Migration Planning / Roadmap Builder

What this is for: Build a two-track migration roadmap (key-exchange/HNDL ∥ signatures-PKI/TNFL) on the 8-phase spine, with gates G0–G6 (+ G8 at closure) and milestone dependencies.

What a good answer looks like: Each phase has an exit test, not just an end date. "Done" has to be checkable by someone who was not in the room.

Worked example: Tick your country's deadline chips, keep the defaults — 'Pilot ML-KEM hybrid in TLS' (2027, Track A), 'Re-issue root / intermediate CAs (PQC)' (2030, Track B) — and add a mitigation with a sunset date: the export shows the critical path.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Track A (confidentiality, key exchange) and Track B (integrity, signatures and PKI) run in parallel on the eight-phase spine with gates G0 to G6: each phase needs an exit test, not only an end date.
GRC / Risk & Compliance
Add milestones against the regulatory dates listed for your countries and check the Mitigation Gateways: the Roadmap Export shows each gate's criterion, which is the evidence the programme review will ask for.

A PQC migration runs as two parallel tracks on the framework's phase spine, not one linear list:

  • Track A (Confidentiality / KEM) — urgent now because of Harvest-Now-Decrypt-Later (HNDL).
  • Track B (Integrity / Signatures & PKI) — not urgent today but the longest lead time, so it must start early because of Trust-Now-Forge-Later (TNFL): forged signatures only matter once a quantum computer can forge them, but replacing signing keys and trust anchors takes years.

Gates G0→G3 (mandate → inventory → CBOM → risk scoring) are a shared governance spine both tracks pass through together, producing the prioritized backlog and approved roadmap (G4) they then execute against. From there the same phase/gate structure runs independently and in parallel per track, because the two tracks don't share deadlines or dependencies once execution begins. The illustrative milestones below show one example: Track A piloting hybrid key exchange (G5) while Track B first migrates code-signing algorithms (also G5) before later re-issuing PKI root/intermediate CAs (G6) — infrastructure work that only shows up once a roadmap actually reaches that stage.

US federal deadlines below derive from Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks” (June 22, 2026): High Value Assets and high-impact federal systems transition to PQC for key establishment by December 31, 2030, and digital signatures by December 31, 2031.

Regulatory deadlines (0/65 selected)

Australia (1)

Brazil (1)

Canada (4)

Czech Republic (2)

European Union (5)

France (2)

G7 (1)

Germany (4)

Hong Kong (5)

India (2)

Israel (2)

Japan (1)

Jordan (1)

NATO (1)

Spain (1)

Sweden (1)

Thailand (1)

United Arab Emirates (1)

United States (21)

United States (CNSA) (7)

Uruguay (1)

202520272029203120332035

Program — Foundations & Gates

Mandate · inventory · governance · gates G0–G6 (+ G8 at closure)
2026
P0 · G0Executive mandate & budget approved
2026
P1 · G1Cryptographic inventory complete
2027
P2 · G2CBOM published (machine-verifiable)
depends on:Cryptographic inventory complete
2027
P3 · G3Risk scoring & QRA delivered
depends on:CBOM published (machine-verifiable)

Track A — Confidentiality (KEM / HNDL)

Key exchange & data-at-rest
2027
P5 · G5Pilot ML-KEM hybrid in TLS
depends on:Risk scoring & QRA delivered
2028
P5 · G5Migrate VPN / IPsec key exchange
depends on:Pilot ML-KEM hybrid in TLS

Track B — Integrity (Signatures / PKI / TNFL)

Code/firmware signing & PKI
2028
P5 · G5Migrate code/firmware signing to ML-DSA
depends on:Risk scoring & QRA delivered
2030
P6 · G6Re-issue root / intermediate CAs (PQC)
depends on:Migrate code/firmware signing to ML-DSA

Critical path: spans 4 years across 5 milestones (longest dependency chain — the time span is what actually constrains the timeline).

Add milestone

depends on:

Mitigation Gateways (CSWP.39 §4.6)

For assets where direct migration is blocked, document the gateway / bump-in-the-wire that mitigates the risk — every entry must carry a mandatory sunset date.

No mitigations specified.

Roadmap Export

Export your two-track migration roadmap with per-track milestones, gates, dependencies, regulatory deadlines, and mitigation gateways.

Try it

What does each phase need besides an end date?

Next step

Next in Migration Planning: Stakeholder Comms Planner

Stakeholder Comms Planner is the next Migration Planning tool in the Command Center.