PQC migration guide
Post-quantum cryptography migration: an operating roadmap
Post-quantum migration is a multi-year systems-change program. The durable path begins with visibility and ends with verified, repeatable cryptographic agility—not a one-time algorithm swap.
Decision brief
- Primary query
- post quantum cryptography migration
- Best for
- Teams that need reviewable cryptographic evidence, ownership, and continuous migration control.
- Safety boundary
- Evidence supports decisions; it is not proof of implementation safety or compliance.
NIST finalized FIPS 203, 204, and 205 in 2024 and advises organizations to begin migration. That direction does not remove implementation decisions. Teams must discover where quantum-vulnerable public-key cryptography is used, understand protocol and product support, prioritize long-lived sensitive data, engage vendors, test standardized implementations, and coordinate change across producers and consumers.
Use migration waves rather than a single deadline. Group systems by shared libraries, protocols, certificate infrastructure, business service, vendor, or deployment environment. Define entry criteria, interoperability cases, performance limits, fallback behavior, key and artifact handling, rollout metrics, and exit evidence for each wave. Maintain classical and hybrid approaches only where architecture and policy justify them.
Capabilities
What the operating model needs to do
Inventory first
Locate quantum-vulnerable algorithms and connect them to systems, data, owners, and dependencies.
Prioritize by consequence
Consider data lifetime, exposure, criticality, replacement lead time, and vendor control.
Test interoperability
Validate actual products, protocols, versions, parameters, performance, and failure behavior.
Prevent regression
Update architecture, approved libraries, policy, procurement, and CI after migration.
Workflow
A repeatable path to evidence
Use explicit scope, accountable decisions, and verification gates. Keep unknowns visible so progress is not manufactured by narrowing the denominator.
- 1
Mobilize
Set governance, scope, standards watch, evidence model, owners, and reporting boundaries.
- 2
Discover and triage
Build the inventory, expose unknowns, and rank systems into migration cohorts.
- 3
Pilot
Test representative low-risk systems and shared platforms before broad rollout.
- 4
Scale and verify
Migrate in waves, confirm production state, close old paths, and monitor drift.
Expected deliverables
Artifacts the next team can inspect
- PQC program charter
- Cryptographic inventory and coverage
- Prioritized migration cohorts
- Interoperability and performance evidence
- Production verification and regression controls
Buyer checklist
Questions for a proof of value
- 01Does the roadmap connect standards to actual system dependencies?
- 02Are vendor products and procurement included?
- 03Can tests be reproduced for each protocol and implementation?
- 04Does closure require production verification?
- 05How will the organization remain agile after the first migration?
Limits and cautions
What this page does not promise
- Do not forecast a precise quantum break date as fact.
- Standardized algorithms still require correct, supported implementations.
- Migration can introduce availability and interoperability risk if rushed.
Continue evaluating
Related decision pages
CNSA 2.0 guide
CNSA 2.0 planning: inventory, policy, migration evidence, and limits
Use current NSA sources to plan CNSA 2.0-related inventory and migration work while keeping applicability, implementation validation, and compliance decisions with the proper authority.
Read pageNIST PQC standards guide
NIST post-quantum cryptography standards: what migration teams need to track
A current, source-led guide to FIPS 203, FIPS 204, FIPS 205, ongoing NIST work, inventory, implementation testing, and migration governance.
Read pageQuantum security buyer guide
Quantum security companies: how to evaluate the post-quantum market
A current buyer framework for cryptographic inventory, posture management, PQC migration, runtime remediation, PKI and CLM, implementations, and quantum-safe networking vendors.
Read pageCryptographic inventory software
A cryptographic inventory your engineering teams can keep current
Discover cryptographic assets in source, dependencies, configuration, containers, and authorized TLS endpoints. Preserve evidence, ownership, and change history in one inventory.
Read pageStart with evidence from one representative repository
Run a scoped scan, inspect every result, export the CBOM, and decide whether the evidence is strong enough to support your operating model.