Migration Planning / Hybrid Transition Planner
§3.2.4What this is for: Architect-facing decision tree from CSWP.39 §3.2.4 - pick traditional+PQC, PQC+PQC, pure PQC, or crypto-gateway pathway with concrete algorithm pairings.
What a good answer looks like: A stated exit from hybrid, with a trigger. Hybrid without an end date is permanent, and permanent hybrid is twice the maintenance forever.
Worked example: Leave the defaults — TLS 1.3 on X25519, key exchange only, data lifetime 5 - 15 years, deadline 2030: the preview recommends Hybrid (Traditional + PQC) with X25519MLKEM768, a hybrid target of Q4 2028 and a pure-PQC sunset of Q4 2030.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Security Architect
- Inventory the protocol, the algorithm in use, the data lifetime and the deployment maturity, set the interoperability and compliance constraints, then edit the plan narrative: the tool's decision tree from CSWP.39 §3.2.4 picks traditional+PQC, PQC+PQC, pure PQC or a gateway, and a hybrid without an exit trigger is flagged as permanent.
Hybrid Algorithm Transition Planner
Architect-facing decision tree from NIST CSWP 39 Section 3.2.4 - Hybrid Cryptographic Algorithms. Recommends a transition pathway and emits an editable migration plan.
Traditional
Today: RSA, ECDSA, ECDH - quantum-vulnerable under Shor.
Hybrid (Traditional + PQC)
Transition step: classical and PQC together while PQC confidence builds.
Pure PQC
End-state: FIPS 203 / 204 / 205 standalone, with hybrid-PQC+PQC as a sibling option.
Step 1 — Inventory
Which protocol or asset is this transition plan for?
Step 2 — Constraints
What limits your choices?
Step 3 — Plan narrative (editable)
Edit the narrative, risks, and validation steps that will appear in the exported plan.
- NIST CMVP — Cryptographic Module Validation
- NIST ACVP — Automated Crypto Validation Protocol
- NIST FIPS 203 — ML-KEM
- NIST FIPS 204 — ML-DSA
- NIST FIPS 205 — SLH-DSA
- Carnegie Mellon CyLab (Americas)
- UC Berkeley BQIC (Americas)
- Ruhr University Bochum Cryptography (EMEA)
- Max Planck Institute Security and Privacy (EMEA)
- Brno University of Technology (EMEA)
- Duke University Quantum Center (Americas)
Try it
Why does the tool flag a hybrid plan without an exit trigger?
Next step
Next in Migration Planning: MTI NegotiatorMTI Negotiator is the next Migration Planning tool in the Command Center.