Building the Business Case for a PQC Migration Programme

The most common reason PQC migration budgets stall is not technical complexity. It is the framing. Security teams present it as a technology project with an uncertain start date, and boards defer accordingly. The correct framing is a compliance and risk management programme with a specific regulatory deadline, a quantifiable exposure, and a cost that grows with every year of delay.

This article gives CISOs and heads of information security the structure for a three-part board case. Each leg stands independently. A regulator-only argument works in heavily regulated sectors. A data risk argument works wherever long-term data retention creates exposure. A cost-of-delay argument works for any board that has been through a Y2K-scale infrastructure remediation and does not want to repeat the experience. Together, the three arguments are difficult to dismiss without either disputing the regulatory record or claiming implausible certainty about the CRQC timeline.

The technical details of ML-KEM (FIPS 203) and lattice-based cryptography belong in the CISO's implementation brief, not the board paper. The board presentation should treat PQC migration as a capital programme with a defined scope, a cost range, and a decision gate at the end of Phase 1.

Why "We Will Deal With This When Quantum Computers Arrive" Is the Wrong Frame

The standard objection to early PQC migration is that cryptographically relevant quantum computers (CRQCs) do not yet exist. The objection is technically correct and strategically irrelevant. It fails on three counts.

First, regulatory mandates with specific calendar dates already exist. NCSC UK guidance from 2024 sets 2028 as the target date for organisations to have defined their migration goals, completed a discovery exercise of cryptographic assets, and built an initial migration plan; and 2031 as the milestone for having begun migrating the most critical cryptographic systems, with 2035 as the outer boundary for completing migration of all systems. CNSA 2.0 (September 2022) sets deployment deadlines for US National Security System owners ranging from 2030 to 2033 depending on system type. These are compliance dates, not predictions about when quantum computers will arrive.

Second, harvest-now-decrypt-later (HNDL) attacks collect encrypted data today for decryption when a CRQC becomes available. Data encrypted under RSA-2048 or ECDSA P-384 that is retained for five or more years is already at risk. The threat is not future. The data collection is current.

Third, and most practically: the migration timeline for large enterprises runs to 18 to 36 months for financial services organisations and longer for defence, critical infrastructure, and organisations with OT environments. Gartner's 2024 analysis places the cost range at $2 million to $15 million for Fortune 500 migrations. An organisation that waits until CRQC existence is confirmed before beginning migration has already lost its planning window.

The Regulatory Mandate Leg

UK and EU Obligations

UK-regulated organisations are subject to the UK Network and Information Systems (NIS) Regulations 2018 (SI 2018/506). Operators of Essential Services and relevant Digital Service Providers must implement appropriate and proportionate technical and organisational measures to manage risks to the security of network and information systems. The NCSC's Cyber Assessment Framework translates this obligation to specific cryptographic controls. The NCSC's 2024 PQC migration guidance constitutes authoritative CAF-aligned advice for NIS Regulations compliance. For a full analysis of the NCSC guidance and its migration milestones, see NCSC PQC migration guidance for UK organisations.

EU member state organisations are subject to NIS 2 (Directive 2022/2555). Article 21(2)(h) requires essential and important entities to implement "the use of cryptography and, where appropriate, encryption" as a cybersecurity risk management measure. ENISA's NIS 2 implementation guidance (2023) explicitly names PQC as a relevant cryptographic update for compliance with this obligation. UK-only organisations are not bound by NIS 2, which does not bind organisations outside EU member states. This distinction must be stated clearly in the board paper: applying the wrong regulatory reference creates compliance confusion and credibility problems.

DORA (EU Regulation 2022/2554) applies to EU-regulated financial entities. Article 9(2) requires ICT risk management frameworks to include policies and procedures for the security of data transfers and network security. EBA, ESMA, and EIOPA technical standards specify cryptographic controls. Financial entities in scope of DORA face a direct obligation to demonstrate cryptographic currency. UK financial institutions are not in DORA scope unless they provide ICT services to EU-regulated entities as a critical ICT third-party service provider under Article 31. UK financial institutions are subject to FCA and PRA operational resilience rules (PS21/3, SS1/21) instead.

