Risk & Strategy / ROI Calculator
§5What this is for: Calculate migration ROI with breach avoidance, compliance savings, and payback period.
What a good answer looks like: A payback period you would defend under questioning — which means the breach-avoidance input is a number you can source, not the one that makes the case work.
Worked example: Pick the 'Average org' tier, enter your products to migrate and planning horizon, then halve the breach-probability input: if the payback period still lands inside the horizon, the case does not depend on the scary number.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Pick the SMB, Average org or Fortune-1000-class tier, enter the products to migrate, capex per product and the planning horizon: the three-year total cost against the cost of inaction is the payback figure for the board, exportable as .pdf or .docx.
- GRC / Risk & Compliance
- The Applicable Frameworks and Penalty per Incident inputs put regulatory exposure into the same figure as breach cost; keep the HNDL exposure and breach-probability inputs you used, because they are the assumptions an auditor will ask about.
Board-ready business case. Intended audience: CFO, CIO, and board. Figures are illustrative estimates; pair with your organization's finance model before seeking approval.
Total Cost (3yr)
$5.4M
Capex $3.8M + Opex $1.7M
Cost of Inaction (3yr)
$6.1M
Expected breach + compliance exposure
NPV @ 10%
-$95K
3-year ROI: +12%
Payback Period
31mo
Capex recoup from net benefit
Investment
Capex: 50 × $75K = $3.8M + Opex $563K/yr × 3yr = $5.4M total
Cross-check vs your assessment
Run the assessment to generate a second, independent cost estimate — then this panel cross-checks it against your per-product model so you never present a single unverified number.
Risk Reduction
Industry breach baseline (Other): $4.4M — IBM Cost of a Data Breach Report 2025. Quantum amplification is composed from three defensible factors below.
Default reflects the selected organization size — Cyentia IRIS 2025 anchors per organization size (Figures 6 and 7 of the report). The tiers sit close together because IRIS 2025's finding is that they have converged: small-firm risk has more than doubled since 2008 while the largest firms' has fallen. Drag the slider to override.
$4.4M × quantum amp 2.50× × 9.3% = $1.0M/year
Regulatory Exposure
5 frameworks × $2.0M × 10% incident rate = $1.0M/year
Financial Modeling
$1.5M/yr net × 3 yr, discounted @ 10% = NPV -$95K
Sensitivity — NPV impact at ±30%
Bars show NPV delta when each driver moves ±30% from its current value. Longest bars are your most material assumptions — defend them first.
Calculation Methodology
Investment: Capex (products × per-product cost) plus annual opex modeled as a % of capex. Typical ongoing opex covers HSM maintenance, key rotation, and audit — industry defaults are 10–20% of capex.
Risk reduction: Industry breach baseline (IBM Cost of a Data Breach Report 2025) × a composed quantum amplification factor × annual breach probability. The amplification factor is the sum of three defensible components — HNDL exposure (fraction of data at risk of retroactive decryption), post-CRQC attacker uplift (new capability ceiling once a CRQC exists), and detection-timeline uplift (mean time to detect will lengthen).
Regulatory exposure: Number of applicable regulatory frameworks × average penalty per incident × a 10% annual incident probability per framework.
NPV: Σ (netAnnualBenefit / (1 + WACC)^t) − capex, where netAnnualBenefit = grossAnnualBenefit − annualOpex.
Payback: capex / (netAnnualBenefit / 12). Uses annual (not horizon) benefit so payback is not understated by the horizon.
Sensitivity: Each driver is varied ±30% from its current value while all others are held constant; the resulting NPV delta indicates which assumption most moves the business case.
Qualitative factors not modeled: Operational efficiency from crypto agility, competitive advantage from early PQC adoption, customer trust.
Which costing model this is: a bottom-up parametric estimate (assets × unit cost) with deterministic ±30% sensitivity. It is one of several model families — top-down budget-percentage anchoring, probabilistic Monte-Carlo bands, and expert-elicited scenario ranges are the others. No single method is reliable for PQC under deep uncertainty, so triangulate: treat agreement across two or three independent estimates as confidence, and divergence as a prompt to revisit assumptions. See the Learn tab's “Choosing a Costing Model” section for the full comparison.
Educational estimates for planning. Pair with your finance function's discounted cash-flow model before committing capital.
PQC Migration ROI — Export
Export the ROI analysis above as markdown, PDF, or DOCX for board distribution. The artifact is also saved to your Command Center Risk Artifacts list.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Halve the Annual Breach Probability input. What tells you the case did not depend on the scary number?
Next step
Next in Risk & Strategy: Board Pitch BuilderBoard Pitch Builder is the next Risk & Strategy tool in the Command Center.