Everybody keeps asking the same quantum question:
When is Q-Day?
But that may not be the question that matters to the person who eventually has to sign the migration plan.
Before an organization can replace vulnerable cryptography, it has to know where that cryptography exists. And before leadership tells a board that the problem can be fixed, somebody has to determine whether a replacement actually exists.
In this episode of The Briefing, Dr. Tuboise Floyd sits down with David Pollak, Founder and CEO of Spice Labs, for a practical examination of post-quantum readiness, cryptographic discovery, CBOMs, software supply-chain risk, and crypto agility.
Pollak argues that traditional source-code and network scanning can reveal pieces of the problem without necessarily producing a complete, correlated view of the cryptography embedded across applications, libraries, containers, virtual machines, third-party components, certificates, and dependencies.
The conversation gets to a larger leadership question:
What evidence would you be willing to sign your name to?
Pollak describes the role of a Cryptographic Bill of Materials (CBOM) in identifying cryptographic libraries, where cryptography is being invoked, how algorithms are configured, and the cryptographic material contained inside software.
The discussion also examines why crypto agility matters. Pollak compares hard-coded cryptography to putting a jacuzzi motor behind drywall: when something changes, you have to tear into the system to replace it. Crypto agility creates the equivalent of an access door, allowing cryptographic algorithms to be changed with substantially less disruption.
The conversation then moves from discovery to measurement.
For Pollak, readiness cannot simply be a green spreadsheet or completed Jira burndown. Organizations need evidence of what has actually been compiled into software and a way to measure whether cryptographic posture changes as remediation proceeds.
Floyd and Pollak also examine the procurement problem: an organization can address its own code and still inherit cryptographic exposure through someone else's software. That makes vendor evidence, supply-chain auditing, CBOMs, and third-party attestation increasingly important to buyers.
And when the conversation reaches the decision a CISO, CIO, CTO, or board can make now, Pollak offers a deceptively difficult answer:
Decide what can be dropped.
Prioritization requires saying no. If everything is important, nothing is. Leadership therefore needs to know what matters, what does not, and document that decision.
The result is a different way of thinking about post-quantum readiness.
It does not begin with predicting Q-Day.
It begins with knowing what you have, knowing what can be replaced, knowing what cannot, determining what evidence demonstrates that the work was actually completed, and putting a name next to the decision.
IN THIS EPISODE
• Why cryptographic discovery comes before post-quantum migration
• Why source-code scanning alone cannot reveal the entire cryptographic estate
• Why network scanning and application inventories must be correlated
• SBOM vs. CBOM
• What a Cryptographic Bill of Materials actually contains
• Cryptography hidden inside third-party and open-source software
• Software artifacts, JARs, containers, virtual machines, and dependencies
• Cryptographic certificates, keys, algorithms, and material
• Crypto agility and the cost of hard-coded cryptography
• Measuring actual remediation instead of relying on compliance spreadsheets
• Software supply-chain exposure
• Vendor and procurement questions for post-quantum readiness
• External auditing and third-party attestation
• Why software must be treated as a dynamic asset
• Long-term technology investment and short-term organizational incentives
• What CISOs, CIOs, CTOs, and boards should prioritize now
• Why every migration plan eventually requires someone to decide what does not get fixed first
THE BUYER'S TEST
A vendor tells you:
“We're quantum safe.”
What should you ask next?
Have you tested the system without classical certificates, cryptography, or keys?
What evidence demonstrates what exists inside third-party and open-source components?
Mechanics. Process. Third-party attestation.
CHAPTERS
00:00 — Q-Day May Be the Wrong Question
01:00 — Meet David Pollak, Founder & CEO of Spice Labs
02:00 — Do Organizations Know Where Their Cryptography Is?
03:00 — Why an Inventory Is Not Enough
05:00 — Inspecting the Build Artifact
07:00 — What Would You Be Willing to Sign?
08:00 — What's Actually Inside Modern Software?
10:00 — Decision Assurance and Cryptographic Evidence
11:00 — SBOM vs. CBOM
12:00 — What a CBOM Actually Tells You
14:00 — Cryptographic Material and Legacy Certificates
15:00 — Inside Spice Labs' Cryptographic Analysis
17:00 — Third-Party Software and Quantum Readiness
18:00 — Migration Deadlines and the Leadership Problem
19:00 — Why Post-Quantum Migration Takes Time
20:00 — Partner Message: MCGlobalTech CMMC Assured Enclave
21:00 — Harvest Now, Decrypt Later—and Digital Trust
23:00 — What Happens When Digital Signatures Cannot Be Trusted?
27:00 — What Crypto Agility Actually Means
31:00 — Discovery Is the Starting Line
32:00 — Measurement vs. Compliance Checklists
34:00 — Measuring Ground Truth
37:00 — Software Supply-Chain Visibility
38:00 — Should Buyers Require CBOM Evidence?
39:00 — The Buyer's Test for “Quantum Safe” Vendors
41:00 — What Executives Misunderstand About Software
43:00 — Short-Term Incentives vs. Long-Term Readiness
44:00 — The One Decision Leaders Can Make Monday Morning
45:00 — What Do You Drop on the Floor?
GUEST
Founder & CEO, Spice Labs
David Pollak has spent nearly two decades building open-source systems and examining how software is composed. He created Lift, one of the early major Scala web frameworks, helped advance Scala adoption across industry and academia, and later worked as a distinguished engineer on dependency analysis and enterprise software risk.
At Spice Labs, Pollak is applying mathematical methods to software and cryptographic discovery to produce verifiable records of system composition and help organizations understand the software, dependencies, and cryptography their systems actually contain.
ABOUT THE BRIEFING
The Briefing with Dr. Tuboise Floyd is an independent Human Signal production examining consequential decisions across artificial intelligence, quantum technology, cybersecurity, governance, and emerging technology risk.
Real conversations. Higher stakes.
Find the decision. Follow the evidence. Name who owns it.
Hosted by Dr. Tuboise Floyd
Creative Director: Jeremy Jarvis
A Human Signal Production
PARTNER DISCLOSURE
This episode includes a partner message from MCGlobalTech, a Human Signal partner, for the CMMC Assured Enclave.
Commercial partnerships and underwriting do not determine guest selection, questions, analysis, or editorial conclusions.