Artwork for podcast The Briefing with Dr. Tuboise Floyd
Post-Quantum Readiness: Can You Find Your Cryptography Before Quantum Does? | David Pollak
22nd September 2026 • The Briefing with Dr. Tuboise Floyd • Dr. Tuboise Floyd
00:00:00 00:44:36

Share Episode

Shownotes

Everybody keeps asking the same quantum question:

When is Q-Day?

But that may not be the question that matters to the person who eventually has to sign the migration plan.

Before an organization can replace vulnerable cryptography, it has to know where that cryptography exists. And before leadership tells a board that the problem can be fixed, somebody has to determine whether a replacement actually exists.

In this episode of The Briefing, Dr. Tuboise Floyd sits down with David Pollak, Founder and CEO of Spice Labs, for a practical examination of post-quantum readiness, cryptographic discovery, CBOMs, software supply-chain risk, and crypto agility.

Pollak argues that traditional source-code and network scanning can reveal pieces of the problem without necessarily producing a complete, correlated view of the cryptography embedded across applications, libraries, containers, virtual machines, third-party components, certificates, and dependencies.

The conversation gets to a larger leadership question:

What evidence would you be willing to sign your name to?

Pollak describes the role of a Cryptographic Bill of Materials (CBOM) in identifying cryptographic libraries, where cryptography is being invoked, how algorithms are configured, and the cryptographic material contained inside software.

The discussion also examines why crypto agility matters. Pollak compares hard-coded cryptography to putting a jacuzzi motor behind drywall: when something changes, you have to tear into the system to replace it. Crypto agility creates the equivalent of an access door, allowing cryptographic algorithms to be changed with substantially less disruption.

The conversation then moves from discovery to measurement.

For Pollak, readiness cannot simply be a green spreadsheet or completed Jira burndown. Organizations need evidence of what has actually been compiled into software and a way to measure whether cryptographic posture changes as remediation proceeds.

Floyd and Pollak also examine the procurement problem: an organization can address its own code and still inherit cryptographic exposure through someone else's software. That makes vendor evidence, supply-chain auditing, CBOMs, and third-party attestation increasingly important to buyers.

And when the conversation reaches the decision a CISO, CIO, CTO, or board can make now, Pollak offers a deceptively difficult answer:

Decide what can be dropped.

Prioritization requires saying no. If everything is important, nothing is. Leadership therefore needs to know what matters, what does not, and document that decision.

The result is a different way of thinking about post-quantum readiness.

It does not begin with predicting Q-Day.

It begins with knowing what you have, knowing what can be replaced, knowing what cannot, determining what evidence demonstrates that the work was actually completed, and putting a name next to the decision.

IN THIS EPISODE

• Why cryptographic discovery comes before post-quantum migration

• Why source-code scanning alone cannot reveal the entire cryptographic estate

• Why network scanning and application inventories must be correlated

• SBOM vs. CBOM

• What a Cryptographic Bill of Materials actually contains

• Cryptography hidden inside third-party and open-source software

• Software artifacts, JARs, containers, virtual machines, and dependencies

• Cryptographic certificates, keys, algorithms, and material

• Crypto agility and the cost of hard-coded cryptography

• Measuring actual remediation instead of relying on compliance spreadsheets

• Software supply-chain exposure

• Vendor and procurement questions for post-quantum readiness

• External auditing and third-party attestation

• Why software must be treated as a dynamic asset

• Long-term technology investment and short-term organizational incentives

• What CISOs, CIOs, CTOs, and boards should prioritize now

• Why every migration plan eventually requires someone to decide what does not get fixed first

THE BUYER'S TEST

A vendor tells you:

“We're quantum safe.”

What should you ask next?

  1. How are you managing certificates and cryptographic inputs?

Have you tested the system without classical certificates, cryptography, or keys?

  1. How have you audited your software supply chain?

What evidence demonstrates what exists inside third-party and open-source components?

  1. Who independently audited the claim?

Mechanics. Process. Third-party attestation.

CHAPTERS

00:00 — Q-Day May Be the Wrong Question

01:00 — Meet David Pollak, Founder & CEO of Spice Labs

02:00 — Do Organizations Know Where Their Cryptography Is?

03:00 — Why an Inventory Is Not Enough

05:00 — Inspecting the Build Artifact

07:00 — What Would You Be Willing to Sign?

08:00 — What's Actually Inside Modern Software?

10:00 — Decision Assurance and Cryptographic Evidence

11:00 — SBOM vs. CBOM

12:00 — What a CBOM Actually Tells You

14:00 — Cryptographic Material and Legacy Certificates

15:00 — Inside Spice Labs' Cryptographic Analysis

17:00 — Third-Party Software and Quantum Readiness

18:00 — Migration Deadlines and the Leadership Problem

19:00 — Why Post-Quantum Migration Takes Time

20:00 — Partner Message: MCGlobalTech CMMC Assured Enclave

21:00 — Harvest Now, Decrypt Later—and Digital Trust

23:00 — What Happens When Digital Signatures Cannot Be Trusted?

27:00 — What Crypto Agility Actually Means

31:00 — Discovery Is the Starting Line

32:00 — Measurement vs. Compliance Checklists

34:00 — Measuring Ground Truth

37:00 — Software Supply-Chain Visibility

38:00 — Should Buyers Require CBOM Evidence?

39:00 — The Buyer's Test for “Quantum Safe” Vendors

41:00 — What Executives Misunderstand About Software

43:00 — Short-Term Incentives vs. Long-Term Readiness

44:00 — The One Decision Leaders Can Make Monday Morning

45:00 — What Do You Drop on the Floor?

GUEST

David Pollak

Founder & CEO, Spice Labs

David Pollak has spent nearly two decades building open-source systems and examining how software is composed. He created Lift, one of the early major Scala web frameworks, helped advance Scala adoption across industry and academia, and later worked as a distinguished engineer on dependency analysis and enterprise software risk.

At Spice Labs, Pollak is applying mathematical methods to software and cryptographic discovery to produce verifiable records of system composition and help organizations understand the software, dependencies, and cryptography their systems actually contain.

ABOUT THE BRIEFING

The Briefing with Dr. Tuboise Floyd is an independent Human Signal production examining consequential decisions across artificial intelligence, quantum technology, cybersecurity, governance, and emerging technology risk.

Real conversations. Higher stakes.

Find the decision. Follow the evidence. Name who owns it.

Hosted by Dr. Tuboise Floyd

Creative Director: Jeremy Jarvis

A Human Signal Production

PARTNER DISCLOSURE

This episode includes a partner message from MCGlobalTech, a Human Signal partner, for the CMMC Assured Enclave.

Commercial partnerships and underwriting do not determine guest selection, questions, analysis, or editorial conclusions.



This podcast uses the following third-party services for analysis:

OP3 - https://op3.dev/privacy

Chapters

Video

More from YouTube