Three dates now sit in front of most security leaders in regulated sectors. The EU’s NIS Cooperation Group published its Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography in June 2025, recommending that member states begin their transitions by the end of 2026 and complete high-risk use cases by the end of 2030. It recommends rather than requires, which is worth stating before it reaches a board paper as a mandate. Canada’s federal migration roadmap, issued by the Treasury Board of Canada Secretariat in 2025, puts high-priority government systems on a 2031 deadline and the remainder on 2035. And NIST’s draft transition guidance, IR 8547 (initial public draft, November 2024), proposes deprecating RSA-2048 and the elliptic curve algorithms in general use after 2030, then disallowing them after 2035.
None of those dates describes a machine that exists today. All three describe procurement language, audit questions and contract clauses, and all three are close enough to land in next year’s budget conversation.
That is the opening. A security leader who has spent five years failing to fund a complete asset inventory now has an external deadline attached to a body of work that cannot start without one. Most teams are under-using that, and the way they use it decides whether the second year of funding arrives.
Why the quantum line gets approved when the hygiene line doesn’t
Budget follows exposure that someone outside the organization can name. Asset discovery has never had that. It has no examiner, no filing date and no artifact that a board member recognizes, so it competes for operational money every year and loses to whatever incident happened most recently. We have all written that business case. We have all watched it get deferred.
Post-quantum migration arrives with the missing pieces already attached. There is a dated requirement in published guidance. There is a named deliverable, the cryptographic inventory, that an auditor can ask to see. There is a second-order pressure from customers and insurers, who are starting to put quantum questions into due diligence packs. And there is a threat mechanism that does not depend on any future date at all: harvest now, decrypt later, the practice of capturing encrypted traffic today and holding it until a capable machine exists. Any data with a confidentiality life measured in decades is already exposed to it.
The useful part, for budget purposes, is what the first phase of a post-quantum program actually consists of. For the first eighteen months to two years in a large estate, that phase is discovery, inventory, cleanup and governance rather than algorithm deployment. It is the backlog, funded under a different heading, with a deadline that holds it in place.
What actually rides along
Six work streams sit inside a credible first phase. Each one is an item that has probably been on your roadmap for years. Cost them explicitly in the paper, because a by-product that nobody wrote down is a by-product nobody gets credit for.
Asset discovery
You cannot inventory the cryptography in systems you have not identified. That makes complete asset discovery a hard prerequisite rather than a nice-to-have, which is exactly the framing that has been missing. CIS Critical Security Control 1 has asked for this since the control set existed: know every enterprise asset, including end-user devices, network gear, mobile, servers, cloud instances and the operational technology on the factory floor. Almost nobody has it. Devices arrive through business units, acquisitions and contractors, and the tooling that promised full coverage delivered partial coverage.
A discovery sweep run for post-quantum purposes finds the same things a discovery sweep run for any purpose finds. Forgotten management interfaces. Dual-homed hosts. Appliances still on factory credentials. Those findings are worth remediating on their own, and now the sweep has a sponsor.
Cryptographic inventory and the CBOM
The second stream is the one every published requirement leads with. You map which systems, applications, devices and third-party services use encryption or digital signatures, and you record what they use: algorithm, key length, certificate, library, protocol version. The output is usually called a cryptographic bill of materials, or CBOM, a machine-readable list of those cryptographic components tied to the systems that depend on them.
Most organizations have never assembled one. Crypto accumulates the way anything else accumulates, through inheritance, integration and acquisition, and the knowledge of where it sits lives with whoever built each system. A CBOM converts that into an asset you can query. When a library is found vulnerable on a Tuesday afternoon, the question of which of your services depend on it becomes a lookup rather than a week of email.
Crypto debt
Crypto debt is the outdated or misconfigured cryptography already in your stack: deprecated hash functions, undersized RSA keys, expired and self-signed certificates, unsupported libraries, hard-coded secrets, protocol versions that should have been disabled years ago. These are current weaknesses, exploitable by ordinary attackers with ordinary tooling.
Inventory work turns them up because it is the first exercise that looks at cryptographic detail rather than at patch levels. Routine audits check whether a system is supported and current. They rarely check which cipher suites it negotiates. The gap between those two questions is where crypto debt survives, sometimes for a decade, and clearing it is the fastest measurable risk reduction the program will produce. It is also the finding most likely to persuade a skeptical CFO that the money is buying something now.
Crypto-agility
Crypto-agility means being able to change algorithm without changing the application: cryptography reached through an interface, algorithm choice held in configuration, key management centralized rather than scattered through code. Post-quantum migration forces the question, because you will be introducing ML-KEM (formerly CRYSTALS-Kyber) and ML-DSA (formerly CRYSTALS-Dilithium) alongside existing algorithms rather than instead of them, often in hybrid mode for a period.
