Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Leadership and Governance

Overseeing a Migration You Don’t Technically Understand

Marin Ivezic9 min read

NIST standardized the first post-quantum algorithms in August 2024, ML-KEM for key establishment in FIPS 203 and ML-DSA for signatures in FIPS 204. Its transition guidance for retiring RSA and elliptic-curve cryptography is still a draft, NIST IR 8547, so no universal retirement date is in force. The dates that bind a particular organization come from regulators and customers instead. The EU’s coordinated implementation roadmap targets completion of high-risk use cases by the end of 2030, and NSA’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requires exclusive use of post-quantum algorithms in national security systems by 2035. A board approving a five-year technology plan in 2026 is approving systems that will still be in production when those dates arrive.

The worry that surfaces in risk committees runs like this: can a director who cannot evaluate a lattice-based key exchange provide meaningful oversight of a program built on one? The answer is yes, and the reason has nothing to do with cryptography. The useful question is whether the board has the governance architecture to oversee a technical program it cannot personally assess. That architecture already exists in every organization that governs credit, market, or operational risk, and it has simply never been pointed at cryptography.

Governing What You Cannot Personally Assess

Most directors can’t build a credit model, stress-test an actuarial assumption, or audit a derivatives book. They govern those risks competently through three instruments. A risk appetite statement says what the organization is prepared to accept. Tolerance thresholds mark the boundary between acceptable and not. Key risk indicators, or KRIs, are the handful of measurements chosen so that a movement in the number signals that something real has changed in the risk.

Cryptographic migration fits those three instruments without modification. It differs in one respect, and the difference creates work rather than difficulty: most enterprise risk taxonomies have no line for cryptography, so the appetite statements, the thresholds, and the indicators all have to be written before anything can be monitored. That’s a one-time build. It belongs to the enterprise risk function and the accountable executive, not to the board.

Why Deferral Isn’t Available

Item 106 of Regulation S-K, in force since December 2023, requires US public companies to describe in the annual report how the board oversees risks from cybersecurity threats, and to identify the committee holding that responsibility. Delaware’s Caremark line of cases sets the liability standard sitting behind the disclosure. Directors can be personally exposed where they fail to establish a reporting system for a known material risk, or where they ignore the system they already have. Once migration deadlines are public and dated, a board with no reporting line for them has a documentation problem as well as a technology problem.

In the EU, the Digital Operational Resilience Act (DORA) has applied to financial entities since January 2025 and requires them to maintain policies on cryptographic controls and to keep those controls current with developments in cryptanalysis. The NIS Cooperation Group’s coordinated roadmap for post-quantum transition, published in June 2025, asks member states to begin transition by the end of 2026 and to complete migration of high-risk use cases by the end of 2030.

For organizations selling into or operating national security systems, the CNSA 2.0 suite sets staged adoption dates by product category, with exclusive use of the post-quantum algorithms by 2035. The pattern across all three jurisdictions is the same. The deadline that binds an organization first is almost always a regulator’s or a major customer’s, not any estimate of when a cryptographically relevant quantum computer (CRQC) arrives. The EU roadmap’s 2030 target and CNSA 2.0’s 2035 requirement are written down and dated. No regulator has issued a date for the arrival of a CRQC.

The Statements the Board Approves

A risk appetite statement is one or two sentences the board signs, written in outcomes rather than technology. It should not name an algorithm, a key size, or a protocol version. Three examples, to be recalibrated by sector, regulator, and data profile:

  • Systems processing or storing data with a confidentiality requirement beyond ten years will run on NIST-approved post-quantum algorithms by December 31, 2030, and the organization will retain the capacity to accelerate the remaining estate within 12 months of a material change in the threat assessment.
  • The organization will remain compliant with every post-quantum migration deadline issued by its regulators, with compliance status reported to the risk committee quarterly.
  • Every Tier 1 and Tier 2 supplier will provide a documented post-quantum migration roadmap by June 30, 2027, and contracts with critical suppliers that cannot will not be renewed after that date.

The accountable executive drafts these alongside enterprise risk and the cryptographic engineering team, since only the engineers can say what is achievable on what timeline. The board approves them and then holds the program to them.

Four to Six Numbers, Reported Quarterly

Each board-level indicator maps to one appetite statement and carries a green, amber, and red threshold. Four to six is the working range. Beyond that, directors receive operational detail they can neither evaluate nor act on.

Cryptographic estate visibility. The share of the IT and operational technology (OT) estate scanned for cryptographic usage and recorded in the cryptographic bill of materials, or CBOM, which is simply the inventory of where every key, certificate, and algorithm sits. A program 12 months old that has inventoried 30% of the estate is behind, whatever else it has delivered.

