Testing, acceptance and rollback
Each production migration needs a risk-appropriate test and acceptance plan covering interoperability, actual algorithm negotiation, authentication and trust validation, invalid inputs, downgrade, size and fragmentation, resource exhaustion, performance, backup, failover and rollback. Acceptance requires approval by engineering and the service owner, an observation period, and evidence that production uses the new configuration with legacy paths removed or excepted. G80 is a separate, narrower agility proof.
New to this? Read Crypto agility: definition and practical demonstration first. After this, continue with What G80 means and how to satisfy it.
In one sentence: A migration is complete only when tested, accepted in production and cleaned of legacy paths.
Why it matters
Post-quantum changes alter key and signature sizes, negotiation and trust chains. Problems often appear only with real counterparties, intermediaries or failover, so a lab test alone can overstate readiness.
Illustrative example: a migrated VPN passes functional tests but fails during failover because the standby node holds the old profile. Acceptance is withheld until failover and rollback are tested.
What the test plan covers
Omitted categories need a documented technical non-applicability rationale, and environments must represent the affected critical pathway.
| Area | Categories (QCI-4.7-01) |
|---|---|
| Interoperability | End-to-end interoperability; actual algorithm negotiation |
| Trust | Authentication and trust validation |
| Failure handling | Invalid key, ciphertext and signature inputs; downgrade and fallback; resource exhaustion |
| Performance | Message and certificate size and fragmentation where relevant; capacity and latency |
| Resilience | Backup and restore; failover; authorized rollback |
Operational acceptance
- Engineering and the accountable service owner approve results, failure dispositions, monitoring, support readiness, recovery procedures and residual exceptions (QCI-4.7-02).
- An observation period proportionate to the change (QCI-4.7-02).
- Evidence of effective production configuration (QCI-4.7-02).
- Removal or explicit exception of legacy paths, and disposition of obsolete keys, certificates and configurations (QCI-4.7-02).
- Trust-chain changes include roots, trust-store distribution, revocation, offline verifiers and update verification (QCI-4.6-02).
Rollback
Rollback must be tested and authorized. A rollback that restores vulnerable protection is governed as an exception (QCI-4.7-02), with an owner, expiry and review triggers under Clause 4.3.
How this relates to the G80 gate
Migration testing applies to every production migration and decides whether that change is accepted. G80 asks whether at least one critical trust pathway has passed a representative end-to-end crypto-agility test under Clause 4.7 within the previous 12 months, with the pathway and test limits disclosed (QCI-6.3-01).
The two share the Clause 4.7 categories, but a passed migration test does not by itself satisfy G80, and one G80 proof does not show enterprise readiness. The standard's informative guidance calls the minimum G80 proof deliberately narrower than the representative testing needed for P4 levels 4 and 5.
What organizations should do
- Write the test and acceptance plan before the change, covering every Clause 4.7 category or justifying omissions.
- Test with representative counterparties, intermediaries and failover paths.
- Define the observation period in proportion to criticality.
- Test and authorize rollback; govern any vulnerable rollback as an exception.
- Close the change only with evidence of production configuration and legacy-path disposition.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Test and acceptance plan with results | Each production migration | Engineering | Before acceptance | Check every category is tested or justified | QCI requirement (QCI-4.7-01) |
| Acceptance approval | Each production migration | Engineering and accountable service owner | At acceptance | Confirm approvals, observation period and residual exceptions | QCI requirement (QCI-4.7-02) |
| Legacy path and key disposition record | Migrated pathway | Service owner | At completion | Inspect production configuration | QCI requirement (QCI-4.7-02) |
| Rollback exception (if used) | Rolled-back change | Competent approving authority | Until expiry | Check Clause 4.3 fields | QCI requirement (QCI-4.3-02) |
How NIST or other primary authorities address it
QCI-QS1 Annex E lists NIST SP 1800-38, Migration to Post-Quantum Cryptography, as informative implementation support whose preliminary draft materials include interoperability and performance testing; it is not a final mandatory baseline. Protocol specifications define what correct negotiation and encoding look like for each protocol.
How QCI-QS1 addresses it
Clause 4.7 sets the test and acceptance requirements. Clause 6.2 defines completion, and Clause 6.3 uses a Clause 4.7 test for the G80 gate.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-4.7-01 | 4.7 | explicit requirement | P4 | G80 |
| QCI-4.7-02 | 4.7 | explicit requirement | P4 | — |
| QCI-4.6-02 | 4.6 | explicit requirement | P4 | — |
| QCI-6.2-02 | 6.2 | explicit requirement | P4 | — |
| QCI-6.3-01 | 6.3 | explanatory context | — | G80 |
Common mistakes
- Counting a pilot or vendor release as production migration (QCI-4.7-02).
- Skipping failover and rollback tests.
- Leaving legacy paths enabled without an exception.
- Presenting one passed migration test as the G80 proof or as enterprise readiness.
Questions for the board
- How many migrations were accepted this quarter, and how many rollbacks are open as exceptions?
Questions
Is a successful pilot a completed migration?
No. A pilot or vendor release alone does not count as production migration (QCI-4.7-02).
Does passing a migration test satisfy G80?
Not by itself. G80 needs a representative end-to-end crypto-agility test on a critical trust pathway within the previous 12 months, with pathway and limits disclosed (QCI-6.3-01).
Can we roll back to classical cryptography?
Yes, if rollback is authorized and tested, but a rollback that restores vulnerable protection is governed as an exception (QCI-4.7-02).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Test and acceptance.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.6. Supports: Trust migration.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clauses 6.2–6.3. Supports: Completion and G80.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex E (informative). Supports: SP 1800-38 status.
Related learning
Before this
Back to Migration and crypto agility · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). Testing, acceptance and rollback. https://quantumcoreinstitute.com/learn/migration/pqc-migration-testing
Link: https://quantumcoreinstitute.com/learn/migration/pqc-migration-testing