The Applied Quantum PQC Migration Framework is an open-access, practitioner-grounded methodology for planning and executing enterprise-wide post-quantum cryptography migration. Built from real programs, not theory, it provides the complete lifecycle from securing executive mandate through sustained crypto-agility, with sector-specific extensions for the industries facing the greatest complexity.
Licensed under CC BY 4.0. Free to use, adapt, and share, including for commercial purposes, with attribution to Marin Ivezic and Applied Quantum.
THE APPLIED QUANTUM PQC MIGRATION FRAMEWORK
The Applied Quantum
PQC Migration Framework & Methodology
An open-access, practitioner-grounded methodology covering the complete 8-phase PQC migration lifecycle, from securing executive mandate and building cryptographic inventories through CBOM documentation, risk-prioritized roadmaps, hybrid pilots, infrastructure modernization, and vendor governance.
Version 3.0 is a major version. It makes crypto-agility the program’s method and its measured result. Your first algorithm change is the migration itself. The program closes when you can make the second one on a date you choose.
Framework Extensions
All six publish at v3.0 with the Universal Framework. Each one adds the challenges and phase adaptations specific to its sector. Use them alongside the Universal edition, not in place of it.
Financial Services
Banking, capital markets, and insurance. Covers HNDL urgency on cross-border flows, HSM migration constraints, regulatory alignment (PCI DSS 12.3.3, DORA, FINMA, HKMA), and 20 industry-specific challenges with phase-by-phase adaptations. Version 3.0 adds crypto-agility guidance for banks. You set the date on your own edge, issuers and signing services. Where a scheme or a core vendor sets it instead, the extension says what to record.
Payments
Card networks, RTGS, SWIFT, payment HSMs, and terminal infrastructure. Anchored by BIS Project Leap Phase 2 findings, covering 10 payment-specific challenges including PCI standards, real-time payment systems, and ATM network security. Version 3.0 adds crypto-agility guidance for payment estates. You rehearse an algorithm change on your gateways, signing pipelines and HSMs. Schemes and terminal fleets set the remaining dates.
Digital Assets
Blockchain, cryptocurrency, DeFi, and tokenized assets. Covers on-chain public key exposure, consensus-level migration, smart contract dependencies, PoS validator risk, ZK proof vulnerabilities, and exchange and custodial infrastructure. Version 3.0 adds crypto-agility guidance for exchanges and custodians. You change algorithms on your own stack and APIs. On-chain keys depend on each chain’s own protocol change.
Telecommunications
Guidance for mobile operators, fixed-line carriers, and converged network providers – covering 5G-AKA, roaming interfaces, the 6G standardization window, GSMA PQ.01–PQ.07 alignment, lawful intercept, vendor concentration, and 3GPP dependencies. Version 3.0 adds crypto-agility guidance for operator estates. You change algorithms on the layers you control. Standards bodies and roaming partners set the dates on the interfaces you share.
OT & CNI
Adaptations for energy, utilities, water, transportation, and other critical infrastructure – addressing 15–25 year equipment lifecycles, safety-case recertification, ICS/SCADA constraints, process historian data, and gateway-based PQC deployment. Version 3.0 adds a cryptographic ownership register and a gateway encapsulation pattern for equipment that cannot carry PQC itself. It scopes the facilities estate for discovery and supplies a PQC tender template for OT procurement.
Government & Defense
Framework adaptations for federal agencies, defense departments, intelligence organizations, and defense industrial base contractors – covering CNSA 2.0 and CNSSP 15, the January 1, 2027 acquisition gate, and classified system migration. Version 3.0 rebuilds the regulatory content on two mandate chains agencies now run at once. CNSA 2.0 through CNSSP 15 binds national security systems. Executive Order 14412 and OMB M-26-15 bind civilian agencies. The extension also records the CMMC Phase 2 suspension.
8-Phase Lifecycle with Cross-Cutting Foundations
The framework organizes PQC migration into eight phases — from establishing the executive mandate through continuous vendor governance — supported by five foundational capabilities that run across the entire program. Earlier phases cascade into later ones, while Phases 5 and 6 run iteratively in parallel and Phase 7 operates continuously from day one.
