Skip to content

Education

PQC migration phases: discover, prioritize, hybrid, verify

Post-quantum migration is a program, not a project. These four phases align to federal guidance and mid-market execution reality.

PQC migration phases stack diagram.
How to Build Your 12-Month Post-Quantum Strategy With NIST's Dustin Moody Watch on YouTube

Phase 1 — Discover

  • Automated cryptographic inventory across TLS, certs, keys, libraries
  • CycloneDX CBOM export with algorithm tags
  • Mosca HNDL scoring by data class

References: NIST IR 8547, CISA factsheet

Phase 2 — Prioritize

  • Map findings to NSM-10 and CNSA 2.0 tiers
  • Sort by data shelf-life × exposure vector
  • Assign owners and deadline tier per asset

Dustin Moody's embedded interview stresses that large organizations need multi-year runway — start Phase 1 now.

Phase 3 — Hybrid deploy

  • ML-KEM hybrid TLS on highest-priority endpoints
  • Pilot signature migration on non-critical chains first
  • Coordinate vendor upgrades (LB, CDN, HSM, SaaS)

See hybrid TLS migration guide.

Phase 4 — Verify

  • Re-scan after remediation; diff drift
  • Signed reports + public verify links
  • Attach evidence to GRC workflows — inventory aid, not formal attestation

This quarter

Complete Phase 1 with external baseline + CBOM export. Schedule Phase 2 prioritization workshop with legal retention inputs.

Continue on the Q-Day hub: PQC deadlines guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.