What determines PQC migration duration and effort
There is no reliable industry average for how long PQC migration takes. Duration depends on how many critical systems and flows need transition, system age, protocol and library support, supplier lead times, trust-anchor and hardware changes, testing effort, maintenance windows and criticality. QCI-QS1 asks organizations to estimate effort and capacity per roadmap item and record shortfalls as delivery risks, rather than rely on a single headline figure.
New to this? Read PQC migration roadmap, milestones and decision records first. After this, continue with What migrates first and why.
In one sentence: Migration takes as long as your slowest dependencies and your committed capacity allow, so estimate it item by item.
Why it matters
A single programme-level estimate hides the items that will take longest, such as hardware replacement or supplier-dependent changes, and makes it hard to see where deadlines are at risk.
Illustrative example: two systems use the same TLS library. One can be reconfigured in a routine window; the other runs on an appliance whose vendor has no supported release. The second item's duration is set by the supplier, not by engineering effort.
Duration drivers
| Driver | Longer when | Shorter when |
|---|---|---|
| System age and support | End-of-support platform or custom cryptography | Supported platform with configurable profiles |
| Protocol and library support | No approved profile available for the protocol | Approved profile supported in current library |
| Supplier dependency | Vendor release or attestation outstanding | Adequate supplier response already accepted |
| Trust and hardware | Roots, HSMs or firmware must change | Change limited to software configuration |
| Testing | Many interoperating parties or size limits | Single controlled pathway |
| Maintenance windows | Few windows or high availability constraints | Routine change windows available |
| Criticality | Extensive acceptance and observation period | Proportionate, shorter observation |
Estimation worksheet
Use one row per roadmap item. Fill in your own figures; QCI does not publish benchmark durations.
| Field | What to record |
|---|---|
| Item and owner | System or flow, accountable owner |
| Milestone types needed | Planning, procurement, pilot, production acceptance, retirement |
| Blocking dependencies | Supplier, trust anchor, hardware, partner |
| Dependency lead time | Source of the estimate (supplier commitment, contract) |
| Engineering effort | Estimated effort and committed capacity |
| Test scope | Clause 4.7 categories and parties |
| Change windows | Available windows and constraints |
| Observation period | Proportionate to the change (QCI-4.7-02) |
| Deadline | Applicable date from the obligations register |
| Gap | Capacity or lead-time shortfall recorded as a delivery risk |
What organizations should do
- Estimate per roadmap item rather than for the programme as a whole.
- Use supplier commitments, not assumptions, for dependency lead times.
- Include the acceptance observation period in each estimate.
- Compare each estimate with the applicable deadline and record gaps as delivery risks (QCI-4.1-02).
- Re-estimate when a supplier response, test result or obligation changes.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Per-item effort and capacity estimate | Each roadmap item | Executive sponsor | Reviewed at least quarterly | Compare with committed capacity | QCI requirement (QCI-4.1-02) |
| Supplier commitments with dates | Supplier-dependent items | Relationship owner | Checked quarterly | Check owned, dated commitments in the response | QCI requirement (QCI-7.2-03) |
| Completed estimation worksheet | Roadmap items | Quantum Risk Owner | Each planning cycle | Spot-check drivers against inventory records | Editorial suggestion |
How NIST or other primary authorities address it
NIST's standards define the target algorithms but do not estimate migration duration for organizations. QCI has not identified a primary source that publishes a reliable cross-industry duration, so this page gives no average.
How QCI-QS1 addresses it
QCI-QS1 requires roadmap items to carry estimated effort or cost, committed capacity and milestones, and to consider lead time and operational constraints.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-4.1-02 | 4.1 | explicit requirement | P1 | — |
| QCI-4.2-02 | 4.2 | explicit requirement | P4 | — |
| QCI-4.7-02 | 4.7 | supporting evidence | P4 | — |
| QCI-7.2-03 | 7.2 | supporting evidence | P5 | — |
Common mistakes
- Quoting a single industry figure as the plan.
- Leaving supplier lead times out of the estimate.
- Omitting testing and observation time.
Questions
How many years does PQC migration take?
It depends on scope and dependencies. QCI does not publish an average; estimate each roadmap item from its drivers and committed capacity.
What usually sets the longest items?
Often supplier releases, trust-anchor changes and hardware replacement, because they depend on others' lead times. Your own inventory and supplier responses will show which items they are.
What if the estimate misses a deadline?
Record the shortfall as a delivery risk rather than moving the date (QCI-4.1-02), and escalate under your defined thresholds (QCI-4.3-01).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clauses 4.1–4.2. Supports: Effort, capacity, lead time.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Observation period.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7.2. Supports: Dated supplier commitments.
Related learning
Back to Migration and crypto agility · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What determines PQC migration duration and effort. https://quantumcoreinstitute.com/learn/migration/pqc-migration-duration
Link: https://quantumcoreinstitute.com/learn/migration/pqc-migration-duration