US and Sector-Specific Obligations

OMB Memorandum M-23-02 (18 November 2022) required US federal agencies to submit a prioritised cryptographic inventory and migration plan by 18 May 2023. This is the documented federal precedent for PQC migration as a funded, planned programme with a specific submission deadline. Agencies receiving federal funding are affected.

NYDFS Part 500 (amended 2023) requires covered entities to maintain a cybersecurity programme that includes encryption of nonpublic information and an encryption policy that addresses current cryptographic standards. NYDFS superintendent guidance notes PQC as a required planning consideration for covered entities with long-term data retention obligations.

CNSA 2.0 (September 2022) requires US National Security System owners and operators to have ML-KEM-1024 and ML-DSA-87 deployed by specific dates: 2030 for networking equipment, and 2033 for firmware, software, and operating systems. Defence contractors subject to CMMC Level 2 and Level 3 and those operating National Security Systems are in scope.

Quantifying HNDL Exposure with Mosca's Inequality

Mosca's inequality provides a decision framework: if x plus y exceeds z, act now. Where x is the time to complete a PQC migration, y is the sensitivity lifetime of data encrypted today, and z is the estimated time before a CRQC capable of breaking current asymmetric algorithms is deployed.

The Global Risk Institute's 2024 survey places a 14 to 34 per cent probability of a CRQC capable of breaking RSA-2048 within 24 hours by the 2033 to 2035 range. This is the most rigorous publicly available expert elicitation on Q-Day probability, using structured expert elicitation methodology equivalent to that used in IPCC climate risk assessments. For a worked calculator applying the inequality to an organisation's own data categories, see the Mosca inequality calculator walkthrough.

Applying the inequality across three data categories illustrates how the framework operates:

  • Regulated personal data (GDPR and data protection obligations). Migration time x: 18 to 36 months for financial services (Gartner 2024). Data retention period y: MiFID II and PRA operational resilience requirements mean regulated financial data encrypted today may be retained until 2031 to 2033 at minimum. CRQC planning horizon z: 2033 to 2035. The inequality is satisfied or borderline. Action is indicated.
  • Intellectual property and trade secrets. Patent protection periods extend 20 years. Trade secrets have indefinite retention. The HNDL risk for IP encrypted today and retained until 2040 clearly satisfies the inequality under any reasonable CRQC estimate, including the most conservative.
  • Authentication credentials and PKI trust anchors. Root CA certificates have validity periods of 10 to 20 years. A root CA certificate issued today under RSA-2048 or ECDSA P-384 will be in operational use until 2035 to 2044. The inequality is satisfied with significant margin before any CRQC probability adjustment.

This framework should be presented as three worked examples with the organisation's own values substituted. The specific numbers matter less than the structure: show the board that the inequality is satisfied for at least two of the three categories under the conservative GRI 2024 lower-bound estimate, and they cannot reasonably argue that action is premature. For a detailed treatment of the HNDL risk calculation, see the HNDL risk assessment framework.

Cost-of-Delay Economics

Migration Cost Estimates and the Compounding Effect of Delay

Gartner's 2024 analysis estimates PQC migration costs for Fortune 500 organisations at $2 million to $15 million. Financial services organisations, with higher algorithmic complexity but a more bounded cryptographic surface than manufacturing or defence, sit toward the lower end of this range with migration timelines of 18 to 36 months. Defence and critical infrastructure with embedded systems and OT environments sit at the upper end.

These estimates apply to organisations that begin migration with adequate planning time. Emergency migration, triggered by a confirmed CRQC deployment, a regulatory enforcement action, or an incident, has historically cost three to five times the planned migration equivalent. The SHA-1 deprecation cycle in 2017 provides a relevant comparator: organisations that had deferred from early warnings to emergency response paid substantially more per cryptographic asset migrated than those that planned ahead.

