Migration Planning / Infrastructure Modernization Planner

What this is for: Phase 6 deliverable — consolidates the PKI modernization plan, HSM/KMS upgrade schedule, network/middlebox compatibility report, and PQC capacity plan into one infrastructure-readiness artifact.

What a good answer looks like: PQC work rides existing refresh cycles wherever it can. Hardware you were replacing anyway is the cheapest migration you will ever do.

Worked example: List your HSMs with firmware and PQC capability (for example 4× Luna 7 PQC-capable, 2× nCipher without), the protocols you tested and the per-handshake growth: the export consolidates the PKI plan, the HSM/KMS upgrade schedule, the middlebox report and the capacity plan.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
The PKI modernization, HSM and KMS upgrade schedule, middlebox report and capacity plan consolidate into one export: it is the infrastructure investment the migration needs, with hardware replacement planned two to four years out.
GRC / Risk & Compliance
Enter the CA lifetimes, the HSMs inventoried with firmware and PQC status, the protocols tested through middleboxes and the capacity impact: the export records the infrastructure controls and their dates.

Infrastructure Modernization Planner

Phase 6 — Infrastructure Modernization & Performance. Consolidate the PKI modernization plan, HSM/KMS upgrade schedule, network compatibility report, and capacity plan into one deliverable (activities 6.1–6.5).

PKI Modernization

Why these defaults: the framework's PKI modernization guidance (activity 6.1) recommends shortening root CA lifetimes from 20+ years to 10 years, intermediate CAs to 5 years, and end-entity certificates to 90–365 days — this limits Trust-Now-Forge-Later exposure on long-lived signing keys and builds the certificate-rotation discipline needed before dual-stack/PQC certificates arrive (NIST CSWP 39 §3.2.1 — Preserving Protocol Interoperability).

HSM & KMS Upgrade Schedule

Framework vendor notes (activity 6.2): Thales Luna 7.8.0+ introduced initial PQC support (ML-KEM, ML-DSA); the Luna HSM Firmware v7.9 Release: NIST-Approved PQC Algorithms (June 2025) adds further capabilities. Utimaco Quantum Protect is a new hardware variant — not a firmware upgrade for existing devices, so budget for hardware replacement if running older Utimaco models.

Network & Middleboxes · 1 protocol tested

Mark each protocol verified to complete a PQC handshake through your production network and middleboxes. Grounded in NIST CSWP 39 §3.2.1 (Preserving Protocol Interoperability).

Capacity Plan

Why these thresholds: the framework's capacity guidance (activity 6.5) expects roughly a 5–15% CPU increase for signature-heavy workloads and a 2–5× certificate-storage increase at scale. The readiness flags below trigger at ≥20% CPU impact — above that typical range, so headroom needs explicit verification — and at ≥2× storage growth — the low end of the expected range, so provisioning should already be underway.

Infrastructure Modernization Plan — Export

Save this plan to your Command Center, or export as markdown / PDF / Word. This is the single Phase-6 deliverable consolidating PKI modernization, the HSM/KMS upgrade schedule, network compatibility, and the capacity plan.

Try it

List HSMs with firmware and PQC status. Which of them need a plan beyond firmware?

Next step

Next in Migration Planning: Refresh-Cycle Alignment

Refresh-Cycle Alignment is the next Migration Planning tool in the Command Center.