Quantum Academy begins operations on August 15, 2026. Enrollment opens soon.
Skip to content

Courses

Post-Quantum Certified Specialist (PQCS) Training

Preparation for the Post-Quantum Certified Specialist Exam

Organizations beginning their PQC migration need professionals who can assess cryptographic exposure, evaluate algorithm options, and participate meaningfully in migration planning. The PQCS Specialist Training course builds those capabilities systematically, preparing you for the PQCS certification exam.

The curriculum draws on the PQC Migration Framework, an eight-phase methodology for enterprise cryptographic transition available under Creative Commons (CC BY 4.0). Where the Post-Quantum Foundation course introduces the “what” and “why” of PQC, the Specialist Training develops the “how” — with hands-on exercises, technical depth on each standardized algorithm, and applied methodology for real-world migration scenarios.

By the end of this course, you will be able to conduct a cryptographic inventory, evaluate algorithm options for specific deployment contexts, assess hybrid implementation approaches, and develop a structured migration roadmap. These are the skills the PQCS certification exam validates.

Who Should Take This Course

This course is designed for security engineers, security analysts, application security specialists, infrastructure architects, developers, systems engineers, and technical consultants who are or will be involved in PQC migration efforts.

You should take this course if you:

  • Are responsible for assessing your organization’s cryptographic posture or quantum exposure
  • Need to evaluate PQC algorithm options for systems you build, maintain, or secure
  • Will contribute to PQC migration planning, even if you are not leading the program
  • Want a structured, vendor-independent methodology for approaching PQC migration
  • Are preparing to pursue the PQCS certification as a professional credential

No quantum computing expertise is required. The Post-Quantum Foundation course covers the necessary background.

What You Will Learn

After completing this course, you will be able to:

  • Conduct a cryptographic inventory across code, certificates, protocols, infrastructure, and third-party dependencies using structured discovery methodology
  • Build a Cryptographic Bill of Materials (CBOM) that identifies every cryptographic asset, its algorithm, its key length, and its exposure profile
  • Score and prioritize cryptographic assets for migration based on quantum risk, business criticality, and migration complexity
  • Evaluate each NIST standardized PQC algorithm — ML-KEM (formerly CRYSTALS-Kyber), ML-DSA (formerly CRYSTALS-Dilithium), SLH-DSA (formerly SPHINCS+), and FN-DSA (formerly FALCON) — for specific deployment scenarios based on performance characteristics, key and signature sizes, and security assumptions
  • Assess HQC (the code-based KEM selected as a backup standard) and its role in hedging against lattice-based risk
  • Design hybrid implementation approaches for key exchange (combining classical and post-quantum algorithms) and digital signatures
  • Analyze PQC migration requirements for TLS 1.3, SSH, IPsec, S/MIME, code signing, and PKI
  • Develop a structured PQC migration roadmap using risk-based prioritization and phased deployment
  • Apply cryptographic agility principles to system design and architecture planning to reduce the cost of future transitions

Course Outline

Module 1 — The Quantum Threat: Beyond the Headlines

The Foundation course introduces the quantum threat conceptually. This module goes deeper: how Shor’s algorithm actually breaks RSA and ECC, what resource estimates tell us about CRQC timelines, where error correction thresholds stand today, and how to build a defensible timeline assessment rather than relying on vendor predictions or media narratives. You will examine the HNDL (harvest-now-decrypt-later) and TNFL (trust-now-forge-later) threat models in technical detail and learn to assess which of your organization’s assets are exposed to each.

Module 2 — NIST PQC Algorithms: Technical Assessment

A rigorous evaluation of every NIST standardized algorithm. For each — ML-KEM, ML-DSA, SLH-DSA, FN-DSA, and HQC — you will examine the underlying mathematical problem, performance characteristics (key generation, encapsulation/decapsulation or signing/verification times), key and ciphertext/signature sizes, security level mapping to NIST categories, and known implementation considerations. The module covers how to select the right algorithm for a specific deployment context: when ML-KEM is the default choice, when SLH-DSA’s conservative security assumptions justify its larger signatures, when FN-DSA’s compact signatures matter, and where HQC provides meaningful diversity against lattice-based risk.

