Running PQC Readiness As A Programme: Governance, Roles And Budget
Post-quantum migration spans years, teams and budget cycles. This article sets out who should own what, what a migration plan should contain and how to keep costs down.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Post-quantum migration is usually framed as a technical change, but most of the hard decisions are about ownership, money and timing. The work will run for several years, touch most systems and depend on suppliers. Without clear governance it tends to stall after the first inventory.
This article draws on the most detailed public guidance available as of October 2026, the US Office of Management and Budget’s memorandum M-26-15, along with the UK National Cyber Security Centre’s migration timelines. M-26-15 is written for US federal agencies, so treat it as one well-documented model rather than a rule for everyone.
Why It Cannot Sit Only With IT
OMB is direct on this point: migration is not solely the job of the chief information officer and chief information security officer, and every member of the leadership team carries responsibility for it.1 The NCSC makes a similar observation from a different angle, noting that migration will typically span several leadership cycles in a large organisation.2
The practical reason is that the decisions cross departments. Finance has to fund work that may not show results for years. Procurement has to write post-quantum requirements into contracts. System owners have to schedule changes into their own roadmaps. Risk owners have to decide which legacy systems can be tolerated and for how long.
Roles And Responsibilities
OMB’s Appendix B gives sample roles.1 The table below maps those roles to the main activities of a programme. The R, A, C and I letters (responsible, accountable, consulted, informed) are our own illustration of how the roles described by OMB could divide the work, not a table OMB publishes. Each activity has exactly one accountable role, which is the usual rule for this kind of grid.
| Role | Inventory | Prioritise | Fund | Procure | Implement | Accept risk |
|---|---|---|---|---|---|---|
| CIO and CISO | A | A | A | A | A | A |
| Programme office or requirement owner | I | C | I | R | I | I |
| Chief financial officer | I | C | R | C | I | C |
| Migration programme manager | R | R | C | C | C | C |
| PQC technical lead | R | C | I | C | R | C |
| Security architect | C | C | I | C | R | C |
| Application and system owners | C | C | I | C | R | R |
For US agencies part of this structure is now set by executive order. Executive Order 14412 required each agency head to name a PQC migration lead, reporting to the chief information officer and responsible for cryptographic inventory management, the prioritised migration plan and coordination across agencies, within 30 days of the order.3
In OMB’s descriptions, the CIO and CISO are accountable for prioritisation, risk acceptance and resourcing. The programme office makes sure vendor requirements include post-quantum readiness and crypto-agility. The chief financial officer works with them to get migration costs into the annual budget request. A migration lead coordinates the programme and reports to senior leadership, a technical lead oversees inventory, algorithm choice and testing, a security architect handles integration, and system owners implement the change on their own systems.1
What A Migration Plan Should Contain
OMB lists the minimum contents of an agency migration plan.1 The list works well as a checklist for any organisation:
- Governance Roles
Who owns the programme, who decides, who implements.
- Inventory Method
The methods and automated tools used to build and maintain the cryptographic inventory.
- Risk-Based Prioritisation
Which systems go first, with a justification for each.
- Timelines And Milestones
For each migration phase, including any protocol upgrades such as TLS 1.3.
- Crypto-Agile Architecture
How systems will be designed so algorithms can change again later.
- Third-Party Coordination
How suppliers, cloud providers and partners will be engaged.
- Funding And People
An estimate of the money and staff required.
- Risk Management During Migration
How the organisation stays safe while old and new cryptography run side by side.
OMB also expects the plan to be a living document that matures over time.1 Expect the first version to contain gaps, and record them openly rather than filling them with guesses.
Budgeting Without Surprises
The NCSC says the total cost of migration could be significant and that organisations should budget for preparatory work as well as for the migration itself.2 As of October 2026 we are not aware of a reliable published cost benchmark for private organisations, so the first budget will usually be an estimate built from the inventory.
Costs fall when migration rides on changes that are already planned. OMB makes the same point: it tells agencies to fold post-quantum upgrades into cloud migrations, software development lifecycles and hardware refresh cycles to keep costs down, and to flag systems that cannot support post-quantum or hybrid cryptography as priorities for replacement or retirement.1 The NCSC adds that some legacy systems may never be capable of post-quantum cryptography, and that the strategy has to account for them.2
Fitting Into Existing Frameworks
A migration programme does not need its own control framework. NIST’s NCCoE has published a draft mapping of its migration project capabilities to the NIST Cybersecurity Framework 2.0 and to the SP 800-53 control catalogue, so that post-quantum work can be tracked inside controls many organisations already use.4 OMB similarly asks agencies to build migration into existing governance, asset management and supply chain risk processes.1 Canada’s federal roadmap treats the same supporting work as part of its preparation phase, listing roles and responsibilities, financial planning, an education strategy and procurement policies among the early activities.5
The NCSC also suggests publishing a statement of intent for your migration. It signals demand to suppliers and shows customers that the threat is being managed.2
Footnotes
-
Office of Management and Budget, “Execution of the Migration to Post-Quantum Cryptography” (M-26-15), 24 June 2026. whitehouse.gov ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩ ↩2 ↩3 ↩4
-
The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026. govinfo.gov ↩
-
NIST NCCoE, CSWP 48 (initial public draft), “Mappings of Migration to PQC Project Capabilities to NIST Cybersecurity Framework 2.0 and to Security and Privacy Controls for Information Systems and Organizations”, 18 September 2025. csrc.nist.gov ↩
-
Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, effective 23 June 2025. cyber.gc.ca ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.