PQC Migration for Cloud Platforms and SaaS
Cloud providers face the migration twice over. They have to migrate their own infrastructure while enabling their customers’ migrations at the same time. The shared responsibility model creates questions about what the provider must do versus what the customer must do. TLS termination at cloud scale involves different engineering challenges than enterprise TLS migration. And KMS/HSM fleet upgrades affect every customer simultaneously.
This course covers PQC migration for cloud platforms, SaaS providers, and managed service providers.
Course Outline
Module 1. Shared Responsibility in PQC Migration
What the provider must migrate versus what the customer must migrate. How to communicate PQC migration responsibilities to customers. Customer-managed key considerations. API and SDK PQC support timelines.
Module 2. TLS at Cloud Scale
TLS termination for millions of connections: performance implications of PQC algorithms at scale. Load balancer and CDN considerations. Certificate management at scale. Hybrid deployment during transition.
Module 3. KMS and HSM Fleet Migration
Key management service PQC migration affecting all customers. HSM firmware upgrade coordination. Customer-managed key transitions. Key wrapping and re-encryption at scale.
Module 4. Compliance and Market Requirements
FedRAMP PQC requirements. SOC 2 implications. Customer audit expectations. Building PQC readiness as a competitive differentiator.
Prerequisites
None. Sector experience is helpful but not required. For a broader PQC foundation, consider starting with Post-Quantum Foundation.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. This is not a professional certification.
Who this course is for
Platform security architects, key management service owners, TLS and edge infrastructure leads, and compliance staff who own FedRAMP or equivalent obligations. Product managers belong here too. Customer-facing post-quantum capability becomes a roadmap commitment.
If you consume cloud rather than provide it, the sector overview for your own industry is the better fit.
What you’ll be able to do afterward
- Draw the post-quantum line through a shared responsibility model and defend where you put it
- Plan hybrid key exchange rollout across TLS termination at platform scale
- Sequence key management service migration without breaking customer key hierarchies
- Answer a customer post-quantum readiness questionnaire with something specific and true
- Turn customer-facing post-quantum capability into a product roadmap
What you leave with
You leave with the course handbook, a PDF of the full material with the instructor notes written out in place of the slides’ bullet points, and a PDF copy of Quantum Ready, included at no extra cost. The handbook is yours to keep. For most organizations, that shared reference is the clearest return on a training budget.
Enrollment includes 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
Where this course fits
Nothing is required. Post-Quantum Foundation covers the algorithm vocabulary if you want it first. The Quantum-Safe Cloud Service Providers Intensive is the working session. Hybrid Cryptographic Implementations for the TLS engineering underneath it.
Why we teach this
The course is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org and written by the practitioners who teach here. The people who teach this course are running migration programs inside organizations now, and the course covers what those programs hit.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.