FIPS 140-2 validated cryptographic modules move to the historical list on September 21, 2026. That date is fixed by CMVP policy. NIST has finalized its PQC standards (FIPS 203-205) but has not set deprecation dates for RSA-2048 or approved elliptic-curve cryptography in SP 800-131A, so watch that document for any change in status. NSA’s CNSA 2.0 does set dated timelines, and they bind National Security Systems rather than everyone else. The EU’s coordinated roadmap asks member states to have high-risk use cases migrated by the end of 2030, as a recommended target rather than a binding one. One of those dates is fixed, one binds only national security systems, one is a recommendation, and none of them waits for your budget cycle. So the funding request has to go in this year, and the first question the finance committee asks has no published answer.
That question is what it will cost. There is no number to look up, because no enterprise has completed a post-quantum cryptography migration and published what it spent. The vendor market’s cost claims are marketing until a customer publishes actuals, and none has. What follows is a way to build a budget anyway: not by finding a benchmark, but by constructing an estimate from figures your own organization already holds.
Why the number does not exist
Post-quantum cryptography, or PQC, is the set of algorithms designed to resist attack by a large quantum computer. Migrating to it means finding and replacing the public-key cryptography embedded across an entire estate. The reason nobody can price that work has three parts, and only one of them is about quantum computing.
The first is that cryptography has never been a line item. It sits inside development budgets, infrastructure contracts, appliance refreshes, and managed service fees. Ask your finance team what the organization spent on cryptography last year and they can’t tell you, because no chart of accounts has ever carried the category. There is no baseline to grow from.
The second is that nobody knows the size of the estate before they look. Certificates, embedded libraries, hardcoded keys in twenty-year-old applications, cryptography inside devices your vendors manage on your behalf. The scope is unknown until discovery measures it, and discovery is itself a funded piece of work.
The third is that comparable programs are still running. Enterprise migrations are two years into a decade. The data that would let anyone build a top-down cost model arrives around 2030, which is also roughly when the model would stop being useful.
Go into the meeting precise about which parts of the budget you can defend and which parts are still ranges. Finance committees work with imprecise estimates constantly, in acquisitions, R&D portfolios and capital programs. What they can’t approve is a blank space, and what they won’t forgive is a single confident number that turns out to be wrong.
Three tiers of confidence
Split the program into three tiers according to what determines the cost, not according to when the work happens. This is the structural move that makes the whole request defensible, because it lets you be exact where exactness is available and honest where it isn’t.
Tier one costs are set by your org chart. Program leadership, governance, training, first contact with vendors. What these cost depends on how your organization staffs a multi-year program, not on how much cryptography you own. You can price them to within a few percent today.
Tier two costs are set by the scope of the search. Discovery, tooling, the analysis effort behind a cryptographic inventory. The bounds are known even though the findings aren’t, because you already know how many sites, networks, applications and business units exist. You can price this to within a reasonable band today.
Tier three costs are set by what the search finds. Infrastructure rebuild, application remediation, testing, vendor coordination, running two cryptographic stacks in parallel. These stay ranges until discovery closes, and pretending otherwise is where credibility goes.
Present the tiers in that order and the shape of the ask follows on its own. You are requesting tier one and tier two in full, with line items. You are giving finance a bounded envelope for tier three, plus a date when the envelope narrows.
Tier one: the costs your org chart sets
Everything here can be built from four inputs your organization already has, and none of them come from a quantum vendor.
Finance holds the fully loaded cost of an internal engineer-year and of a program manager-year. Procurement holds the day rate on your existing advisory framework agreements. HR holds the cost per seat of external technical training, and the PMO holds the actual staffing profile of the last two multi-year infrastructure programs the organization ran.
