Risk & Strategy / Cost of Inaction Analyzer

What this is for: Model the discounted cost of delaying PQC migration — breach exposure, HNDL residual, and regulatory penalties.

What a good answer looks like: A figure that changes a decision. If waiting and acting come out within rounding of each other, say so plainly rather than tuning the inputs until they diverge.

Worked example: Keep the horizon fixed and slide the migration delay from 0 to 3 years: the cumulative-NPV chart shows the year where waiting becomes the more expensive choice, and the breakdown shows which cost drives it.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Slide Migration delay from 0 to 3 years with the horizon fixed: the ten-year cumulative NPV chart shows the year where waiting becomes the more expensive choice, and the breakdown shows which cost drives it.
GRC / Risk & Compliance
The Delay cost breakdown separates accumulated exposure from delay premium; record the annual breach probability and migration duration you chose, since they carry the whole comparison.
Industry
1 yrpast 2025 →8 yrs
1%25%
1 yr6 yrs
Migrate Now (10-yr NPV)
$12.1M
Migration + residual HNDL exposure
Delay 2yr (10-yr NPV)
$14.3M
Accumulated exposure + delay premium
Cost of Inaction
$2.2M
Extra cost from delaying 2 years
Mosca's inequality

Payment card data must stay secure for 3 years; migration takes 3. Migration should start no later than 2032 to stay protected through the median CRQC arrival year (2037.6).

Crossover year

Delaying 2 years permanently costs more starting 2029.

10-Year Cost Comparison (cumulative NPV)

YearMigrate NowDelay 2yrΔ Cost
2026$6.5M$2.0M-$4.5M
2027$8.4M$3.9M-$4.5M
2028$10.1M$10.0M-$19K
2029$10.4M$11.6M+$1.1M
2030$10.8M$13.0M+$2.2M
2031$11.1M$13.3M+$2.2M
2032$11.4M$13.6M+$2.2M
2033$11.7M$13.8M+$2.2M
2034$11.9M$14.1M+$2.2M
2035$12.1M$14.3M+$2.2M

What this is telling you

Waiting 2 years costs you about $2.2M more over 10 years than starting now — not because migration gets more expensive on its own, but because you carry full exposure for longer and pay a rising premium to compress the work later. The date that actually binds you is 2032 — that is when starting later stops being a cost decision and becomes an exposure you cannot undo.

Delay 2yr — Cost Breakdown (10-year NPV)

Migration (with delay premium)

$4.5M

Base $4.5M + $900K premium, discounted

Expected breach loss

$3.6M

Full exposure while unmigrated, ramping to a residual HNDL tail (already-harvested data only) once migration completes

Regulatory exposure

$6.3M

$1.5M/yr fine (BOI Quantum Risk Directive) once unmigrated past the 2025 deadline (BOI Quantum Risk Directive).

How this is calculated

Breach loss: the same probability-weighted model as the Breach Scenario Simulator — a blend of "no CRQC exists" and "CRQC exists" outcomes. Each projected year is weighted by the probability, from the GRI 2025 survey's arrival curve, that a CRQC exists by then — not merely that one arrives in that particular year, since a machine built in 2032 is still there in 2040. HNDL exposure decays with Payment card data's 3-year shelf life, measured at the moment the data would be decrypted rather than today: that is what migrating early buys you, because a corpus frozen well before a CRQC arrives has aged out of its own shelf life by the time anyone can read it. Applied at your 9.3% annual breach probability. Defaults: 5 years of harvested data, 30% HNDL exposure.

Migrating now is not zero-risk: data harvested before you migrate stays decryptable, so a residual HNDL tail persists after migration — exposure ramps down over the 3-year migration window rather than switching off instantly, and no further data is harvested once migration begins.

Deadline: a binding requirement (BOI Quantum Risk Directive) — 2025 is derived from complianceData.ts / the timeline CSV, not hand-picked. Penalties accrue only once migration is fully complete and past a HARD deadline — a short delay that still finishes before it incurs none.

Mosca's inequality: shelf life + migration time compared against the median CRQC arrival year (2037.6, GRI 2025 consensus scenario) — the same decision rule the Breach Scenario Simulator uses.

NPV: all cash flows are discounted at 10% over 10 years, matching the ROI Calculator.

Illustrative estimates. Migration cost and delay premium are industry-analyst estimates, not cited figures. Pair with your finance model before committing capital.

Cost of Inaction — Export

Export the cost-of-inaction analysis as markdown, PDF, or DOCX. It is also saved to your Command Center Risk Artifacts.

Try it

Slide the migration delay from 0 to 3 years with the horizon fixed. What does the chart show?

Next step

Next in Risk & Strategy: Cost Model Explorer

Cost Model Explorer is the next Risk & Strategy tool in the Command Center.