards a Unified Quantum Risk Assessment,” Electronics 2025, Vol. 14, Page 3338, vol. 14, no. 17, p. 3338, Aug. 2025, doi: 10.3390/ELECTRONICS14173338.

[21] A. R. Hevner, S. T. March, J. Park, and S. Ram, “Design Science in Information Systems Research 1,” Design Science in IS Research MIS Quarterly, vol. 28, no. 1, p. 75, 2004.

[22] K. Peffers, T. Tuunanen, M. A. Rothenberger, and S. Chatterjee, “A design science research methodology for information systems research,” Journal of Management Information Systems, vol. 24, no. 3, pp. 45–77, Dec. 2007, doi: 10.2753/MIS0742-1222240302;PAGE:STRING:ARTICLE/CHAPTER.

[23] H. F. Hsieh and S. E. Shannon, “Three approaches to qualitative content analysis,” Qual. Health Res., vol. 15, no. 9, pp. 1277–1288, Nov. 2005, doi: 10.1177/1049732305276687.

[24] J. M. Corbin and A. Strauss, “Grounded theory research: Procedures, canons, and evaluative criteria,” Qual. Sociol., vol. 13, no. 1, pp. 3–21, Mar. 1990, doi: 10.1007/BF00988593.

[25] “PRISMA 2020 flow diagram — PRISMA statement.” Accessed: Jul. 19, 2026. [Online]. Available: https://www.prisma-statement.org/prisma-2020-flow-diagram

[26] V. Erol, “Quantum Readiness in Cryptography: A Maturity-Based Framework for Post-Quantum Transition,” Oct. 02, 2025. doi: 10.20944/preprints202509.2584.v1.

[27] NIST, “Transition to Post-Quantum Cryptography Standards,” 2024, doi: 10.6028/NIST.IR.8547.IPD.

[28] ETSI, “TR 103 619 - V1.1.1 - CYBER; Migration strategies and recommendations to Quantum Safe schemes,” Jul. 2020.

[29] CSA, “(Draft for Public Consultation) Quantum-Safe Handbook,” Singapore, Oct. 2025.

Downloads

Published

2026-07-31

Issue

Section

Articles

How to Cite

Sabila, F. I., & Fauziah. (2026). Development and Preliminary Validation of PQC-ORI: A Public-Sector Readiness Assessment Instrument for Post-Quantum Cryptography. Jurnal Ilmiah Informatika Komputer, 31(1), 14-30. https://doi.org/10.35760/ik.2026.v31i1.325

Most read articles by the same author(s)

Similar Articles

11-11 of 11

You may also start an advanced similarity search for this article.