With those four numbers, tier one is arithmetic. A dedicated program lead, a program office sized against your PMO’s own precedent, a fixed number of advisory days for cryptographic architecture review, a board and executive briefing, and a training budget expressed as seats times seat cost. Write it as a formula with your organization’s rates substituted in, and show the formula to the CFO. A budget line that decomposes into headcount times a rate finance already approves is a budget line finance can check.
Two points that decide whether tier one holds up. The program lead cannot be the CISO doing this on top of the day job, and the training is not deferrable. Application teams meet PQC requirements in their sprint backlogs long before the central program reaches them, and every team that meets them without preparation produces rework that lands in tier three.
Tier two: the cost of looking
Discovery produces the cryptographic bill of materials, or CBOM: a structured inventory of every place the organization uses public-key cryptography, classified by algorithm, key size, protocol, owner and business criticality. It is the artifact that converts tier three from a guess into a plan.
Its cost is boundable because its scope is countable. You know how many network segments, endpoints, applications, and operational technology sites you have. What you don’t know is what the scan will find inside them, and finding out is exactly what you are asking to fund.
Four things belong in this line, and the first is the one that most often goes missing. Cryptographic discovery tools scan against an asset inventory. If your asset inventory is partial, and in most organizations it is, then building it is a prerequisite cost that appears in the PQC budget whether or not it belongs to PQC. Check this before the meeting, because a CFO who discovers it in month four will discount every subsequent estimate you produce. The other three are the tooling itself, deployment into a change-controlled production environment including any sandbox your change board demands, and the analyst effort to interpret, classify and validate results. Automated tools miss operational technology, air-gapped systems, embedded devices and anything a vendor manages for you, so a share of discovery is people asking questions.
Size the analyst effort against a program the PMO can show you, not against a vendor’s estimate. Your last major discovery exercise, whether that was a data mapping program under GDPR or a software bill of materials rollout, has a real staffing curve attached to it in your own records.
Tier three: the costs the search will set
You still owe finance a directional total, so give them one as a bounded range with two independent anchors and the assumptions written on the face of it.
Anchor one: a published public-sector total
The US Office of Management and Budget’s July 2024 Report on Post-Quantum Cryptography, submitted to Congress under the Quantum Computing Cybersecurity Preparedness Act, put the cost of migrating federal civilian agency systems at roughly $7.1 billion (USD) across 2025 to 2035. It is the only large published figure in existence and it is worth using, with one caution. Dividing it by the population to get a cost per citizen has no basis: the money buys agency systems, not people. Treat it as an order-of-magnitude check on whether your own total is plausible for an estate of comparable scale, and say so out loud when you present it. A CFO who spots you over-claiming on your only external reference will discount the internal ones too.
Anchor two: your own last cryptographic migration
This is the stronger anchor, and almost nobody uses it. Your organization has already run a cryptographic migration. The SHA-1 to SHA-2 transition, the retirement of TLS 1.0 and 1.1, a CA change after a vendor distrust event. Finance holds the invoices, the PMO holds the schedule, and the application owners remember which systems took three months longer than planned.
Pull the actuals. Then state the multiplier and defend it: this program touches more systems, has a harder deadline, changes key and signature sizes rather than just a hash, and involves vendors whose own timelines you don’t control. A ratio applied to a documented internal precedent is far harder to argue with than a range quoted from an industry report, because the base is auditable and the multiplier is the only thing under discussion.
Present tier three as three scenarios, and attach each one to an assumption finance can independently test. The optimistic case assumes a current asset inventory, mostly cloud-native services with cryptography behind an abstraction layer, little operational technology, and cooperative tier-one vendors. The conservative case assumes the opposite of each. The CFO can call the CIO and ask whether the asset inventory is current, and when the answer comes back, the anchor moves without you having to argue for it.
Where the estimate moves, and which way
Tier three estimates move in one direction. Naming the mechanisms in the budget paper is what separates a range from an evasion.
Algorithm replacement is the small part. Swapping a key exchange is a fraction of the work. The rest is application refactoring, data format changes, interface contracts, re-certification, and regression across everything downstream. Programs that scope PQC as an algorithm change discover the remainder in year two, when the funding envelope is already fixed.