Module 3 — Cryptographic Inventory and CBOM

The work that every migration depends on: finding where cryptography lives in your environment. This module teaches structured discovery methodology across application code, TLS/SSH/IPsec configurations, certificate deployments, key management infrastructure, database encryption, file and disk encryption, hardware security modules, and third-party services. You will learn to build a CBOM using standardized formats, automate discovery where tooling exists, handle the gaps where it does not, and score each asset using a risk-weighted prioritization model that drives migration sequencing.

Module 4 — Hybrid Implementations

Hybrid cryptography — running classical and post-quantum algorithms simultaneously — is the consensus transition approach endorsed by NIST, BSI, ANSSI, and NCSC. This module covers the engineering specifics: how hybrid key exchange works in TLS 1.3 (the concatenation and combiner approaches), how hybrid signatures can be constructed, what the performance and bandwidth implications are, how to handle fallback and negotiation, and what “hybrid exit” looks like once confidence in post-quantum algorithms is established. Hands-on exercises include configuring hybrid TLS with open-source libraries.

Module 5 — Protocol Migration Assessment

Each protocol presents different migration challenges. TLS 1.3 has the most mature PQC support (ML-KEM hybrid key exchange is already deployed at scale). SSH requires key exchange and host key migration. IPsec faces IKEv2 integration and performance considerations. S/MIME and email encryption involve certificate chain changes and legacy client compatibility. Code signing involves long-lived trust anchors. PKI migration is an entire discipline (covered in depth in the advanced PKI course). This module gives you the assessment framework: for each protocol in your environment, what changes are required, what is available today, and what sequencing makes sense.

Module 6 — Migration Planning and Prioritization

Turning the inventory into a roadmap. This module covers risk-based prioritization (which assets migrate first and why), phased approaches (quick wins versus long-term architectural changes), pilot program design, testing and validation strategies, vendor and supply chain considerations (what happens when your migration timeline depends on a vendor who has not yet shipped PQC support), rollback planning, and stakeholder communication. You will develop a migration roadmap for a realistic scenario as a course exercise.

Module 7 — Cryptographic Agility

The PQC migration will not be the last cryptographic transition. This module covers designing systems that can change algorithms with bounded effort: agility at the application layer, protocol layer, and infrastructure layer. You will examine which architecture patterns genuinely achieve agility versus those that only claim it, how to test agility in practice, and how agility relates to ongoing compliance and risk management. The module concludes with a self-assessment: how agile are the systems you work with today, and what would it take to improve them?

Format and Delivery

This course is available in three delivery formats. All formats cover the same curriculum and prepare you for the same PQCS certification exam.

Online (self-paced) — US$1,999. Access the full course on the Quantum Academy learning platform (learn.quantumacademy.com). Approximately 40 hours of content including video, text, interactive exercises, and hands-on labs. Progress at your own pace within a 180-day access window.

Live online (instructor-led) — US$1,999. Real-time, instructor-led sessions delivered over multiple days via video conference. Includes live Q&A, group exercises, and direct instructor access. Scheduled cohorts throughout the year.

In-person (instructor-led) — US$2,999. Multi-day sessions at scheduled locations worldwide. Small-group format with printed course materials, hands-on lab environments, and direct instructor access.

Corporate delivery — Custom training for organizational teams of 10 or more, delivered online or at your location. Contact training@quantumacademy.com for scheduling and pricing.

All formats include course materials. The PQCS certification exam is not included (purchased separately or as a bundle — see pricing below).

Prerequisites

Recommended Reading

What Comes Next

After completing this course, you are eligible to sit for the PQCS certification exam. The exam validates the competencies covered in this course through a proctored, scenario-based assessment.

Upon earning your PQCS credential, you may pursue any of the three specialized post-quantum certifications:

Earn all three and you are automatically awarded PQCX — Post-Quantum Certified Expert.

Pricing

OptionPrice
Online (self-paced)US$1,999
Live online (instructor-led)US$1,999
In-person (instructor-led)US$2,999
Online training + PQCS exam bundleUS$2,399
In-person training + PQCS exam bundleUS$3,399
Foundation → PQCS online bundle (Foundation + training + exam)US$2,649
Foundation → PQCS in-person bundle (Foundation + training + exam)US$3,599

All prices are in US dollars.