Implementation

    Testing, acceptance and rollback

    Each production migration needs a risk-appropriate test and acceptance plan covering interoperability, actual algorithm negotiation, authentication and trust validation, invalid inputs, downgrade, size and fragmentation, resource exhaustion, performance, backup, failover and rollback. Acceptance requires approval by engineering and the service owner, an observation period, and evidence that production uses the new configuration with legacy paths removed or excepted. G80 is a separate, narrower agility proof.

    New to this? Read Crypto agility: definition and practical demonstration first. After this, continue with What G80 means and how to satisfy it.

    In one sentence: A migration is complete only when tested, accepted in production and cleaned of legacy paths.

    Why it matters

    Post-quantum changes alter key and signature sizes, negotiation and trust chains. Problems often appear only with real counterparties, intermediaries or failover, so a lab test alone can overstate readiness.

    Illustrative example: a migrated VPN passes functional tests but fails during failover because the standby node holds the old profile. Acceptance is withheld until failover and rollback are tested.

    What the test plan covers

    Omitted categories need a documented technical non-applicability rationale, and environments must represent the affected critical pathway.

    Clause 4.7 test categories
    AreaCategories (QCI-4.7-01)
    InteroperabilityEnd-to-end interoperability; actual algorithm negotiation
    TrustAuthentication and trust validation
    Failure handlingInvalid key, ciphertext and signature inputs; downgrade and fallback; resource exhaustion
    PerformanceMessage and certificate size and fragmentation where relevant; capacity and latency
    ResilienceBackup and restore; failover; authorized rollback

    Operational acceptance

    • Engineering and the accountable service owner approve results, failure dispositions, monitoring, support readiness, recovery procedures and residual exceptions (QCI-4.7-02).
    • An observation period proportionate to the change (QCI-4.7-02).
    • Evidence of effective production configuration (QCI-4.7-02).
    • Removal or explicit exception of legacy paths, and disposition of obsolete keys, certificates and configurations (QCI-4.7-02).
    • Trust-chain changes include roots, trust-store distribution, revocation, offline verifiers and update verification (QCI-4.6-02).

    Rollback

    Rollback must be tested and authorized. A rollback that restores vulnerable protection is governed as an exception (QCI-4.7-02), with an owner, expiry and review triggers under Clause 4.3.

    How this relates to the G80 gate

    Migration testing applies to every production migration and decides whether that change is accepted. G80 asks whether at least one critical trust pathway has passed a representative end-to-end crypto-agility test under Clause 4.7 within the previous 12 months, with the pathway and test limits disclosed (QCI-6.3-01).

    The two share the Clause 4.7 categories, but a passed migration test does not by itself satisfy G80, and one G80 proof does not show enterprise readiness. The standard's informative guidance calls the minimum G80 proof deliberately narrower than the representative testing needed for P4 levels 4 and 5.

    What organizations should do

    1. Write the test and acceptance plan before the change, covering every Clause 4.7 category or justifying omissions.
    2. Test with representative counterparties, intermediaries and failover paths.
    3. Define the observation period in proportion to criticality.
    4. Test and authorize rollback; govern any vulnerable rollback as an exception.
    5. Close the change only with evidence of production configuration and legacy-path disposition.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Test and acceptance plan with resultsEach production migrationEngineeringBefore acceptanceCheck every category is tested or justifiedQCI requirement (QCI-4.7-01)
    Acceptance approvalEach production migrationEngineering and accountable service ownerAt acceptanceConfirm approvals, observation period and residual exceptionsQCI requirement (QCI-4.7-02)
    Legacy path and key disposition recordMigrated pathwayService ownerAt completionInspect production configurationQCI requirement (QCI-4.7-02)
    Rollback exception (if used)Rolled-back changeCompetent approving authorityUntil expiryCheck Clause 4.3 fieldsQCI requirement (QCI-4.3-02)

    How NIST or other primary authorities address it

    QCI-QS1 Annex E lists NIST SP 1800-38, Migration to Post-Quantum Cryptography, as informative implementation support whose preliminary draft materials include interoperability and performance testing; it is not a final mandatory baseline. Protocol specifications define what correct negotiation and encoding look like for each protocol.

    How QCI-QS1 addresses it

    Clause 4.7 sets the test and acceptance requirements. Clause 6.2 defines completion, and Clause 6.3 uses a Clause 4.7 test for the G80 gate.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-4.7-014.7explicit requirementP4G80
    QCI-4.7-024.7explicit requirementP4—
    QCI-4.6-024.6explicit requirementP4—
    QCI-6.2-026.2explicit requirementP4—
    QCI-6.3-016.3explanatory context—G80

    Common mistakes

    • Counting a pilot or vendor release as production migration (QCI-4.7-02).
    • Skipping failover and rollback tests.
    • Leaving legacy paths enabled without an exception.
    • Presenting one passed migration test as the G80 proof or as enterprise readiness.

    Questions for the board

    • How many migrations were accepted this quarter, and how many rollbacks are open as exceptions?

    Questions

    Is a successful pilot a completed migration?

    No. A pilot or vendor release alone does not count as production migration (QCI-4.7-02).

    Does passing a migration test satisfy G80?

    Not by itself. G80 needs a representative end-to-end crypto-agility test on a critical trust pathway within the previous 12 months, with pathway and limits disclosed (QCI-6.3-01).

    Can we roll back to classical cryptography?

    Yes, if rollback is authorized and tested, but a rollback that restores vulnerable protection is governed as an exception (QCI-4.7-02).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Test and acceptance.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.6. Supports: Trust migration.
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clauses 6.2–6.3. Supports: Completion and G80.
    4. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex E (informative). Supports: SP 1800-38 status.

    Back to Migration and crypto agility · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). Testing, acceptance and rollback. https://quantumcoreinstitute.com/learn/migration/pqc-migration-testing

    Link: https://quantumcoreinstitute.com/learn/migration/pqc-migration-testing