Vendor & Supply Chain Governance
Metrics & KPIs
Crypto-Agility
Regulatory Mapping
Skills & Teams
90-Day Quick Start
You don’t need to complete the full framework to begin. The first 90 days establish the foundation that every subsequent phase builds on.
The Applied Quantum PQC Migration Framework was first drafted in March 2023, tested through real migration programs over two years, and first published in full in June 2025. It is the first published PQC migration methodology that covers the complete lifecycle at operational depth in a single integrated framework, from executive mandate and cost estimation through cryptographic discovery, CBOM documentation, risk prioritization, program governance, hybrid deployment, PKI architecture evolution, infrastructure performance analysis, vendor supply chain management, and operational security integration. Before the release of the version 1.1, a comprehensive survey of 80+ published PQC frameworks found that no other single framework covers this full scope; its own conclusion states that organizations must combine four or five separate frameworks to assemble what this one provides.
Beyond its scope, the framework introduced original concepts that did not exist in any prior PQC migration guidance, including the Minimum Viable CBOM, Law on Crypto-Agility, the TNFL (Trust Now, Forge Later) framing, risk-driven discovery scoping, cost estimation methodology, the Two-Track Migration Model, Deployment Environment Classification, SOC detection specifications and incident response playbooks for quantum threats, a cascading KRI framework for PQC governance, crypto-agility as a five-dimensional operational discipline, and sector-specific extensions across six industries (Financial Services, Payments, Telecommunications, Government & Defense, Critical National Infrastructure/OT, and Digital Assets). A full list with supporting survey evidence is published on the license page.
The framework is published under CC BY 4.0 because PQC migration is too important to lock behind paywalls or proprietary restrictions. Anyone can use, adapt, and build on this work, including for commercial purposes, provided they credit Marin Ivezic and Applied Quantum and do not restrict others from doing the same.
If you encounter a PQC migration framework from a consulting firm that covers the same ground, uses very similar concepts, or follows a similar structure, check whether it credits this source. If it does, they are using the framework as intended. If it does not, ask them why.
Resources & Related Projects
The framework is part of a broader ecosystem of open frameworks, publications, training, and services focused on helping organizations navigate the quantum transition.
The Cryptographic Concentration Framework. A second-line risk instrument that measures cryptographic concentration beneath the vendor layer. Phases 3 and 7 of this framework cross-reference it and never recompute it. By Steve Vaile and Marin Ivezic, open under CC BY 4.0.
The Applied Quantum CBOM Profile. A property taxonomy layered on CycloneDX. Phase 2 of this framework cites it by minimum version, as optional machine-readable carriage for a cryptographic inventory. By Steve Vaile and Marin Ivezic, open under CC BY 4.0.
A practitioner newsletter tracking regulatory developments, cryptographic research, and vendor readiness changes that affect PQC migration programs. Every issue applies one filter: does this change how organizations plan, execute, or govern their migration?
Marin’s personal blog on quantum security with over 1 million monthly readers. In-depth practitioner analysis covering PQC migration, cryptographic inventory, CBOM, hybrid deployment, vendor governance, and sector deep dives.
The practitioner’s complete guide to PQC migration, the book companion to this framework. A step-by-step roadmap for CISOs, security architects, and program managers leading the transition to quantum-safe cryptography.
Strategic leadership in the quantum era, the companion book for policymakers, executives, and board directors. Covers the geopolitical, economic, and national security dimensions of quantum technology.
Live and online trainings and certifications on the topics this framework covers, matched to the roles and training levels in its Skills & Team Structure section. Founded and taught by Marin Ivezic.
Research-driven professional services firm focused entirely on quantum technologies, from quantum computing and systems integration to strategy, sovereignty advisory, and quantum-safe security across all sectors.
Applied Quantum’s security-focused practice. Hands-on services including PQC readiness assessments, cryptographic inventory and CBOM, crypto-agility consulting, hybrid implementation, quantum risk assessment, and regulatory advisory.

