What migrates first and why
What migrates first depends on comparing each item's exposure, criticality, confidentiality and verification horizons, feasibility and dependencies, not on a fixed order. Items with long-lived data already exposed to capture often move early, while long-lead trust-anchor and hardware work may start in parallel. QCI-QS1 forbids postponing all signature or hardware work until key exchange is complete.
New to this? Read PQC migration roadmap, milestones and decision records first. After this, continue with Hybrid approaches and their limitations.
In one sentence: Sequence by exposure, horizon, lead time and dependency, and start long-lead work early.
Why it matters
A fixed order, such as key exchange everywhere before any signatures, can leave long-lead trust changes too late. A purely feasibility-based order migrates easy systems first and leaves the most exposed ones untouched.
See the worked example below. It is qualitative and does not produce a score.
Comparison factors
- Exposure: vulnerable protection of long-lived confidentiality, present capture, signature or trust dependencies with long verification horizons (QCI-5.3-01).
- Criticality: consequence if the system, flow or supplier fails, as classified under Clause 1.1.
- Horizons: how long data must stay confidential and how long evidence must remain verifiable, assessed separately.
- Feasibility: approved profile available, supplier support, test complexity.
- Dependencies and lead time: trust anchors, hardware, partners, end-of-support (QCI-4.2-02).
Worked qualitative example (hypothetical)
Three invented items compared on the factors above. Ratings are judgments recorded for discussion, not a formula and not a Q-Risk Score.
| Item | Exposure and horizon | Feasibility | Dependencies | Decision |
|---|---|---|---|---|
| Inter-site link carrying health records | High: long confidentiality horizon, traffic capturable now | Approved hybrid profile supported | None blocking | Migrate first |
| Firmware signing root | High: long verification horizon | Low now: HSM upgrade needed | Long supplier lead time | Start procurement now in parallel |
| Internal dashboard sessions | Low: short-lived data | High | None | Later; record rationale |
Recording the sequence
Each decision goes into the roadmap with its factors and milestone type (QCI-4.2-02). Items not yet scheduled get a decision record with owner, rationale, interim treatment and review triggers. An approved migration plan does not clear an exposure flag (QCI-5.3-01).
What organizations should do
- Make sure every candidate item has horizons and exposure flags before ranking.
- Compare items on all five factors and record the reasoning.
- Start long-lead trust and hardware items when their dependency analysis requires.
- Do not let ease of migration outrank high exposure without a recorded decision.
- Revisit the sequence when exposure, supplier status or obligations change.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Exposure flags and treatment status | Critical systems and flows | Record owner | Validated at least quarterly | Sample records for flags and horizons | QCI requirement (QCI-5.3-01) |
| Sequencing rationale in roadmap | Each prioritized item | Quantum Risk Owner | Each planning cycle | Check QCI-4.2-02 factors are recorded | QCI requirement (QCI-4.2-02) |
| Comparison worksheet | Candidate items | Steering function | Each planning cycle | Confirm ratings trace to inventory records | Editorial suggestion |
How NIST or other primary authorities address it
NIST's algorithm standards and the draft transition guidance in IR 8547 do not set a single migration order for every organization. QCI-QS1 Annex E notes that national guidance, such as NSA's CNSA 2.0 materials, discusses category-specific planning for its own scope; those dates are not a global enterprise deadline.
How QCI-QS1 addresses it
QCI-QS1 sets the decision factors and forbids a mandatory sequence that postpones signature or hardware work; it does not prescribe an order. QCI-M1 describes sequencing by exposure, lead time and dependency as method guidance.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-4.2-02 | 4.2 | explicit requirement | P4 | — |
| QCI-5.3-01 | 5.3 | explicit requirement | P3 | — |
| QCI-5.3-02 | 5.3 | supporting evidence | P3 | — |
| QCI-1.1-02 | 1.1 | supporting evidence | — | — |
Common mistakes
- Applying a fixed order to every domain.
- Ranking by ease of change alone.
- Treating an approved plan as clearing an exposure (QCI-5.3-01).
- Building an informal points formula and presenting it as a QCI score.
Questions for the board
- Which high-exposure items are not yet scheduled, and why?
Questions
Should key exchange always migrate before signatures?
No. QCI-QS1 forbids any mandatory sequence that postpones all signature or hardware work until key-exchange work is complete (QCI-4.2-02).
Is there a QCI formula for ranking items?
No. QCI-QS1 lists the factors to weigh. The Q-Risk Score measures readiness maturity and is not a prioritization formula.
Does scheduling an item reduce its exposure?
No. An approved migration plan does not clear an exposure flag; closure needs evidence of reduced exposure (QCI-5.3-01, QCI-5.3-02).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.2. Supports: Sequencing factors.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 5.3. Supports: Exposure flags and treatment.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex E (informative). Supports: Scope of national guidance.
- QCI-M1 Migration Governance Method, Quantum Core Institute, V2.0, September 23, 2026 (methodology; not required for conformance), Section 2. Supports: Sequence by exposure, lead time and dependency.
- IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards, NIST, Initial public draft, November 12, 2024. Supports: Draft transition guidance; not final.
Related learning
Before this
Elsewhere
Back to Migration and crypto agility · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What migrates first and why. https://quantumcoreinstitute.com/learn/migration/pqc-migration-prioritization
Link: https://quantumcoreinstitute.com/learn/migration/pqc-migration-prioritization