The Isidore Quantum Implementation Work Plan for ASEAN PQC Readiness provides a structured, twelve-month roadmap that guides governments and enterprises through seven phases of PQC adoption. The Playbook outlines each phase—from governance planning and cryptographic inventory to full-scale deployment and continuous readiness auditing—defining objectives, timelines, metrics, and alignment with Singapore’s QRI and CSA 2025 framework. By following this work plan, ASEAN member states and organizations can achieve measurable, standards-based quantum resilience through coordinated governance, proven technology integration, and sustained capability development.

Objective / Goal

Establish a national or enterprise-level PQC governance framework that integrates with cybersecurity and digital trust policies


Timeline

0–3 months


Quantified Outcomes / Metrics

• PQC Steering Committee formed
• National/enterprise PQC policy draft completed


Exit Criteria / Completion Definition

Governance framework formally approved by leadership and aligned with digital resilience strategies.


Impact / Alignment with QRI & CSA 2025
QRI: Governance Domain –

Establishes top-level leadership oversight and accountability

CSA 2025: Governance –

Defines PQC governance and roles

Objective / Goal

Use Cassian™ to inventory all cryptographic systems, dependencies, and data flows that rely on RSA/ECC or other legacy algorithms. Establish Objectives for Proof Of Concept (PoC) Pilots. Execute One Page PoC Documentation (PoCDoc).


Timeline

1–4 months (overlaps with Phase 1)


Quantified Outcomes / Metrics

• 100% of critical systems inventoried
• Cryptographic dependencies mapped


Exit Criteria / Completion Definition

• Inventory report completed and validated
• Critical assets prioritized by sensitivity and exposure
• Objectives for Proof Of Concept (PoC) Pilots established
• One Page PoC Documentation (PoCDoc) executed


Impact / Alignment with QRI & CSA 2025
QRI: Risk Assessment Domain –

Enables quantum-risk profiling

CSA 2025: Asset Management –

Supports algorithm replacement planning

Objective / Goal

Deploy Isidore Quantum devices with QRNG in a controlled environment to validate key management, and performance. Generate simulations for workforce training.


Timeline

1 week


Quantified Outcomes / Metrics

• Pilot with ≥10 nodes (servers, IoT, OT, gateways)
• <1ms latency confirmed
• 100% uptime during testing


Exit Criteria / Completion Definition

Successful pilot demonstrating PQC integration without disruption to existing operations.


Impact / Alignment with QRI & CSA 2025
QRI: Technology Domain –

Tests readiness for PQC deployment

CSA 2025: Risk/Technology –

Reduces cryptographic exposure

Objective / Goal

Implement Cassian or comparable programs AI-driven orchestration for automated fleet management (generation, rekeying, zeroization)


Timeline

1 week


Quantified Outcomes / Metrics

• Fleet-wide rekeying automated
• Zeroization and compliance logging enabled


Exit Criteria / Completion Definition

Autonomous key management active across all nodes with AI anomaly detection confirmed.


Impact / Alignment with QRI & CSA 2025
QRI: Governance/ Technology –

Enables continuous compliance

CSA 2025: Governance & Risk –

Enforces cryptographic agility

Objective / Goal

Upskill cybersecurity teams on PQC operations, AI-driven management, and compliance tracking. Use PoC simulations to train workforce.


Timeline

5–8 months


Quantified Outcomes / Metrics

• 100% of key personnel trained
• PQC certification achieved for operators


Exit Criteria / Completion Definition

• Training completion and certification documented
• Staff demonstrate operational proficiency


Impact / Alignment with QRI & CSA 2025
QRI: Training & Capability Domain –

Builds sustainable PQC expertise

CSA 2025: Training –

Ensures skill continuity

Objective / Goal

Transition Isidore Quantum to operational environments across national or enterprise infrastructure


Timeline

9–12 months


Quantified Outcomes / Metrics

100% of prioritized systems migrated- PQC integration success rate ≥95%


Exit Criteria / Completion Definition

• Deployment completed across all critical systems
• Quantum-safe state validated


Impact / Alignment with QRI & CSA 2025
QRI: Technology/Risk Domain –

Achieves “Adaptive” readiness tier

CSA 2025: Technology & Risk –

Operationalizes quantum-safe migration

Objective / Goal

Maintain PQC readiness through AI-driven monitoring, cryptographic inventory updates, and quarterly readiness scoring


Timeline

12+ months (ongoing)


Quantified Outcomes / Metrics

• Zero PQC configuration drift
• Quarterly QRI reassessments
• <0.5% cryptographic failures


Exit Criteria / Completion Definition

• Continuous compliance reports generated
• Readiness tier maintained or improved


Impact / Alignment with QRI & CSA 2025
QRI: Governance/ Technology Domain –

Enables long-term assurance

CSA 2025: External Engagement –

Supports cross-border trust and reporting