The correct CapEx framing for a board: PQC migration is predominantly an OpEx programme (staff time, consulting, testing) with CapEx components for HSM replacement and network infrastructure. Structuring it as a capital programme with defined phases and deliverables (discovery and inventory, prioritisation and piloting, migration, validation) enables standard capital approval processes rather than requiring an unplanned operational expenditure request.

The Opportunity Cost of Delay

Every year of delay is a year in which newly deployed infrastructure uses deprecated algorithms. A Kubernetes cluster deployed in 2026 with ECDSA P-256 workload certificates, a Vault installation with RSA-3072 transit keys, and a SaaS integration with RSA-2048 TLS will require a full re-migration when the CRQC window arrives. The infrastructure was deployed with deprecated algorithms when the migration could have been built in from the start at marginal additional cost.

Hardware refresh cycles provide the practical opportunity. HSMs already at end-of-life, network equipment due for replacement, and cloud infrastructure replatforming projects all represent natural migration points. A PQC-capable HSM purchased at the next planned refresh cycle costs the same as a non-PQC HSM at the same procurement point. Deferring the migration to the cycle after next adds a full additional migration project on top of the hardware cost that would have been incurred anyway.

Structuring the Three-Part Board Case

The practical structure for a board paper or presentation:

  • Regulatory mandate (two to three slides). Relevant regulations by jurisdiction, specific article numbers and regulation references, deadline dates, and consequences of non-compliance: regulatory censure, GDPR and NIS enforcement, DORA supervisory action for EU financial entities, NYDFS enforcement for US-covered entities. This section should be drafted by legal and compliance, not security. The board must see it as a legal obligation, not a security team preference.
  • HNDL exposure quantification (one to two slides). Mosca's inequality applied to the organisation's top three data categories. Present as a table: data category, sensitivity lifetime, Mosca result (satisfied, borderline, or not yet triggered). This is the risk argument. It must be quantified, not qualitative.
  • Cost and timeline (two to three slides). A three-phase plan with cost ranges from Gartner benchmarks, internal resource estimate, and external advisory estimate. The cost-of-delay line as a separate risk item. Close with the specific budget approval ask and a decision gate at the end of Phase 1 before Phase 2 funding is committed.

The board presentation should not include any technical description of ML-KEM, lattice problems, or algorithm implementation details. The board's decision is: authorise Phase 1 discovery and inventory at a specific cost, with a defined deliverable, and a review gate before Phase 2. That is the ask. Everything else is context for the three legs of the case. For a companion resource on structuring quantum risk for board audiences, see quantum risk board agenda for CISOs.

Common Points of Board Resistance and How to Address Them

Boards raise predictable objections to PQC migration proposals. Having prepared responses changes the dynamic from a negotiation about urgency to a discussion about implementation sequencing:

  • "We will wait until NIST finalises standards." NIST finalised FIPS 203, 204, and 205 on 13 August 2024. Standards are final. This objection has not been valid since August 2024 and should be closed immediately in the presentation. For a concise summary of what the NIST finalisation means in practice, see NIST FIPS 203, 204, and 205: what the standards mean for your organisation.
  • "Our cloud provider will handle this." Cloud providers are migrating their infrastructure on their own timelines. They cannot migrate your application-layer cryptography, your PKI, your HSMs, or your legacy OT systems. The platform migration is their responsibility. The application layer migration is yours.
  • "The quantum computer timeline is uncertain." The regulatory deadline is not uncertain. The NCSC's 2035 boundary, CNSA's 2030 to 2033 deployment requirements, and NIS and DORA enforcement timelines are calendar events, not technology forecasts.
  • "This is a security team problem, not a board problem." A PQC migration programme at Fortune 500 scale costs $2 million to $15 million and takes 18 to 36 months. Capital allocation at that scale is a board-level decision by any standard capital governance framework.

Present This to Your Board

Quantum Security Defence works with CISOs and senior IT leaders to structure PQC migration business cases for board presentation: regulatory mapping, Mosca inequality application to organisation-specific data categories, and cost framework development using current benchmark data. Contact us to discuss a business case advisory engagement.