Quantum-safe readiness at scale: migrating after NIST’s PQC standards
Executive summary
In August 2024, NIST completed its initial set of standards for post-quantum cryptography. The completed standards include FIPS 203 (ML-KEM) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. According to NIST, the standards are “available for use now; they can no longer wait,” and institutions ought to
This driver is characterized as the “harvest-now-decrypt-later” threat model facilitated by quantum computing technology, implying “harvesting” ciphertext presently and decrypting later on. The joint factsheet by CISA, NSA, and NIST proposes early roadmapping, cryptography inventories, and threat analysis as important measures. In terms of specific techniques,
Vendor engagement because migration is a long process.
Introduction
The following is an analytical practitioner’s report for technical professionals at all levels. Quantum
Computing is developing its own schedule, while we have our own schedule to make sure cryptography is ready for.
Assumptions (Implicit): the scope of the industry is wide; the approach is a global perspective, while still being relevant to U.S. NIST/CISA standards and guidance being implemented into current items of interest regarding information systems and procurement.
“When it comes to multi-million dollar security programs, it isn’t necessarily about which algorithm you pick; it’s about whether you can adjust the crypto without blowing up production. As NIST states, they know that ‘our cryptographic standards and guidelines have been widely adopted and implemented across governments around the world.’
Standards, timeline, and what “migrating after NIST” really means
These baseline standards for 2024 establish the fundamental approach to enterprise post-quantum cryptography: ML-KEM (FIPS 203) for shared secrets, and ML-DSA and SLH-DSA (FIPS 204 and FIPS 205) for signing and verification
The programme describes this process as a long-run process (started in 2015, drafts by 2023, finalisation to follow in 2024) with ongoing work on further/backup algorithms. As NIST Director Laurie E. Locascio says in their 2024 announcement:
“These finalized standards are the capstone of NIST’s efforts to safeguard our confidential electronic information.” Project lead Dustin Moody made the implementation point: “We encourage system administrators to start integrating them into their systems immediately, because full integration will take time.”
It then published a draft of a transition plan (NIST IR 8547, Nov 2024), detailing a path it envisages for the migration from quantum-vulnerable to quantum-resistant standards.
Threat model and why timing matters
The joint quantum-readiness factsheet itself states:
“The potential threat posed by cyber actors who may already be encrypting data with ‘long secrecy lifetime’ using ‘harvest now, decrypt later’ approaches must be addressed in quantum-safe readiness. This means prioritizing by confidentiality requirements: to reach further into the future, even if it is harder, to the confidentiality horizons of 10+ years.”
Timing is not a scare tactic, but a logistics reality. A U.S. government buyer’s guide, pulling together NIST’s transition work, reports that transitioning from standardization to products, procurement, and integration can take as long as 10 to 20 years. Thus, a reason for the need for post-quantum cryptography is that it must be initiated ahead of when quantum computing will break our current public-key systems.
Migration architecture and hybrid cryptography at scale
Let us start with cryptographic visibility. The above factsheet has suggested the need for proactively discovering and inventorying, knowing that public key cryptography is ubiquitous in key establishment and signatures, along with various software/firmware update paths. For your inventory, various aspects to be included are: crypto use-cases, algorithms, key/certificate lifecycle, and various vendors/devices impacting changes. Next, design an architecture that will facilitate a phased migration into four domains:
Transport/TLS. There is an IETF process creating a hybrid TLS 1.3 variant driven by the move to quantum-resistant cryptography, as well as draft designs for hybrid groups using ECDHE and ML-KEM. This is an obvious early candidate for piloting hybrid cryptography since it is important and quantifiable in terms of latency and failures in gateways and meshes.
PKI/identity. FIPS 204, FIPS 205 specify signature destinations, but Enterprise PKI has to grow end-to-end: CA issuance, HSM support, certificate types, and validation libraries for old and new clients, data at rest.
