Risk & Strategy / Cost of Inaction Analyzer
§5What this is for: Model the discounted cost of delaying PQC migration — breach exposure, HNDL residual, and regulatory penalties.
What a good answer looks like: A figure that changes a decision. If waiting and acting come out within rounding of each other, say so plainly rather than tuning the inputs until they diverge.
Worked example: Keep the horizon fixed and slide the migration delay from 0 to 3 years: the cumulative-NPV chart shows the year where waiting becomes the more expensive choice, and the breakdown shows which cost drives it.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Slide Migration delay from 0 to 3 years with the horizon fixed: the ten-year cumulative NPV chart shows the year where waiting becomes the more expensive choice, and the breakdown shows which cost drives it.
- GRC / Risk & Compliance
- The Delay cost breakdown separates accumulated exposure from delay premium; record the annual breach probability and migration duration you chose, since they carry the whole comparison.
Payment card data must stay secure for 3 years; migration takes 3. Migration should start no later than 2032 to stay protected through the median CRQC arrival year (2037.6).
Delaying 2 years permanently costs more starting 2029.
10-Year Cost Comparison (cumulative NPV)
| Year | Migrate Now | Delay 2yr | Δ Cost |
|---|---|---|---|
| 2026 | $6.5M | $2.0M | -$4.5M |
| 2027 | $8.4M | $3.9M | -$4.5M |
| 2028 | $10.1M | $10.0M | -$19K |
| 2029 | $10.4M | $11.6M | +$1.1M |
| 2030 | $10.8M | $13.0M | +$2.2M |
| 2031 | $11.1M | $13.3M | +$2.2M |
| 2032 | $11.4M | $13.6M | +$2.2M |
| 2033 | $11.7M | $13.8M | +$2.2M |
| 2034 | $11.9M | $14.1M | +$2.2M |
| 2035 | $12.1M | $14.3M | +$2.2M |
What this is telling you
Waiting 2 years costs you about $2.2M more over 10 years than starting now — not because migration gets more expensive on its own, but because you carry full exposure for longer and pay a rising premium to compress the work later. The date that actually binds you is 2032 — that is when starting later stops being a cost decision and becomes an exposure you cannot undo.
Delay 2yr — Cost Breakdown (10-year NPV)
Migration (with delay premium)
$4.5M
Base $4.5M + $900K premium, discounted
Expected breach loss
$3.6M
Full exposure while unmigrated, ramping to a residual HNDL tail (already-harvested data only) once migration completes
Regulatory exposure
$6.3M
$1.5M/yr fine (BOI Quantum Risk Directive) once unmigrated past the 2025 deadline (BOI Quantum Risk Directive).
How this is calculated
Breach loss: the same probability-weighted model as the Breach Scenario Simulator — a blend of "no CRQC exists" and "CRQC exists" outcomes. Each projected year is weighted by the probability, from the GRI 2025 survey's arrival curve, that a CRQC exists by then — not merely that one arrives in that particular year, since a machine built in 2032 is still there in 2040. HNDL exposure decays with Payment card data's 3-year shelf life, measured at the moment the data would be decrypted rather than today: that is what migrating early buys you, because a corpus frozen well before a CRQC arrives has aged out of its own shelf life by the time anyone can read it. Applied at your 9.3% annual breach probability. Defaults: 5 years of harvested data, 30% HNDL exposure.
Migrating now is not zero-risk: data harvested before you migrate stays decryptable, so a residual HNDL tail persists after migration — exposure ramps down over the 3-year migration window rather than switching off instantly, and no further data is harvested once migration begins.
Deadline: a binding requirement (BOI Quantum Risk Directive) — 2025 is derived from complianceData.ts / the timeline CSV, not hand-picked. Penalties accrue only once migration is fully complete and past a HARD deadline — a short delay that still finishes before it incurs none.
Mosca's inequality: shelf life + migration time compared against the median CRQC arrival year (2037.6, GRI 2025 consensus scenario) — the same decision rule the Breach Scenario Simulator uses.
NPV: all cash flows are discounted at 10% over 10 years, matching the ROI Calculator.
Illustrative estimates. Migration cost and delay premium are industry-analyst estimates, not cited figures. Pair with your finance model before committing capital.
Cost of Inaction — Export
Export the cost-of-inaction analysis as markdown, PDF, or DOCX. It is also saved to your Command Center Risk Artifacts.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Slide the migration delay from 0 to 3 years with the horizon fixed. What does the chart show?
Next step
Next in Risk & Strategy: Cost Model ExplorerCost Model Explorer is the next Risk & Strategy tool in the Command Center.