Governance & Policy / KPI Dashboard Builder

What this is for: Build KPI dashboards for tracking PQC migration metrics and progress.

What a good answer looks like: Three to five measures that would move if the programme stalled. Anything that stays flat either way is reporting, not measurement.

Worked example: Choose the Executive lens, drag Systems Inventoried down to 40 and leave Vendor Readiness auto-scored from your Migrate catalog: the Overall Score becomes the weighted average, and the export lists each KPI's score, weight and target.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Switch View as to Executive: the overall score and the KPIs such as Algorithms Migrated and Budget Utilization are the three to five measures that would move if the programme stalled.
GRC / Risk & Compliance
Enter the scores you can evidence, Customise Weights to your framework's priorities, and note which KPIs need assessment or compliance data to unlock; How this score is computed is the method to cite with the .csv export.
5 of 13 KPIs — 47% of weight — need assessment or compliance data to unlock. Complete the linked step on each locked KPI below to bring it into the score.

Adjust KPI sliders to reflect your organization's PQC migration progress. Vendor Readiness and threat-scoped KPIs auto-populate from the catalog, industry threats, and your assessment; weights adapt to the selected persona lens.

View as:

PQC Governance KPIs — Overall Score

23

/100

Weighted scorecard — executive lens.

Weights sum to 20% — overall score auto-normalises.

Systems Inventoried

Percentage of systems scanned for cryptographic usage (CBOM coverage).

Not yet scored(7%)

Algorithms Migrated

Percentage of quantum-vulnerable algorithms replaced with PQC or hybrid alternatives.

Not yet scored(10%)

Vendor Readiness

Tiered PQC-ready share of the product catalog (Full=1.0, Hybrid=0.7, Pilot=0.4, Roadmap=0.2, None=0).

64(7%)

FIPS-Validated Deployment

Percentage of catalog products with FIPS 140-2/3 validation certificates.

9(3%)

Compliance Gaps Closed

(13%)

Select compliance frameworks in the assessment to enable auto-scoring.

Regulatory Exposure Index

(7%)

Select compliance frameworks in the assessment to compute regulatory exposure.

Pace-to-Deadline

(10%)

Select a country with a mandatory PQC deadline in the assessment to enable pacing.

Crown-Jewel Coverage

Percentage of classified / highest-sensitivity data flows already behind PQC (hybrid or full). Set manually today — will auto-populate once the assessment wizard captures a crown-jewel scope.

Not yet scored(7%)

Threat Exposure

Inverse of critical + high industry-scoped threats (higher = lower exposure).

0(10%)

HNDL Time Horizon

(7%)

Complete the risk assessment to compute HNDL horizon.

Board-Ready NIST CSF Composite

(10%)

Complete the risk assessment at /assess to compute the board composite.

Complete assessment →

Training Completion

Percentage of relevant staff who have completed PQC awareness and technical training.

Not yet scored(3%)

Budget Utilization

Percentage of allocated PQC migration budget spent on plan (target range: 70–90%).

Not yet scored(7%)

PQC Governance KPIs — Export

Export the scorecard above as a shareable document.

Try it

Why do some KPIs show as needing assessment or compliance data?

Next step

Next in Governance & Policy: Program Charter

Program Charter is the next Governance & Policy tool in the Command Center.