Prioritise long retention archives and backups, and demonstrate “re-keying readiness”, rotate keys, rewrap keys, and then re-encrypt without compromise of restore goals, or “holds” for compliance. This closes the “harvest now” window on stored data.
Embedded/IoT. Constrained devices require trade-off decisions. The U.S. federal report on PQC points out that in certain systems, changes will be impossible if algorithms are hardcoded or capacity-constrained, and the cost of replacement is high.
Where necessary, use hybrid deliberately to buy compatibility and risk reduction, rather than apply everywhere. For a global lens, ENISA underlines “hybrid implementations,” which means combining pre‑ and post‑quantum schemes as well as the mixing of pre-shared keys as the near‑term mitigations while standards and deployments mature.
Finally, make crypto‑agility a design requirement. NIST’s crypto‑agility paper stresses that the PQC transition is larger than earlier migrations and future transitions are inevitable; agility is the capability to swap algorithms in protocols, software, hardware, and firmware with controlled disruption.
Programme governance, budgeting, supply chain, and operating cadence
Consider the process of being quantum safe at scale as a form of transformation. This is because the NSA announcement on the joint factsheet calls for the creation of “a roadmap, inventories, and migration plans, and engaging with our vendors as well.” This was clearly explained by Rob Joyce, who said:
“The key is to be on this journey today and not wait until the last minute.”
While budgeting begins with discovery and pilots, and then scales up by domain, the U.S. federal report for 2024 contains information about annual inventories and annual cost estimate updates; here we find projections to the tune of $7.1bn (2024$) to migrate prioritised federal systems between 2025 and 2035.
Procurement language is your leverage. You should require dated deliverables specific to FIPS 203/204/205, interoperability testing for hybrid crypto (especially for TLS), specification of crypto dependencies (something like an SBOM/CBOM), and a clause for upgrades or exit if products cannot deliver.
These entities can also be considered as ‘capability multipliers’ for the domains of cryptographic visibility, PQ cryptography, and supplier governance.
Performance and testing have to be first class. The IETF TLS work is still in Internet Draft state, so pilot implementations should have “latency/CPU” tests, “client diversity” tests, and “rollback” tests. Close the loop: Developers, SREs, and PKI teams, everyone needs “PQC literacy”; PQC changes tooling, failure modes, certificate/key lifecycles, and so on.
Roadmap and measurable milestones
A compact phased roadmap keeps the programme honest and measurable for quantum-safe readiness at scale:
| Phase | Objective | Timeline | Measurable milestone |
| Discover | Cryptographic visibility and risk tagging | 0–90 days | ≥80% of internet‑facing and tier‑0 systems inventoried; secrecy‑lifetime classification completed |
| Pilot | Transport/TLS hybrid cryptography in a controlled slice | 3–6 months | One production service using TLS hybrid key exchange behind a feature flag; latency & error budgets met |
| Extend | PKI/identity readiness for post-quantum cryptography | 6–12 months | PQC‑capable CA and validation pipeline proven; one high‑value signing flow migrated |
| Protect | Data‑at‑rest re‑keying and re‑encryption readiness | 9–18 months | Backup/archive re‑encryption runbook validated; key‑rotation SLAs achieved |
| Embed | Embedded/IoT upgrades with lifecycle controls | 12–36 months | PQC library integrated; update process validated on representative devices |
| Operate | Continuous monitoring and crypto‑agility | Ongoing | Quarterly inventory deltas; vendor compliance >90%; incident drills include crypto failures |
Conclusion
NIST’s 2024 standards introduce the new baseline for trustworthy computing, even as quantum computing improves. It’s harvest now, decrypt later. It means that the right time has already passed, even though it doesn’t feel like it, as it requires years.
Organisations that achieve quantum-safe readiness at scale do three things consistently. They build cryptographic visibility quickly. They adopt hybrid cryptography, which can help to maintain compatibility and reduce risk. And they also institutionalise crypto-agility, so that this cycle is never repeated as a threat response!

