Preparing for post-quantum cryptography: a migration plan
The standards are final and the timelines are published. This is a five-stage plan to inventory, prioritise and migrate quantum-vulnerable cryptography, and what to do this quarter.
- NIST finalised ML-KEM, ML-DSA and SLH-DSA (FIPS 203, 204 and 205) in August 2024 and urged organisations to start using them.
- Most government timelines expect high-priority systems to be migrated around 2030 to 2031 and full migration around 2035.
- Start with a cryptographic inventory; every framework does.
- Prioritise long-lived data, internet-facing key exchange and hard-to-change roots of trust.
- Design for crypto-agility so the next algorithm change is configuration, not a rebuild.
The problem, stated carefully
Today's public-key cryptography (RSA, elliptic-curve schemes and Diffie-Hellman) relies on problems that a sufficiently large quantum computer could solve with Shor's algorithm; CERT-In's guidelines list RSA, ECC, Diffie-Hellman and DSA as vulnerable [1]. No such machine is publicly known to exist, and this plan does not depend on predicting when one might. Two facts make it a present concern: data captured today can be decrypted later [2], and cryptographic migrations take years because cryptography is embedded in libraries, protocols, hardware and partner integrations. Symmetric algorithms are affected far less; NIST does not expect to need to replace AES [3].
The standards and timelines
NIST published FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) on 13 August 2024 [4], and selected HQC in March 2025 as a backup key-encapsulation mechanism [5]. Timelines have converged:
| Framework | Milestones |
|---|---|
| NIST IR 8547 (draft) | Quantum-vulnerable 112-bit algorithms deprecated after 2030; all quantum-vulnerable algorithms disallowed after 2035 [3] |
| NSA CNSA 2.0 | New NSS acquisitions compliant from 1 January 2027; all NSS quantum-resistant by 2035 [6] |
| UK NCSC | Discovery and plan by 2028; high-priority migration by 2031; complete by 2035 [7] |
| EU roadmap | Start by end of 2026; high-risk use cases by end of 2030 [8] |
| India DST task force | CII by 2029; enterprise-wide adoption by 2033 [9] |
More detail: post-quantum compliance timelines.
A five-stage migration plan
1. Discover: build the cryptographic inventory
Find where public-key cryptography is used: TLS, VPNs, SSH, code and document signing, PKI, HSM and KMS keys, databases, message queues, application libraries, firmware and third-party APIs. The CISA, NSA and NIST factsheet recommends discovery tools across network protocols, end-user systems and development pipelines [2]. Record results in a machine-readable CBOM; CycloneDX links cryptographic assets to the software that uses them [10]. See What is a CBOM? and How to build a QBOM.
2. Assess: score quantum exposure
For each asset record the algorithm and key size, what it protects, how long that must stay confidential, exposure and who controls the implementation. See Quantum risk assessment.
3. Prioritise
Rank by the gap between data lifetime and migration time. Long-lived confidential data, internet-facing key exchange and roots of trust come first. Firmware signing keys deserve special attention, which is why CNSA 2.0 puts software and firmware signing on its earliest timeline, 2030 [11].
4. Migrate, with crypto-agility
Adopt hybrid key establishment where your policy calls for it; OpenSSL 3.5 already offers X25519MLKEM768 by default in TLS [12]. Treat hybrids as interim, as the NCSC recommends [13]. Move signing and certificate hierarchies to ML-DSA or hash-based signatures as ecosystem support matures, and remove hard-coded algorithms (see crypto-agility).
5. Govern continuously
Track progress by business service, put PQC requirements into procurement, collect vendor roadmaps and re-scan. In India, CERT-In recommends tiered vendor PQC contract requirements with quarterly progress reports [1]. See QBOM management and PQC procurement requirements.
Obstacles to plan for
- Performance and size. Post-quantum keys and signatures are larger than classical ones. In BIS Project Leap phase 2, tests in a live payment system showed significant performance differences between traditional and post-quantum algorithms [14]. Test latency-sensitive paths early.
- Supplier opacity. The G7 Cyber Expert Group names obtaining detailed vendor roadmaps for cloud and cryptographic services as a barrier [15]. Build supplier requirements into contracts now rather than at renewal.
- Research code in production. Some widely used post-quantum libraries are explicitly for prototyping; Open Quantum Safe's liboqs maintainers do not recommend it for production use [16]. Check the status of every library you deploy (see QBOM tools).
- Inventory decay. New services keep introducing classical cryptography unless engineering standards and pipeline checks stop them.
Who does what
| Role | Responsibility |
|---|---|
| CISO or programme owner | Plan, priorities, board reporting, exceptions |
| Service owners | Data lifetime and business impact for each service |
| Security engineering and PKI teams | Discovery, CBOM accuracy, certificate and key migration |
| Platform and development teams | Library upgrades, hybrid key exchange, removing hard-coded algorithms |
| Procurement and vendor management | Supplier CBOMs, roadmaps and contract terms |
What to do this quarter
- Appoint an owner for the cryptographic inventory and migration plan.
- Produce a first CBOM for your ten most critical services.
- Identify data sets with confidentiality requirements beyond 2035.
- Ask your top suppliers for their PQC roadmap in writing.
- Add "no new hard-coded RSA or ECC" to engineering standards.
How IntelliXBOM helps
IntelliXBOM generates and ingests CBOMs and QBOMs in CycloneDX and SPDX, validates them against required-field policies, and correlates cryptographic assets with software, hardware, vulnerabilities and business services. Version history and diffs show migration progress between releases, and inventory maps to framework controls with timestamped evidence. It helps you plan and evidence the migration; it does not by itself make systems quantum-safe.
Frequently asked questions
Where should a post-quantum migration start?
With a cryptographic inventory. Every major framework, from the CISA, NSA and NIST factsheet to the UK NCSC and India's DST task force, puts discovery and inventory first, because you cannot migrate cryptography you have not found.
Should we wait for more standards before migrating?
NIST advised organisations to start using FIPS 203, 204 and 205 immediately rather than wait. Later standards such as HQC and FN-DSA add options; crypto-agility makes adopting them later less disruptive.
Is hybrid cryptography required?
It depends on the framework. The UK NCSC treats PQ/T hybrid schemes as an interim measure, while NSA does not require hybrids for national security systems. Many organisations use hybrid key exchange during the transition for compatibility.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
- NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards (13 August 2024)NISTwww.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
- NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption (March 2025)NISTwww.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption
- The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
- Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
- Post-Quantum Cryptography policy pageEuropean Commission, Shaping Europe's digital futuredigital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
- Cryptography Bill of Materials (CBOM)OWASP CycloneDXcyclonedx.org/capabilities/cbom/
- CNSA 2.0: Complete Guide to NSA's PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
- OpenSSL 3.5 release notesOpenSSL Libraryopenssl-library.org/news/openssl-3.5-notes/
- Next steps in preparing for post-quantum cryptographyUK National Cyber Security Centrewww.ncsc.gov.uk/paper/next-steps-in-preparing-for-post-quantum-cryptography
- Project Leap phase 2: quantum-proofing payment systems (December 2025)Bank for International Settlementswww.bis.org/publications/project-leap-phase-2-quantum-proofing-payment-systems
- Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)G7 Cyber Expert Group, via U.S. Treasuryhome.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf
- liboqsOpen Quantum Safe on GitHubgithub.com/open-quantum-safe/liboqs
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.