A post-quantum programme can easily become a list of new algorithm names. That list is not a migration plan. The first task is to find every place the organisation depends on public-key cryptography: transport security, virtual private networks, code signing, document signatures, certificate authorities, device onboarding, identity tokens, database encryption wrappers, backup keys and partner exchanges. Add algorithms, parameters, libraries, protocols, key owners, certificate lifetimes and replacement procedures.
Inventory must include cryptography hidden inside appliances, mobile applications, firmware, managed services and partner endpoints. Source scanning helps, but configuration and runtime observation are needed too. A service may call a library without naming the algorithm in application code. A load balancer may terminate TLS before traffic reaches the service. Record the data protected and how long that data needs confidentiality or signature validity. Long-lived sensitive records deserve attention before short-lived sessions.