Cryptographic Inventory Is the Real Bottleneck in Post-Quantum Migration
Organisations report discovery as the hard part, with embedded systems, hardware encryption, legacy infrastructure and third-party dependencies hiding what needs replacing.

Post-quantum migration is reported to depend on building an accurate inventory of cryptographic systems, and organisations describe discovery rather than replacement as the major obstacle. Embedded systems, hardware encryption, legacy infrastructure and third-party dependencies all hide cryptography from the teams responsible for changing it.
Embedded systems are the worst case in that list for a specific reason. Cryptography in a server application is in source code somebody can grep. Cryptography in a device may be in a vendor SDK shipped as a binary, in a secure element with a fixed algorithm set, or in mask ROM. The first can be replaced, the second may require a different part, and the third cannot be changed at all — and from the outside all three look identical, which is why an inventory built from documentation rather than from the devices tends to be wrong in the direction that matters.
The recommended prioritisation is systems holding long-lived sensitive data, which is the sensible order given harvest-now-decrypt-later. The other action worth taking early costs nothing technically: ask vendors, in writing, for their standards support and hybrid transition plans. A supplier without an answer today is a supplier whose parts will constrain your options later, and that is far cheaper to discover during selection than during migration.
Source: The Quantum Insider