Decision

    What determines PQC migration duration and effort

    There is no reliable industry average for how long PQC migration takes. Duration depends on how many critical systems and flows need transition, system age, protocol and library support, supplier lead times, trust-anchor and hardware changes, testing effort, maintenance windows and criticality. QCI-QS1 asks organizations to estimate effort and capacity per roadmap item and record shortfalls as delivery risks, rather than rely on a single headline figure.

    New to this? Read PQC migration roadmap, milestones and decision records first. After this, continue with What migrates first and why.

    In one sentence: Migration takes as long as your slowest dependencies and your committed capacity allow, so estimate it item by item.

    Why it matters

    A single programme-level estimate hides the items that will take longest, such as hardware replacement or supplier-dependent changes, and makes it hard to see where deadlines are at risk.

    Illustrative example: two systems use the same TLS library. One can be reconfigured in a routine window; the other runs on an appliance whose vendor has no supported release. The second item's duration is set by the supplier, not by engineering effort.

    Duration drivers

    What lengthens or shortens a migration item
    DriverLonger whenShorter when
    System age and supportEnd-of-support platform or custom cryptographySupported platform with configurable profiles
    Protocol and library supportNo approved profile available for the protocolApproved profile supported in current library
    Supplier dependencyVendor release or attestation outstandingAdequate supplier response already accepted
    Trust and hardwareRoots, HSMs or firmware must changeChange limited to software configuration
    TestingMany interoperating parties or size limitsSingle controlled pathway
    Maintenance windowsFew windows or high availability constraintsRoutine change windows available
    CriticalityExtensive acceptance and observation periodProportionate, shorter observation

    Estimation worksheet

    Use one row per roadmap item. Fill in your own figures; QCI does not publish benchmark durations.

    Estimation worksheet (fill in per item)
    FieldWhat to record
    Item and ownerSystem or flow, accountable owner
    Milestone types neededPlanning, procurement, pilot, production acceptance, retirement
    Blocking dependenciesSupplier, trust anchor, hardware, partner
    Dependency lead timeSource of the estimate (supplier commitment, contract)
    Engineering effortEstimated effort and committed capacity
    Test scopeClause 4.7 categories and parties
    Change windowsAvailable windows and constraints
    Observation periodProportionate to the change (QCI-4.7-02)
    DeadlineApplicable date from the obligations register
    GapCapacity or lead-time shortfall recorded as a delivery risk

    What organizations should do

    1. Estimate per roadmap item rather than for the programme as a whole.
    2. Use supplier commitments, not assumptions, for dependency lead times.
    3. Include the acceptance observation period in each estimate.
    4. Compare each estimate with the applicable deadline and record gaps as delivery risks (QCI-4.1-02).
    5. Re-estimate when a supplier response, test result or obligation changes.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Per-item effort and capacity estimateEach roadmap itemExecutive sponsorReviewed at least quarterlyCompare with committed capacityQCI requirement (QCI-4.1-02)
    Supplier commitments with datesSupplier-dependent itemsRelationship ownerChecked quarterlyCheck owned, dated commitments in the responseQCI requirement (QCI-7.2-03)
    Completed estimation worksheetRoadmap itemsQuantum Risk OwnerEach planning cycleSpot-check drivers against inventory recordsEditorial suggestion

    How NIST or other primary authorities address it

    NIST's standards define the target algorithms but do not estimate migration duration for organizations. QCI has not identified a primary source that publishes a reliable cross-industry duration, so this page gives no average.

    How QCI-QS1 addresses it

    QCI-QS1 requires roadmap items to carry estimated effort or cost, committed capacity and milestones, and to consider lead time and operational constraints.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-4.1-024.1explicit requirementP1—
    QCI-4.2-024.2explicit requirementP4—
    QCI-4.7-024.7supporting evidenceP4—
    QCI-7.2-037.2supporting evidenceP5—

    Common mistakes

    • Quoting a single industry figure as the plan.
    • Leaving supplier lead times out of the estimate.
    • Omitting testing and observation time.

    Questions

    How many years does PQC migration take?

    It depends on scope and dependencies. QCI does not publish an average; estimate each roadmap item from its drivers and committed capacity.

    What usually sets the longest items?

    Often supplier releases, trust-anchor changes and hardware replacement, because they depend on others' lead times. Your own inventory and supplier responses will show which items they are.

    What if the estimate misses a deadline?

    Record the shortfall as a delivery risk rather than moving the date (QCI-4.1-02), and escalate under your defined thresholds (QCI-4.3-01).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clauses 4.1–4.2. Supports: Effort, capacity, lead time.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Observation period.
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7.2. Supports: Dated supplier commitments.

    Back to Migration and crypto agility · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What determines PQC migration duration and effort. https://quantumcoreinstitute.com/learn/migration/pqc-migration-duration

    Link: https://quantumcoreinstitute.com/learn/migration/pqc-migration-duration