The Applied Quantum PQC Migration Framework is an open-access, practitioner-grounded methodology for planning and executing enterprise-wide post-quantum cryptography migration. Built from real programs, not theory, it provides the complete lifecycle from securing executive mandate through sustained crypto-agility, with sector-specific extensions for the industries facing the greatest complexity.

Licensed under CC BY 4.0. Free to use, adapt, and share, including for commercial purposes, with attribution to Marin Ivezic and Applied Quantum.

THE APPLIED QUANTUM PQC MIGRATION FRAMEWORK


Universal Framework

The Applied Quantum
PQC Migration Framework & Methodology

An open-access, practitioner-grounded methodology covering the complete 8-phase PQC migration lifecycle, from securing executive mandate and building cryptographic inventories through CBOM documentation, risk-prioritized roadmaps, hybrid pilots, infrastructure modernization, and vendor governance.

Version 3.0 is a major version. It makes crypto-agility the program’s method and its measured result. Your first algorithm change is the migration itself. The program closes when you can make the second one on a date you choose.

Version 3.0 · September 2026 · Marin Ivezic / Applied Quantum · CC BY 4.0

Sector-Specific Guidance

Framework Extensions

All six publish at v3.0 with the Universal Framework. Each one adds the challenges and phase adaptations specific to its sector. Use them alongside the Universal edition, not in place of it.


Financial Services Extension v3.0

Sector Extension · v3.0

Financial Services

Banking, capital markets, and insurance. Covers HNDL urgency on cross-border flows, HSM migration constraints, regulatory alignment (PCI DSS 12.3.3, DORA, FINMA, HKMA), and 20 industry-specific challenges with phase-by-phase adaptations. Version 3.0 adds crypto-agility guidance for banks. You set the date on your own edge, issuers and signing services. Where a scheme or a core vendor sets it instead, the extension says what to record.

Download PDF →


Payments Extension v3.0

Sector Extension · v3.0

Payments

Card networks, RTGS, SWIFT, payment HSMs, and terminal infrastructure. Anchored by BIS Project Leap Phase 2 findings, covering 10 payment-specific challenges including PCI standards, real-time payment systems, and ATM network security. Version 3.0 adds crypto-agility guidance for payment estates. You rehearse an algorithm change on your gateways, signing pipelines and HSMs. Schemes and terminal fleets set the remaining dates.

Download PDF →


Digital Assets Extension v3.0

Sector Extension · v3.0

Digital Assets

Blockchain, cryptocurrency, DeFi, and tokenized assets. Covers on-chain public key exposure, consensus-level migration, smart contract dependencies, PoS validator risk, ZK proof vulnerabilities, and exchange and custodial infrastructure. Version 3.0 adds crypto-agility guidance for exchanges and custodians. You change algorithms on your own stack and APIs. On-chain keys depend on each chain’s own protocol change.

Download PDF →


Telecommunications Extension v3.0

Sector Extension · v3.0

Telecommunications

Guidance for mobile operators, fixed-line carriers, and converged network providers – covering 5G-AKA, roaming interfaces, the 6G standardization window, GSMA PQ.01–PQ.07 alignment, lawful intercept, vendor concentration, and 3GPP dependencies. Version 3.0 adds crypto-agility guidance for operator estates. You change algorithms on the layers you control. Standards bodies and roaming partners set the dates on the interfaces you share.

Download PDF →


OT and Critical National Infrastructure Extension v3.0

Sector Extension · v3.0

OT & CNI

Adaptations for energy, utilities, water, transportation, and other critical infrastructure – addressing 15–25 year equipment lifecycles, safety-case recertification, ICS/SCADA constraints, process historian data, and gateway-based PQC deployment. Version 3.0 adds a cryptographic ownership register and a gateway encapsulation pattern for equipment that cannot carry PQC itself. It scopes the facilities estate for discovery and supplies a PQC tender template for OT procurement.

Download PDF →


Government and Defense Extension v3.0

Sector Extension · v3.0

Government & Defense

Framework adaptations for federal agencies, defense departments, intelligence organizations, and defense industrial base contractors – covering CNSA 2.0 and CNSSP 15, the January 1, 2027 acquisition gate, and classified system migration. Version 3.0 rebuilds the regulatory content on two mandate chains agencies now run at once. CNSA 2.0 through CNSSP 15 binds national security systems. Executive Order 14412 and OMB M-26-15 bind civilian agencies. The extension also records the CMMC Phase 2 suspension.

Download PDF →

Framework Architecture

8-Phase Lifecycle with Cross-Cutting Foundations

The framework organizes PQC migration into eight phases — from establishing the executive mandate through continuous vendor governance — supported by five foundational capabilities that run across the entire program. Earlier phases cascade into later ones, while Phases 5 and 6 run iteratively in parallel and Phase 7 operates continuously from day one.

