OT migration is governed by constraints that do not negotiate. Safety cases that must be revalidated before anything changes, patching windows measured once a year, device populations older than the engineers maintaining them, and a substantial share of equipment that will never run post-quantum cryptography at all.
Who this intensive is for
OT security architects, control systems and automation engineering leads, safety engineering, plant and site operations, and the security leadership responsible for the boundary between IT and OT. Delivered privately. The day works from your own asset register.
Safety engineering belongs in the room from the start. A plan that reaches them at the end is a plan that gets rejected at the end.
What you’ll be able to do afterward
- Map cryptographic dependencies across the Purdue levels and mark where they cross the IT and OT boundary
- Triage the asset base into what migrates, what is gatewayed, what is isolated, and what is scheduled for retirement
- Plan around ICS and SCADA protocols that have no post-quantum path and are not getting one
- Work migration steps into existing safety-case revalidation rather than triggering new ones
- Apply the NIS2 and sector compliance overlay as a planning input
- Defend a mitigation decision for an un-upgradeable asset to an auditor or a regulator
What you leave with
Every participant receives the course handbook, a PDF of the full material with the instructor notes written out, and a PDF copy of Quantum Ready. The day itself produces an OT cryptographic dependency map across the Purdue levels, an asset triage with a defensible rationale for each mitigation decision, a migration sequence mapped to safety-case revalidation and patching windows, and a compliance narrative for the un-upgradeable population. All are editable and yours to keep.
The day
Morning, first block. The estate and the boundary. Cryptographic dependencies by Purdue level. Where IT and OT actually meet, as opposed to where the diagram says they do.
Morning, second block. Constraints. Safety cases, patching windows, device lifetimes, and vendor support horizons. What each rules out.
Afternoon, first block. What cannot migrate. Triage and mitigation. Gateways, segmentation, compensating controls, and retirement, each with the argument that defends it.
Afternoon, second block. The plan. Sequence against safety and maintenance calendars. Draft the compliance narrative.
Where this sits in your path
Quantum-Safe OT and Critical Infrastructure is the prerequisite in substance rather than in rule. It covers the same ground at overview depth, and participants who arrive having taken it start the day with the vocabulary already shared. Afterward, Quantum-Safe Energy and Utilities for the regulated utility overlay, and PQC Vendor Governance for the supplier and integrator conversations.
Why we teach this
The day is built on the OT/CNI Extension of the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org. The instructors run migration programs in this sector, and that is where the constraints in this material come from.