Governance & Policy / