Governance & Policy / RACI Builder
§5What this is for: Build RACI matrices for 10 PQC activities across 6 organizational roles.
What a good answer looks like: Exactly one Accountable per row. Two means nobody, and that is the failure this tool exists to prevent.
Worked example: Set Enterprise Architect as Accountable for Crypto Inventory and the CISO as Consulted, then try a second Accountable on the same row: the row is flagged, because two Accountables means nobody.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Read the pre-filled matrix: each PQC activity has one Accountable role and the tool flags a row with two, because two Accountables means nobody owns it.
- GRC / Risk & Compliance
- Set Accountable, Responsible and Consulted per activity, for example the Enterprise Architect as Accountable for Crypto Inventory; the RACI Matrix Export is the governance artefact the programme charter refers to.
Pre-filled from your assessment. Illustrative default Accountable / Responsible assignments for a PQC governance program. Refine per your org chart.
RACI defines how a role relates to an activity: Responsible does the work, Accountable owns the outcome and signs off (answerable if it fails), Consulted gives two-way input before the work happens, and Informed gets a one-way status update after. Exactly one role must be Accountable per activity — accountability split across two people is accountability held by no one. Click a cell to cycle through R, A, C, I, or empty.
| Activity | CISO | CTO | Enterprise Architect | Dev Lead | Compliance Officer | Procurement |
|---|---|---|---|---|---|---|
| Crypto Inventory | ||||||
| Risk Assessment | ||||||
| Vendor Assessment | ||||||
| Algorithm Selection | ||||||
| Testing & Validation | ||||||
| Deployment | ||||||
| Monitoring & Compliance | ||||||
| Training & Awareness | ||||||
| Compliance Auditing | ||||||
| Stakeholder Communications |
RACI Matrix Export
Export your RACI matrix as Markdown, PDF, or CSV.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Set two roles to Accountable on the same activity. What happens?
Next step
Next in Governance & Policy: Policy Template GeneratorPolicy Template Generator is the next Governance & Policy tool in the Command Center.