Testing outruns its allocation. New algorithms change key sizes, signature sizes and handshake behavior, so performance testing is not optional and regression is not a formality. Anything requiring FIPS validation carries a queue measured in quarters, not weeks.
Dual running has a standing cost. Hybrid deployment means classical and post-quantum cryptography operate side by side for years. The sizes are not marginal: an ML-KEM-768 encapsulation key, standardized in FIPS 203, is 1,184 bytes, against 32 bytes for an X25519 public key. That lands on handshake latency, certificate storage, hardware security module capacity and network egress, and it lands on two operational stacks to monitor and staff rather than one.
Vendor timelines are not yours. When a critical supplier cannot meet your date, you wait or you build a workaround that later gets thrown away. Both cost money, and neither is in a first-pass estimate unless you put a contingency line there deliberately.
Operational technology is its own program. Long device lifecycles, constrained update paths, safety-critical change control. Estimate it as a separate workstream with its own discovery, not as a percentage uplift on the IT number.
Matching the ask to the confidence
Structure the request so the precision of each ask matches the confidence behind it.
Ask for tier one and tier two in full, as a fully specified year-one budget with named deliverables and dates. Present tier three as a range with the three scenarios and their assumptions. Then commit to a stage gate: at the close of discovery you return with the CBOM, a remediation plan sized against measured counts, and a narrowed range. Offer the comparison of estimate against actual at each subsequent gate, and offer it before anyone asks for it.
Split the whole thing into CapEx and OpEx, because that’s the language capital committees allocate in. Capital expenditure covers assets that depreciate: hardware security modules, PKI rebuild, purchased tooling, capitalized development effort on application changes. Operating expenditure covers what recurs: program office staffing, advisory days, subscription tooling, training, legal work on contract amendments, and the hybrid running cost. A request that arrives without that split comes back for rework, and the resubmission costs you a quarter.
Show the profile as annual cash flows across the program’s planned duration rather than a single total, with contingency as its own visible line. Contingency buried inside other categories reads as padding when it’s found, and it will be found.
The four questions finance will ask
What is year one? Tier one plus tier two, itemized. Lead with this figure rather than the program total, because it’s the number you can defend line by line.
What is the total? The range, the assumptions, and the date the range narrows. A range with a stated refinement process reads as program management. A confident total reads as a guess until it fails, and then it reads as a credibility problem.
What if we wait two years? The regulatory timetable doesn’t slip to meet you, so the same work compresses into a shorter window with less sequencing freedom and a thinner specialist market. And every additional month extends exposure to harvest now, decrypt later: adversaries capturing encrypted traffic today to decrypt once a capable quantum computer exists. Data with a ten-year confidentiality requirement is already inside that window.
What do we get if Q-Day never comes? A complete cryptographic inventory, certificate lifecycle management that works, legacy protocols retired, vendor governance with cryptographic disclosure rights in the contracts, and crypto-agility, meaning the ability to change an algorithm without reopening every application. Those are improvements the organization owes itself regardless of when a cryptographically relevant quantum computer arrives. The migration is what finally funds them.
What this asks of the people running it
Every step above depends on the same capability: someone in the room who understands the algorithms well enough to size the work honestly, and understands the finance process well enough to phrase the request in terms a capital committee approves. That combination is rare, and hiring for it is slower than training for it.
The PQC Framework at pqcframework.org sets out the migration methodology behind the tiers described here, and PostQuantum.com carries the longer technical treatment of the cost categories. If your team needs the underlying capability rather than the reference material, Quantum Academy’s certification programs cover migration planning, cryptographic discovery and program governance for exactly the people who have to build this budget and then deliver against it. The current catalog is at quantumacademy.com/.
The cost model improves by running the program. It does not improve by waiting for someone else to publish theirs.