The Canadian Centre for Cyber Security treats agility as a general best practice rather than a quantum-specific one, and the history supports that. RC4, DES and SHA-1 were all considered sound in their time. Whatever replaces something in 2032 will need the same plumbing that ML-KEM needs in 2027. Build it once.
Supplier assurance
Your own estate is a fraction of the problem. The joint CISA, NSA and NIST factsheet Quantum-Readiness: Migration to Post-Quantum Cryptography, published in August 2023, advises organizations to assess supply chain readiness and to ask vendors directly about their post-quantum plans. That conversation does two things at once. It tells you which suppliers are already working on this and which have not started, which is useful risk intelligence regardless of quantum. And it gives procurement a reason to add cryptographic requirements to contract templates, which raises the floor for every future purchase.
It also puts security in the same room as procurement, legal and enterprise risk on a recurring basis. That relationship is difficult to build on its own merits and easy to build around a program with a deadline.
Data retention
The last stream starts with an unusual question: which data must stay confidential for ten or twenty years? Answering it requires classification and retention review, work that most organizations postpone indefinitely. Once you have the answer, the follow-up is cheaper than it looks. Data that no longer serves a business or regulatory purpose does not need re-encrypting, migrating or defending. It needs deleting.
Every archive retired now reduces storage cost, breach exposure and migration scope in one move. It is the only stream in this list that returns money directly.
Writing the ask
The framing decides the outcome more than the content does. Six things belong in the paper.
1. Anchor on the requirement that applies to you specifically. Not the general state of the field. The named regulation, the customer contract clause, the sector supervisor’s statement, the due diligence questionnaire that arrived last quarter. One concrete instance beats a survey of the sector.
2. Scope phase one as discovery, not migration. Ask for money to find out what you have. This is honest, it is what the guidance asks for first, and it is a request the board can size. A request to migrate the estate cannot be sized yet, and asking for it invites a challenge you will lose.
3. Cost the by-products in the same document. List the six streams above with their independent value stated plainly. If your asset discovery line has been rejected three years running, say so and say what it costs. The board should be able to see that it is approving one program and receiving several outcomes.
4. Say what you will hand back. If existing budget lines for discovery tooling or certificate management are absorbed by the program, name them and return the difference. Nothing builds credibility for a second-year request faster than a first-year handback.
5. Choose a reporting artifact. Coverage of the cryptographic inventory, expressed as a percentage of in-scope systems, tracked quarterly. It is understandable without technical background, it moves visibly, and it is the number an examiner will eventually ask for anyway.
6. Ask for a multi-year envelope with annual gates. Migration programs in large estates run five to ten years. A single-year approval forces you to re-argue the case every autumn, and each re-argument is a chance to lose. Gates give the board its control point without resetting the program.
What will lose you the room
Two failures are common enough to be worth naming.
The first is the timeline claim. Nobody knows when a cryptographically relevant quantum computer, meaning one able to break RSA and elliptic curve cryptography in practice, will exist. The Global Risk Institute’s annual Quantum Threat Timeline Report surveys the researchers building these machines, and their estimates spread across more than a decade, from the early 2030s to beyond 2040. A budget case built on a specific date invites a board member to find a specialist who disagrees, and once that happens the discussion is about your forecasting rather than your program. Build the case on the published deadlines and the contract questions instead. Those are documented, dated and not open to argument.
The second is claiming a status you do not hold. “Quantum-safe” is not a description of an organization that has completed an inventory. Compliance with a 2030 milestone is not achieved by starting in 2026. Overstating progress in a board pack is the fastest route to losing the mandate when an auditor arrives, and it damages every future ask from the same team. Report coverage, findings and remediation. Let the numbers carry the claim.
The recruiting effect
One return is harder to put in a spreadsheet and worth mentioning to your HR partner anyway. Security teams lose good engineers to boredom as often as to salary. A program that involves testing new algorithms, rebuilding key management and rewriting how applications reach cryptography gives senior people something to build rather than something to triage. Teams that have run these programs report internal volunteers from outside security, which is not the usual pattern for compliance work.
The cost of that engagement is training time, and the training is not optional in any case. The engineers doing the migration need to understand what they are deploying and why the hybrid period exists.
Building the capability before the deadline
The gap between having budget and having a program is capability. Cryptographic inventory work needs people who can recognize what they are looking at. Supplier assurance needs people who can read a vendor’s post-quantum roadmap and tell the difference between a plan and a press release. Crypto-agility needs architects who have thought about where cryptographic decisions belong in a system.
For the migration methodology itself, pqcframework.org sets out the phased approach these budget cases usually describe, and PostQuantum.com carries the deeper technical background on the threat model and the standards.
For the people, that is what we build at Quantum Academy. Our post-quantum programs are designed for security professionals who now own a migration deadline and need to be competent on it within a quarter rather than a year, with the credential to show a board that the team is qualified to run the work it has been funded to do. You can see the current programs and access options at quantumacademy.com/.
Approve the budget first if you must. Just build the capability before the coverage report is due.