Getting PQC Migration Funded
Many organizations recognize the quantum threat but struggle to secure budget for migration. The technical case is clear, but the business case — cost justification, ROI framing, executive presentation — is where programs stall.
This two-hour course addresses that gap. It covers cost modeling for PQC migration, regulatory compliance framing, risk quantification, and the presentation techniques that convert executive awareness into budget approval. It is designed for anyone who needs to justify PQC migration spending to leadership, whether as a CISO, program manager, consultant, or technical leader.
Who Should Take This Course
Security leaders building migration budget proposals, program managers seeking funding, consultants advising clients on PQC investment, and technical leaders who need to translate quantum risk into financial language.
What You Will Learn
- Model PQC migration costs using industry benchmarks and organizational factors: estate size, cryptographic diversity, vendor dependency, and organizational complexity
- Frame PQC migration as regulatory compliance, risk reduction, and competitive positioning rather than discretionary security spending
- Quantify quantum risk exposure using HNDL data sensitivity windows and TNFL trust dependency analysis
- Articulate ROI using frameworks that resonate with CFOs: cost avoidance (regulatory penalties, insurance premiums), risk transfer value, and competitive advantage
- Present the business case to executive audiences using evidence-based urgency without fear-based messaging
- Handle common objections: “quantum computers are decades away,” “our vendors will handle it,” “we’ll wait for standards to mature”
Course Outline
Module 1 — Cost Modeling and Risk Quantification (60 minutes)
What PQC migration actually costs across the program lifecycle: discovery and inventory, planning and architecture, implementation and testing, verification, and ongoing operations. Cost drivers and how to estimate them for your organization. Risk quantification: converting HNDL exposure windows and TNFL trust dependencies into financial terms. The cost of not migrating: regulatory penalties, insurance premium increases, client contract losses, and breach liability in a post-CRQC world.
Module 2 — Making the Case: Framing, Funding, and Follow-Through (60 minutes)
Framing migration as an investment, not an expense. The four business case pillars: regulatory compliance (mandatory spending), risk reduction (quantified exposure), competitive positioning (demonstrable readiness), and operational improvement (cryptographic agility as permanent capability). Presentation techniques for executive audiences. Handling the timeline uncertainty objection: why regulatory deadlines create urgency independent of CRQC arrival. Handling the vendor dependency objection: why waiting for vendors is a risk, not a strategy. Building a phased funding request that gets initial approval and creates momentum.
Format and Delivery
Online (self-paced) — US$249. Approximately 2 hours. 90-day access.
Live online (instructor-led) — US$249. 2-hour session.
In-person (instructor-led) — US$499. 2-hour workshop. Ideal for leadership teams building a joint business case.
Prerequisites
None.
Pricing
| Option | Price |
|---|---|
| Online (self-paced) | US$249 |
| Live online (instructor-led) | US$249 |
| In-person (instructor-led) | US$499 |
All prices are in US dollars.