Cloud providers run two migrations at once. The platform has to move, and customers have to be given the means to move on top of it. Those are different programs with different deadlines, and customers start asking about the second one in their questionnaires long before anyone is ready for it.
This is a working day. You bring your own architecture and your own shared responsibility model, and you leave with both plans and a clear line between them.
Who this intensive is for
Platform security architects, KMS and cryptography service owners, TLS and edge infrastructure leads, compliance staff who own FedRAMP or equivalent obligations, and the product managers who will have to explain post-quantum capability to customers.
Bring product management. The customer-facing half of this workshop produces roadmap commitments, not just engineering ones.
What you’ll be able to do afterward
- Draw the post-quantum line through your shared responsibility model and defend where you put it
- Plan hybrid key exchange rollout across TLS termination at platform scale, including the client compatibility long tail
- Sequence key management service migration without breaking customer key hierarchies
- Answer a customer post-quantum readiness questionnaire with something specific and true
- Map FedRAMP and comparable obligations onto the migration timeline
- Set the product roadmap for customer-facing post-quantum capability and price the engineering behind it
What you leave with
Every participant receives the course handbook, a PDF of the full material with the instructor notes written out, and a PDF copy of Quantum Ready. The day itself produces a platform cryptographic estate map, a shared responsibility boundary statement covering post-quantum, a KMS and key hierarchy migration sequence, and a customer-facing readiness statement and questionnaire response template. All are editable and yours to keep.
The day
Morning, first block. The platform. Cryptographic estate across compute, storage, network, and identity. Where platform ends and customer begins.
Morning, second block. TLS and keys at scale. Hybrid key exchange rollout, the compatibility long tail, and KMS migration without breaking customer hierarchies.
Afternoon, first block. The customer-facing migration. What customers will ask for and when. Turning that into a product roadmap with engineering behind it.
Afternoon, second block. The plan. Assemble both plans. Draft the readiness statement you are prepared to put in writing.
Where this course fits
Quantum-Safe Cloud Service Providers is the prerequisite in substance rather than in rule. It covers the same ground at overview depth, and participants who arrive having taken it start the day with the vocabulary already shared. Afterward, Hybrid Cryptographic Implementations for the engineering detail, and PQC Vendor Governance for the supply chain underneath the platform.
Why we teach this
The day is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org, applied to this sector by instructors who run migration programs in it. No published sector extension exists for this industry yet. The sector material is the instructors’ own field work.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. This is not a professional certification.
Enrollment includes 180 days of access to the corresponding online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.