Supplier readiness. The share of Tier 1 and Tier 2 vendors who have produced a documented migration roadmap or demonstrated post-quantum capability. This one measures the part of the timeline the organization does not control.

Tier 1 migration progress. The share of the most sensitive systems running in hybrid mode, meaning classical and post-quantum key establishment operating together, or fully post-quantum. This is the indicator that reports whether migration is happening rather than being planned.

Regulatory posture. A composite of alignment against every applicable deadline. Amber means one deadline is at risk absent intervention. Red means one has been missed or will be.

Budget variance. Actual against planned spend. Sustained underspend usually means the program isn’t executing. Sustained overspend usually means discovery found more cryptography than the estimate assumed, which is the ordinary outcome rather than the exception.

Threat assessment. A structured judgment from the accountable executive, refreshed semi-annually, on whether external developments have changed the urgency. Not a prediction, and not a headline summary.

Below the board, the same numbers decompose. The steering committee sees Tier 1 progress broken out by business unit, by migration phase, and by named blocker: the hardware security module vendor running six months late, the ERP module that can’t be upgraded outside a major release, the business unit that hasn’t allocated test windows. The program office tracks hundreds of measures beneath that, from certificate rotation rates to regression pass rates, and surfaces an exception upward only when an operational metric threatens a board-level indicator.

What to Ask When a Number Moves

At program launch, four questions establish the mandate. Which deadlines bind us, and what happens if we miss them? How large do we believe the cryptographic estate is, and how confident are we in that estimate? Who is the single accountable executive, and do they hold the budget and the cross-functional authority to deliver? How will we measure progress, at what cadence, against what thresholds?

When an indicator shifts to amber, ask what caused it, whether the cause is a temporary delay or a structural constraint, what the recovery plan requires, and whether any regulatory deadline is now at risk. When one turns red, ask for the business impact of it staying red, the options with their costs, and whether disclosure or regulatory notification is triggered.

At stage gates, ask the question that discovery usually answers uncomfortably: what did we learn that changes our estimate of the work remaining, and do the appetite statements still fit what we now know?

Two Ways Oversight Fails

The first is expertise-chasing. A director who spends twenty minutes of a risk committee meeting on quantum gate fidelity has spent twenty minutes not asking whether the program will meet its deadlines. Two distinctions take a minute each and are enough. Physical qubits are not logical qubits, and announced hardware is not demonstrated hardware. That’s the depth required. Algorithm selection belongs with the cryptographic engineering team.

The second is oscillation. Boards that fund migration hard after a quantum computing announcement and quietly deprioritize it two quarters later produce programs with no sustained momentum and no institutional memory. Approved appetite statements and fixed thresholds exist to insulate the program from the news cycle, and the semi-annual threat assessment gives new information a defined route in.

Where This Belongs on the Risk Report

Post-quantum migration should not get its own governance structure. If the board reads a quarterly enterprise risk report with a standard format, cryptographic risk appears as a line in it. If the risk committee reviews a heat map, it sits on the map, positioned by likelihood and impact like everything else. If the audit committee tracks compliance deadlines, the post-quantum deadlines sit in the same tracker.

The enterprise risk function will usually need to add cryptographic risk as a category in the taxonomy, most often under technology or cybersecurity risk. That’s a one-time update, best done in the program’s first quarter. The target is zero incremental governance overhead: same reports, same format, same cadence, no standing quantum briefing.

The Briefing a Director Actually Needs

The technical grounding for competent oversight is bounded, and it fits comfortably into a single session. A director should be able to state harvest now, decrypt later in one sentence, namely that encrypted traffic captured today can be stored and decrypted years later once the hardware exists, so long-lived data is already exposed. They should know which deadlines bind their own organization. They should be able to follow a status report that distinguishes ML-KEM, the standardized key establishment algorithm in FIPS 203, from ML-DSA, the signature algorithm in FIPS 204. They should know that hybrid deployment is the current default and why. And they should understand that the estate inventory, rather than the algorithm choice, is where these programs usually run late.

That’s the syllabus. It’s a briefing and a working vocabulary, not a physics course, and it’s what turns the KRI report from a page of numbers into a page a director can interrogate.

Quantum Academy’s board and executive programs are built to that scope, covering the threat model, the standards, the regulatory calendar, and the governance mechanics without the mathematics. For the underlying migration methodology that the program office will be executing against, see the PQC Migration Framework. For deeper technical background on the standards and the threat timeline, PostQuantum.com goes several layers below this article.

Explore the executive and board programs at quantumacademy.com/.