Singapore Cyber Regulator releases Quantum-Safe Migration Handbook and Quantum Readiness Index
Key contacts
July 2026, the Cyber Security Agency ("CSA") released guidance and a self-assessment tool titled “Quantum-Safe Migration Handbook” (the “Handbook”) and “Quantum Readiness Index V1” (the “Index”) to help organisations prepare for quantum-safe migration. The Handbook provides practical guidance on how to build quantum readiness, provides updated recommendations on quantum-safe algorithms, and addresses Singapore's latest requirements for Critical Information Infrastructure (“CII”) owners. Meanwhile, the Index complements the Handbook, assisting organisations in understanding their current level of quantum readiness and prioritises action areas for quantum-safe migration.
Introduction to the Quantum Threat
Quantum computing poses a tangible threat to digital systems today. By making use of quantum mechanics, quantum computers are able to process information and solve complex problems significantly faster than traditional computers. These capabilities threaten to undermine the existing cryptography systems used to secure communications, transactions, and critical systems. With quantum technology, threat actors can decrypt such systems and access sensitive information – for instance, financial data – in a matter of seconds. This is the essence of the Quantum Threat.
Although quantum computing still remains largely theoretical, the potential risks are so significant that preventive steps must be taken now to address them. In June 2026, Microsoft announced that it was bringing its timeline forward and aiming to transition to quantum-safe products by 2029. Solutions being used to mitigate the Quantum Threat, include new cryptographic methods designed to resist attacks from quantum computers, post-quantum cryptography ("PQC") and quantum safe infrastructure such as Quantum Key Distribution (“QKD”).
The Quantum-Safe Migration Handbook
The Handbook breaks down the process of Quantum-Safe Migration into five main domains of effort.
Domain 1 – Risk Assessment: This is the primary starting point for quantum-safe migration. Organisations should first identify and prioritise their most critical systems, before conducting cryptographic asset discovery to map the cryptographic assets deployed within those systems. To support this process, the Handbook recommends the use of threat modelling, including practical examples of how it may be applied.
Domain 2 – Governance: Organisations are also encouraged to establish structures with clearly defined roles, timelines, and milestones to ensure coordinated execution and measurable progress. To support this, the Handbook recommends the use of the RACI model – assigning clear roles as to who is Responsible, Accountable, Consulted, and Informed about the work. In practice, this would ideally lead to quantum readiness becoming integrated into existing processes; for instance, quantum-safe requirements can be embedded into existing governance structures and naturally incorporated into technology upgrades and refreshes.
Domain 3 – Technology: As quantum-safe technologies continue to mature, organisations should familiarise themselves with the available solutions and assess how they can be integrated into existing systems or deployed as replacements for vulnerable cryptographic assets. The Handbook provides a brief overview of several viable options – for instance, PQC, selected algorithms, and QKD – as well as certain interim measures organisations can consider before migration is executed. The Handbook further stresses that quantum-safe migration is an ongoing process. Even after implementing quantum-safe solutions, organisations should maintain cryptographic agility – i.e. ensuring cryptographic systems can be replaced with minimal disruption as standards and technologies evolve – and continue to test and validate their solutions.
Domain 4 - Training and Capability: Building from Domain 2, stakeholders identified within the quantum-safe migration structures must be sufficiently trained to perform their designated role. For instance, senior management and decision makers must understand the business implications, regulatory requirements and contractual obligations pertaining to the Quantum Threat before they are able to approve the resources and timelines required.
Domain 5 - External Engagements: Today, many organisations depend on third-party vendors for cloud infrastructure, enterprise applications, and security tooling. This creates two key risks: the organisation may have limited control over the timing and execution of the migration, and vendors that fail to migrate may introduce vulnerabilities into the organisation's supply chain. The Handbook recommends early engagement with vendors and business partners to understand the readiness of their products for quantum-safe migration and their migration timelines and readiness for quantum-safe migration. Given the scale and complexity of quantum-safe migration, the Handbook encourages organisations to draw on external expertise where appropriate, while retaining ownership of the migration strategy and oversight of its implementation.
The Quantum Readiness Index V1
Complementing the Handbook is the Index, a self-assessment questionnaire designed to help organisations assess their quantum readiness and inform decisions on how it can be further enhanced. Its key objectives are to:
- Establish a baseline understanding of organisational readiness to address the Quantum Threat
- Provide a structure for identifying and considering relevant areas required for quantum-safe migration
- Enable engagement with senior leadership by facilitating a clear and consistent articulation of organisational readiness to inform strategic planning and decision-making
- Complement existing guidance, including the Handbook, by supporting organisations in navigating and contextualising relevant recommendations
The Index is organised around the same five domains, each broken down into its own set of objectives. These objectives are assessed across defined levels.
Conclusion
The release of the Handbook and Index is another step in Singapore's broader push towards quantum readiness. For example, the Monetary Authority of Singapore's 2024 Advisory on Addressing the Cybersecurity Risks Associated with Quantum was among the first supervisory statements globally to address the cybersecurity implications of quantum computing for the financial sector. Many of the themes raised in the Advisory are reflected in the Handbook, including the importance of crypto-agility, cryptographic asset discovery, and early planning for migration to quantum-safe technologies. Against this backdrop, the Handbook and Index provide organisations with a practical framework to assess their current level of readiness, plan for quantum-safe migration, and build resilience against the cybersecurity risks posed by future advances in quantum computing.