0
Executive Mandate & Business Case
budget · authority · charter
1
Discovery & Inventory
crypto inventory · asset map
2
CBOM & Documentation
MV-CBOM · queryable records

3
Risk Scoring & Prioritization
prioritized migration backlog
4
Roadmap & Governance
multi-year plan · PMO · gates

5
Pilots & Migration
6
Infrastructure & Performance

7
Vendor & Supply Chain Governance
Starts Q1 Year 1 — runs continuously as a permanent governance function

Program Foundations
Capabilities that span every phase — established early, maintained throughout
Maturity Model
Metrics & KPIs
Crypto-Agility
Regulatory Mapping
Skills & Teams

Getting Started

90-Day Quick Start

You don’t need to complete the full framework to begin. The first 90 days establish the foundation that every subsequent phase builds on.

Month 1
Mobilize
Identify executive sponsor
Draft initial business case
Map regulatory obligations
Identify top 20 critical systems
Identify top 10 vendor dependencies

Month 2
Discover
Deploy cryptographic discovery on 3–5 highest-priority systems
Begin Tier-1 vendor outreach
Start building initial CBOM
Assess PKI root CA landscape
Launch team training program

Month 3
Plan
Complete initial scoping assessment
Present findings and business case to board / risk committee
Secure multi-year budget
Establish SteerCo and governance
Define Year 1 roadmap
Provenance

The Applied Quantum PQC Migration Framework was first drafted in March 2023, tested through real migration programs over two years, and first published in full in June 2025. It is the first published PQC migration methodology that covers the complete lifecycle at operational depth in a single integrated framework, from executive mandate and cost estimation through cryptographic discovery, CBOM documentation, risk prioritization, program governance, hybrid deployment, PKI architecture evolution, infrastructure performance analysis, vendor supply chain management, and operational security integration. Before the release of the version 1.1, a comprehensive survey of 80+ published PQC frameworks found that no other single framework covers this full scope; its own conclusion states that organizations must combine four or five separate frameworks to assemble what this one provides.

Beyond its scope, the framework introduced original concepts that did not exist in any prior PQC migration guidance, including the Minimum Viable CBOM, Law on Crypto-Agility, the TNFL (Trust Now, Forge Later) framing, risk-driven discovery scoping, cost estimation methodology, the Two-Track Migration Model, Deployment Environment Classification, SOC detection specifications and incident response playbooks for quantum threats, a cascading KRI framework for PQC governance, crypto-agility as a five-dimensional operational discipline, and sector-specific extensions across six industries (Financial Services, Payments, Telecommunications, Government & Defense, Critical National Infrastructure/OT, and Digital Assets). A full list with supporting survey evidence is published on the license page.

The framework is published under CC BY 4.0 because PQC migration is too important to lock behind paywalls or proprietary restrictions. Anyone can use, adapt, and build on this work, including for commercial purposes, provided they credit Marin Ivezic and Applied Quantum and do not restrict others from doing the same.

If you encounter a PQC migration framework from a consulting firm that covers the same ground, uses very similar concepts, or follows a similar structure, check whether it credits this source. If it does, they are using the framework as intended. If it does not, ask them why.

Ecosystem

Resources & Related Projects

The framework is part of a broader ecosystem of open frameworks, publications, training, and services focused on helping organizations navigate the quantum transition.

CC Framework

The Cryptographic Concentration Framework. A second-line risk instrument that measures cryptographic concentration beneath the vendor layer. Phases 3 and 7 of this framework cross-reference it and never recompute it. By Steve Vaile and Marin Ivezic, open under CC BY 4.0.

ccframework.org →

CBOM Profile

The Applied Quantum CBOM Profile. A property taxonomy layered on CycloneDX. Phase 2 of this framework cites it by minimum version, as optional machine-readable carriage for a cryptographic inventory. By Steve Vaile and Marin Ivezic, open under CC BY 4.0.

cbomprofile.org →

The PQC Migration Brief

A practitioner newsletter tracking regulatory developments, cryptographic research, and vendor readiness changes that affect PQC migration programs. Every issue applies one filter: does this change how organizations plan, execute, or govern their migration?

pqcmigrationbrief.com →

PostQuantum.com

Marin’s personal blog on quantum security with over 1 million monthly readers. In-depth practitioner analysis covering PQC migration, cryptographic inventory, CBOM, hybrid deployment, vendor governance, and sector deep dives.

postquantum.com →

Quantum Ready

The practitioner’s complete guide to PQC migration, the book companion to this framework. A step-by-step roadmap for CISOs, security architects, and program managers leading the transition to quantum-safe cryptography.

quantumready.com →

Quantum Sovereignty

Strategic leadership in the quantum era, the companion book for policymakers, executives, and board directors. Covers the geopolitical, economic, and national security dimensions of quantum technology.

quantumsovereignty.org →

Quantum Academy

Live and online trainings and certifications on the topics this framework covers, matched to the roles and training levels in its Skills & Team Structure section. Founded and taught by Marin Ivezic.

quantumacademy.com →

Applied Quantum

Research-driven professional services firm focused entirely on quantum technologies, from quantum computing and systems integration to strategy, sovereignty advisory, and quantum-safe security across all sectors.

appliedquantum.com →

Secure Quantum

Applied Quantum’s security-focused practice. Hands-on services including PQC readiness assessments, cryptographic inventory and CBOM, crypto-agility consulting, hybrid implementation, quantum risk assessment, and regulatory advisory.

securequantum.com →

Stay Current