Quantum Academy begins operations on September 1, 2026. Enrollment opens soon.
Skip to content

Technical deep dives

PQC for GRC Professionals

Governance, risk, and compliance for PQC migration. Mapping requirements to ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC, FedRAMP, DORA, and NIS2. Risk assessment, evidence frameworks, and vendor readiness evaluation.

4 hours Intermediate Online On-Demand / Live Online / In-Person US$499–999

Governance, Risk, and Compliance for the Migration

PQC migration intersects with nearly every compliance framework an organization is subject to. Governance, risk, and compliance professionals need to map migration requirements to the frameworks they manage, build the risk assessments that justify the program, and produce the evidence that auditors and regulators will demand. This course covers the GRC dimension of PQC migration in depth.

Who Should Take This Course

GRC professionals, compliance managers, risk analysts, internal auditors, and information security governance specialists.

What You Will Learn

This course provides hands-on technical depth in a specific dimension of PQC migration, aligned with the PQC Migration Framework. You will gain practical, applicable skills you can use immediately in migration work.

Course Outline

Module 1 — Mapping PQC to Compliance Frameworks

How PQC migration maps to major frameworks: ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC, FedRAMP, DORA, and NIS2. Which controls are affected. How cryptographic requirements appear (and are changing) in each framework. Building a cross-framework compliance view for migration.

Module 2 — Risk Assessment for PQC

Conducting quantum risk assessments within existing risk management frameworks. Quantifying quantum exposure for the risk register. The HNDL and TNFL threat models in risk assessment terms. Integrating quantum risk into enterprise risk management and board reporting.

Module 3 — Evidence and Audit Frameworks

Producing compliance evidence for PQC migration. What auditors will look for. Structuring documentation as audit-ready evidence. Mapping migration activities to control requirements. Demonstrating progress and compliance during a multi-year transition.

Module 4 — Vendor Risk and Third-Party Compliance

Assessing vendor PQC readiness as a GRC function. Third-party risk management for cryptographic dependencies. Contractual and compliance requirements for vendors. Building PQC readiness into vendor assessment frameworks and procurement processes.

Prerequisites

A working understanding of PQC fundamentals is recommended. Consider Post-Quantum Foundation or PQCS certification for background. Some courses assume security engineering experience.

Certificate of Completion

Upon completion, you will receive a Quantum Academy certificate of completion. CPE credits earned may apply toward Quantum Academy certification maintenance.

Enroll

Book this course

Online On-Demand

Start immediately and learn at your own pace, with full access to every lesson, exercise, and reference you keep.

US$499

Enrollment opens soon.

Private Team Training

Bring this course to your organization: online or at your location, on your schedule, tailored to your environment.

Custom quote

Contact us about private training

Live Online

Join a scheduled instructor-led cohort over video, with real-time exercises, discussion, and direct Q&A.

US$749

Includes 180 days of access to the online on-demand course.

Dates coming soon.

In-Person

Attend a scheduled classroom session: immersive, hands-on, and away from the distractions of a working day.

US$999

Includes 180 days of access to the online on-demand course.

Dates coming soon.

Online on-demand courses are delivered through the Quantum Academy learning platform. Live online, in-person, and private team sessions are scheduled separately. Prices are shown in US dollars.

← All courses & certifications