Governance & Policy / Program Charter
§5What this is for: Phase 0 mandate artifact — sponsor sign-off, Steering Committee, QRPM appointment, governance cadence, and the multi-year budget commitment.
What a good answer looks like: A named sponsor and a stated scope boundary. The boundary matters more — a charter without one absorbs every adjacent problem.
Worked example: Name the sponsor (for example the CISO), write the purpose and the scope boundary, add the Steering Committee seats, enter a budget such as $4.5M over 3 years and tick the workstreams: the export is a one-page charter.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Name the sponsor, write the purpose and scope boundary, fill the Steering Committee seats and cadence, and enter the year-one budget and multi-year commitment: the export is the one-page charter that closes gate G0.
- GRC / Risk & Compliance
- Record the mandate sign-off date, the QRPM appointment, the governance cadence and the success criteria: these are the Phase 0 records a programme review checks first.
Program Charter
Phase 0 — Executive Mandate. Record sponsor sign-off, the SteerCo, the QRPM appointment, governance cadence, and the multi-year budget commitment.
Gate G0: Charter, budget & QRPM approved — sign-off authority: Executive Sponsor.
Aligned to NIST CSWP 39 §5 (Crypto Agility Strategic Plan — governance) and the Applied Quantum Phase 0 Executive Mandate.
Program
Purpose & scope
Executive sponsorship
Steering Committee · 5 seats
Seats are drawn from the framework core-role model so the charter stays consistent with the Skills & Team plan and the RACI Builder.
The framework's full SteerCo is broader than the role model's seats — it also includes Compliance/Legal, PKI/Identity, Infrastructure/NetSec, and Business-Unit representatives. Add them as named members when you formalize the committee.
Budget commitment
Cost-driver taxonomy (Framework Activity 0.2c): discovery & inventory tooling; cryptographic engineering labor (typically the largest line); vendor PQC licensing & upgrades; HSM/hardware refresh (firmware upgrades alone $50K–$500K+ depending on module count); PKI modernization; performance & capacity uplift; testing environments; program management overhead. Reference program economics: a large-enterprise Year 1 foundation typically runs $1.5M–$4M (varies by estate complexity); a major global telco's decade-scale program has run on the order of $300M–$500M, peaking around 50 FTEs (illustrative anchors, not a quote for your organization).
Workstreams (optional) · 0 selected
The framework's eight Phase-0 workstreams (Activity 0.3). Select the ones this charter stands up leads for now — the rest can be added as the program scales.
Program Charter — Export
Save this charter to your Command Center under the Governance zone, or export as markdown / PDF / Word. This is the Phase-0 mandate artifact (Gate G0).
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Which gate does a signed charter close?
Next step
Next in Governance & Policy: Skills & Team PlanSkills & Team Plan is the next Governance & Policy tool in the Command Center.