Migration Planning / Refresh-Cycle Alignment
§4What this is for: Phase 4 Activity 4.3 — maps PQC migration tasks onto already-funded infrastructure refresh programs (data center, SD-WAN, cloud, PKI, HSM, vendor renewals) so PQC work rides existing budgets.
What a good answer looks like: The assets whose refresh lands AFTER your deadline are named. Those need a decision now, not later.
Worked example: Keep the 3-year horizon, give 'HSM replacement' a next refresh of 2027 and 'Data center hardware' 2031: the first badge reads On budget, the second After horizon, and the banner counts how many of the seven programs need separate PQC spend.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Set the planning horizon and list the refresh programmes with their years: the assets whose refresh lands after the deadline are named, and those need a decision now rather than later.
- GRC / Risk & Compliance
- Add each funded refresh programme (data centre, SD-WAN, cloud, PKI, HSM, vendor renewals) with its year and the PQC task that rides it: the export shows which migration work has a budget line and which does not.
Refresh-Cycle Alignment
Phase 4 — Roadmap & Governance (Activity 4.3) §4. Map PQC migration tasks onto your already-funded infrastructure refresh programs so the work rides existing budgets.
NIST CSWP 39-upd1 §5 names this directly, listing among a crypto-agility strategic plan's key activities the “time, cost, and ease to migrate and mitigate in accordance with technology refresh cycles.” Read §5. Refresh intervals themselves are yours to enter — they vary too much by asset class and vendor for this tool to assert a norm.
Planning horizon
Refresh programs · 7 programs
For each already-funded refresh program, record the next scheduled refresh and the concrete PQC task to embed into it.
Refresh-Cycle Alignment — Export
Save this alignment to your Command Center, or export as markdown / PDF / Word. This is the Phase-4 Activity 4.3 cost-avoidance artifact.
- NIST CMVP — Cryptographic Module Validation
- NIST ACVP — Automated Crypto Validation Protocol
- NIST FIPS 203 — ML-KEM
- NIST FIPS 204 — ML-DSA
- NIST FIPS 205 — SLH-DSA
- Carnegie Mellon CyLab (Americas)
- UC Berkeley BQIC (Americas)
- Ruhr University Bochum Cryptography (EMEA)
- Max Planck Institute Security and Privacy (EMEA)
- Brno University of Technology (EMEA)
- Duke University Quantum Center (Americas)
Try it
Which assets does the tool say need a decision now?
Next step
Next in Migration Planning: Data-at-Rest StrategyData-at-Rest Strategy is the next Migration Planning tool in the Command Center.