ASD's LATICE Guidance of 20 July 2026 and the NCSC's Workshop Report of 22 July 2026 Both Start With the Cryptographic Inventory, and the EU's End-2030 Date Leaves Little Time to Build One
Quentir Defense Monitor
Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · September 4, 2026.

On 4 September 2026 the Taiwanese trade outlet iThome carried two reports on documents that had been public for six weeks: the Australian Signals Directorate's first installment of its post-quantum planning series, dated 20 July 2026, and the UK NCSC's report on its first industry migration workshop, dated 22 July 2026. The same morning the Italian outlet Agenda Digitale published a long piece on quantum security for companies that rests on the EU NIS Cooperation Group's coordinated roadmap of June 2025, a policy timetable addressed to member states. Three jurisdictions, several independently produced sources, one shared first step: find every place traditional public-key cryptography is used before deciding what to replace.
That convergence is the finding, and it should be attributed precisely. ASD's document places location and inventory first by name. The NCSC's timelines guidance makes discovery and assessment the phase due by 2028, and its workshop report asks for initial discovery before the board is engaged. The Commission's materials set dates and leave the method to member states, and Agenda Digitale, reading the EU timetable for Italian companies, names limited visibility of cryptographic assets as the principal obstacle. Each of them arrives at the same artifact, a cryptographic inventory that ASD says will never be complete and should be started anyway.
What ASD Published on 20 July 2026: LATICE and the Places Cryptography Hides
The Australian Signals Directorate posted "Planning for post-quantum cryptography, Part 1: Know what you have" on 20 July 2026 as the first of a series that extends its planning guidance on cyber.gov.au. It frames the transition as five phases under the acronym LATICE: locate and inventory the use of traditional asymmetric cryptography, assess the value and sensitivity of what it protects, triage systems into a priority order, implement post-quantum algorithms, and communicate with vendors and educate stakeholders. The iThome account of 4 September 2026 adds the questions the first phase is meant to answer: where cryptography is used, which asymmetric algorithms with what key lengths and parameters, what data and systems they protect, and who owns each dependency, which vendor supplies it and what lifecycle limit it carries.
The document is specific about why the first phase is hard. Cryptography may be tightly coupled to, or hard-coded into, bespoke applications; embedded in operational technology or hardware; packaged within vendor platforms and cloud services; or buried inside protocols, libraries or compiled binaries. ASD judges it unlikely that any single tool will give an organization complete visibility, and lists the sources that together approximate one: software bills of materials, asset discovery and vulnerability management tools, configuration data, public key infrastructure and key management records, and engagement with vendors and system owners. The proposed container for all of it is a cryptographic bill of materials, which ASD describes as a practical way to document cryptographic dependencies at both environment and system levels. Its closing advice is the sentence the whole series turns on: a planned, partial cryptographic inventory maintained over time is more valuable than a perfect one attempted too late.
What the NCSC Reported on 22 July 2026, and the Dates It Restated
The UK's NCSC hosted its first government and industry workshop on post-quantum migration in December 2025 with Vodafone and the National Cyber Advisory Board, and on 22 July 2026 published a report on it written by its deputy chief technology officer for cyber policy and a Vodafone cyber strategy manager. Three themes came out of the room. The first is the board: migration has to be framed as a business risk with a cost of delay, prioritized toward systems where a breach would hurt most and systems that take longest to migrate, such as those that depend on long-lived hardware, and laid out as a phased roadmap with budgets and skills attached. The second is supplier readiness: an organization's quantum readiness depends on its suppliers, so their roadmaps should be learned and influenced early, and an economical migration will ride natural technology refresh cycles, which only works if products with post-quantum capability are available when the refresh is planned. The third is transparency, with the NCSC asking migrating organizations to publish their plans and lessons.
The dates behind the report come from the NCSC's migration timelines guidance: complete discovery and assessment and an initial plan by 2028, complete the highest-priority migrations by 2031, and complete the migration by 2035. The same guidance expects large organizations, and any that run their own infrastructure, to need two to three years for discovery, assessment, strategy and an initial plan, and another two to three years for early migration activities. iThome's second report of 4 September draws the operational consequence: some industrial internet-of-things devices cannot be upgraded or run proprietary protocols with no post-quantum support, operational technology turns over slowly, and an organization that does not know its equipment lifetimes and vendor plans can find devices still in service that cannot follow the migration.
Quantum pillar: post-quantum cryptography (migration and crypto-agility). Use posture: defensive. Technology readiness: not applicable. Three guidance documents and a roadmap are policy and planning instruments and sit on no rung of the readiness ladder; what the documents rate is an organization's own progress through inventory, assessment and replacement, which a program office measures against the 2028, 2030, 2031 and 2035 dates and never against a technology maturity scale.
