Telecom operators cannot migrate on their own schedule. The cryptographic estate spans the 5G core, the radio access network, transport, signaling, and hundreds of millions of subscriber credentials, and most of it moves only when 3GPP and a handful of equipment vendors decide it moves. Planning around that dependency is the work.
This is a working day, not a lecture. You bring your own network, your own vendor contracts, and your own refresh cycles, and you leave with a migration plan sequenced against the constraints that actually govern it.
Who this intensive is for
Network security architects, core and RAN engineering leads, standards and regulatory affairs staff, vendor management, and the security leadership who will sign the plan. It works best with a mixed group from one operator, because the person who tracks 3GPP rarely owns the SIM estate and neither of them holds the vendor contracts.
Bring at least one person who can speak to procurement. Half the sequencing decisions in this workshop are contract decisions.
What you’ll be able to do afterward
- Map your cryptographic estate across the 5G core, radio, transport, signaling, and subscriber identity, and mark what you control against what a vendor controls
- Turn 3GPP working group status into a dated planning assumption, and say what you do while a decision is still open
- Assess your SIM and USIM population for post-quantum subscriber authentication, including the part of it you cannot reach
- Sequence Open RAN and disaggregated components separately from the monolithic estate, since they migrate on different timelines
- Write post-quantum requirements into the next equipment refresh rather than treating migration as a separate program
- Brief a regulator or a board on where the network stands and what the next 18 months require
What you leave with
Every participant receives the course handbook, a PDF of the full material with the instructor notes written out, and a PDF copy of Quantum Ready. The day itself produces a network cryptographic estate map covering core, radio, transport, and signaling, a vendor dependency register scoring each element by who controls the timeline, a subscriber credential migration model, and a twelve-month roadmap skeleton ready for budgeting. All are editable and yours to keep.
The day
Morning, first block. The estate. Working from your own architecture, map cryptographic dependencies across the network. Where the estate is vendor-controlled, where it is yours, and where nobody has looked.
Morning, second block. Dependencies and standards. 3GPP status turned into planning assumptions. Vendor roadmap claims tested against what has actually shipped. The subscriber credential problem sized honestly.
Afternoon, first block. Sequencing the network. Which network functions migrate first and why. Open RAN against monolithic. What goes into the next refresh cycle and what cannot wait for it.
Afternoon, second block. The plan. Assemble the roadmap. Identify the decisions that need an executive, a regulator, or a vendor, and draft how you will ask for each one.
Where this sits in your path
Quantum-Safe Telecommunications is the prerequisite in substance rather than in rule. It covers the same ground at overview depth, and participants who arrive having taken it start the day with the vocabulary already shared. Afterward, Cryptographic Discovery, Inventory, and CBOM for the teams about to run discovery, and PKI Modernization for Post-Quantum for whoever owns certificate infrastructure.
Why we teach this
The day is built on the Telecommunications Extension of the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org. The instructors run migration programs in this sector, and that is where the constraints in this material come from.