Preparation for the Post-Quantum Certified Manager Exam
PQC migration is not a purely technical exercise. It requires program governance, regulatory awareness, cross-functional coordination, vendor management, budget justification, and executive communication. The organizations that migrate successfully will be led by managers who understand both the technical requirements and the organizational machinery needed to execute a multi-year cryptographic transition.
PQCM Manager Training prepares experienced professionals to lead PQC migration programs from assessment through execution and ongoing compliance. The curriculum is aligned with the PQC Migration Framework, providing a structured methodology that maps program governance activities to each phase of the migration lifecycle.
This course goes beyond the technical competencies covered in PQCS Training. Where PQCS teaches you what needs to change and why, PQCM teaches you how to make it happen within an organization: the governance structures, the stakeholder management, the vendor coordination, and the regulatory compliance that determine whether a migration program succeeds or stalls.
Course Outline
Module 1. PQC Program Governance and Framework Alignment
Establishing the governance structure for a multi-year PQC migration program. Mapping the PQC Migration Framework phases to organizational program management. Defining roles and responsibilities: who owns the migration, who approves technical decisions, who manages vendor relationships, who reports to the board. Standing up a program office versus embedding migration into existing security program structures. Reporting cadence and escalation paths.
Module 2. Regulatory Requirements and Compliance Mapping
The regulatory requirements driving PQC migration across jurisdictions and sectors. CNSA 2.0 and the US federal timeline (including the January 2027 acquisition gate). EU quantum-readiness initiatives and the NIS2 connection. DORA and its crypto-agility requirements for financial services. Sector-specific mandates and how they differ. Mapping each requirement to specific migration activities and deliverables. Building a compliance calendar that keeps the program on track.
Module 3. Organizational Readiness Assessment
Assessing whether your organization is ready to migrate: not just technically, but operationally. People: do you have the skills, and if not, what training or hiring is needed? Processes: are change management, testing, and deployment processes ready for cryptographic changes? Technology: is your tooling sufficient for discovery, migration, and verification? Vendors: which third-party dependencies gate your timeline? Identifying blockers and accelerators. Producing a readiness assessment that drives the program plan.
Module 4. Cross-Functional Program Execution
Building and managing a migration team that spans organizational boundaries. Coordinating across security, engineering, IT operations, procurement, legal, and business units when each has competing priorities. Managing the tension between migration urgency and operational stability. Change management: how to move an organization that has never thought about cryptographic migration into a multi-year program without losing momentum. Practical techniques for maintaining executive sponsorship.
Module 5. Risk Communication and Executive Engagement
Translating quantum risk into language that resonates with executive leadership and board members. Using the HNDL and TNFL threat models in board briefings: the harvest scenario for confidentiality risk, the forgery scenario for authenticity and trust risk. The balance between urgency and accuracy. Avoiding fear-based communication while conveying genuine risk. Distinguishing Q-FUD (vendor-driven quantum panic) from evidence-based urgency. Budget justification and ROI framing: how to present migration as risk reduction, regulatory compliance, and competitive positioning rather than a pure cost center.
Module 6. Vendor and Supply Chain Management
Assessing vendor PQC migration plans and readiness. Contractual requirements for cryptographic transition: what to include in new contracts and how to address existing agreements. Managing third-party cryptographic dependencies when your migration timeline depends on vendors who have not yet shipped PQC support. Criticality tiering: which vendor dependencies are blocking and which can be bridged. Software supply chain considerations and SBOM/CBOM integration. The 62% problem: in the 2025 IBM Institute for Business Value and Cloud Security Alliance study of 750 executives, 62% said they expect vendors to handle the quantum-safe transition for them, and this module covers why that assumption fails.
Module 7. Migration Execution and Lifecycle Management
Pilot program design: selecting the right systems, defining success criteria, and building organizational confidence. Testing and validation requirements at each stage. Rollback planning: ensuring every migration step can be reversed if problems emerge. Production migration sequencing: which systems migrate first and why. Post-migration monitoring: detecting issues that only appear under production load. Ongoing cryptographic health assessment: migration is not a one-time project but a permanent operational capability. Recertification and compliance maintenance.
Format and Delivery
This program is available online on-demand, live online, in person, and as private team training; current prices for each format are in the booking section below. Live online and in-person sessions include 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is. Training format and exam format are independent: however you train, the exam is delivered as a proctored assessment, under arrangements confirmed when you book.
Live online and in-person sessions run 24 hours of instruction across four days, six hours of teaching each day within a seven and a half hour schedule that includes lunch and breaks. The online on-demand course covers the same material at a self-paced pace of roughly 40 hours.
Prerequisites
- Active PQCS – Post-Quantum Certified Specialist certification
What Comes Next
After completing this course, you are eligible to sit for the PQCM certification exam. Earn PQCM + PQCA + PQCV and you are automatically awarded PQCX – Post-Quantum Certified Expert.
Pricing
| Option | Price |
|---|---|
| Online (self-paced) | US$2,499 |
| Live online (instructor-led) | US$2,999 |
| In-person (instructor-led) | US$3,499 |
| Online training + PQCM exam bundle | US$2,999 |
| In-person training + PQCM exam bundle | US$3,999 |
All prices are in US dollars.
Who this course is for
CISOs, security managers, program managers, project managers, compliance managers, risk managers, and senior technical leaders who are responsible – or will be responsible – for overseeing PQC migration within their organizations. It is also appropriate for consultants and advisors who guide clients through PQC transitions.
What you’ll be able to do afterward
- Design and govern a PQC migration program with defined scope, milestones, roles, and success criteria
- Map regulatory requirements (CNSA 2.0, EU directives, sector-specific mandates) to concrete migration timelines and deliverables
- Conduct an organizational readiness assessment covering people, process, technology, and vendor dependencies
- Build and manage a cross-functional migration team spanning security, IT, development, procurement, legal, and compliance
- Develop risk communication strategies for technical and executive audiences, including board-level reporting
- Evaluate vendor PQC readiness and manage supply-chain cryptographic dependencies
What you leave with
You leave with the course handbook, a PDF of the full material with the instructor notes written out in place of the slides’ bullet points, and a PDF copy of Quantum Ready, included at no extra cost. The handbook is yours to keep. For most organizations, that shared reference is the clearest return on a training budget.
Enrollment includes 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
Where this course fits
An active PQCS certification is required before this training. The path runs Foundation, then PQCS, then here. PQC Migration Project Management and PQC Migration: Executing the Waves are the operational follow-ons. PQC Migration: Building the Business Case helps if funding is still unsettled.
Why we teach this
The course is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org and written by the practitioners who teach here. The people who teach this course are running migration programs inside organizations now, and the course covers what those programs hit.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. This is not a professional certification.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.