What the EU Roadmap of 23 June 2025 Sets Out, and the Survey Results Published on 2 September 2026
The European side is older and is directed to member states, which then carry it to companies through their own instruments. On 23 June 2025 the NIS Cooperation Group, supported by the European Commission, issued a coordinated implementation roadmap following the Commission's recommendation of 11 April 2024. The Commission's press release sets two dates: all member states should start transitioning to post-quantum cryptography by the end of 2026, and the protection of critical infrastructures should be transitioned as soon as possible and no later than the end of 2030. The Commission's library page for the roadmap now lists a further item dated 2 September 2026, the published feedback from a stakeholder survey the group ran from 11 August to 29 September 2025, which is the roadmap's first public revision signal.
Agenda Digitale's piece of 4 September 2026 reads that timetable from the Italian side, alongside the national quantum strategy and the work of the national cybersecurity agency ACN. Its diagnosis matches Canberra's and London's: the principal obstacle is limited visibility of cryptographic assets, since many organizations still lack a complete map of the technologies they use, and the change that matters is crypto-agility, the ability to swap algorithms, manage keys and certificates centrally and keep sight of every cryptographic resource, rather than a one-time replacement. It cites a Deloitte survey in which only 37 percent of chief information security officers report a deep, trusted relationship with their chief technology officer, and 22 percent with their chief architect, which is the organizational version of the inventory gap.
What the Three Documents Let a Force Do, and What They Do Not Settle
The defense reading is about time. A military or critical-infrastructure operator that begins the inventory in 2026 is, on the NCSC's own estimate, spending two to three years on discovery, assessment and an initial plan, with early migration work allowed to overlap. The EU's end-2030 date for critical infrastructure and the NCSC's 2031 date for priority systems compress whatever remains, and the compression falls hardest on the dependencies ASD names: firmware in operational technology, vendor platforms that cannot be opened, and compiled binaries nobody on staff wrote. The frameworks are defensive in the plain sense that they protect an operator's own communications, authentication and stored data against a future cryptanalytic capability; they confer no capability against anyone else.
What they let a program office do is refuse a class of proposal. A vendor offering a post-quantum product for a system whose cryptographic dependencies have never been located is offering a replacement for an unknown; ASD and the NCSC put the inventory first in so many words, and a buyer can now cite both for that ordering. The scale of the unknown is measurable. This Monitor's reading of Forescout's count of post-quantum key exchange on 19 million of 160 million SSH servers, with operational technology at 16 percent and medical devices at 6 percent, is a snapshot of one protocol that an inventory would have to cover, and the firmware and silicon layer this Monitor has examined before is where ASD's hard-coded dependencies live.
What the documents do not settle is the artifact's own reliability. ASD supplies the fields an inventory should hold and the sources to fill them from, but none of the documents establishes a common mandatory schema for a cryptographic bill of materials, an evidentiary standard for each entry, or a rule for keeping an entry true after a firmware update, and ASD's counsel to start partial and maintain over time is candid that the inventory will be wrong in places for years. Nor do they resolve the supplier problem the NCSC workshop identified: an inventory can name a vendor dependency, and the vendor can still ship no upgrade. The dates give the operator a schedule; the documents give it a method; whether the equipment on the network can follow either is a question the inventory is designed to surface and cannot answer. Quentir's daily blog read the same tension from the American side when five post-quantum dates arrived before the federal plans were due.
The dated items to watch are the EU's end-2026 start line for every member state, which is less than four months away; the NCSC's 2028 discovery deadline; and the further parts of ASD's series, of which the second, on assessment, was already public by 4 September. Each will show whether the inventory the three documents agree on is being built.
Sources
Primary source: the Australian Signals Directorate, "Planning for post-quantum cryptography, Part 1: Know what you have," published 20 July 2026, for the LATICE phases, the four places cryptography hides, the judgment that no single tool gives complete visibility, the list of discovery sources, the description of a cryptographic bill of materials, and the statement that a planned, partial inventory maintained over time is more valuable than a perfect one attempted too late; the companion planning page on cyber.gov.au was not reachable during this reading. The UK NCSC, "Post-quantum cryptography (PQC) migration workshop report," 22 July 2026, for the December 2025 workshop and its three themes, and the NCSC's migration timelines guidance for the 2028, 2031 and 2035 dates and the two-to-three-year estimates. The European Commission's press release of 23 June 2025 and the library page for the NIS Cooperation Group's coordinated implementation roadmap, for the end-2026 and end-2030 dates, the 11 April 2024 recommendation, and the survey feedback item dated 2 September 2026. iThome, two reports of 4 September 2026, for the inventory questions, the data sources and the industrial equipment consequence. Agenda Digitale, 4 September 2026, for the Italian reading, the visibility diagnosis, the crypto-agility framing and the Deloitte figures. The Forescout figures come from this Monitor's own earlier post on that report, linked inline, which carries Forescout's primary source in its own list. The judgments are this Monitor's own: the reading that the three documents converge on one artifact, the arithmetic placing an inventory begun in 2026 against the 2030 and 2031 dates, the observation that none of the documents establishes a common schema or evidence standard for an inventory entry, and the classification of the sub-branch and posture.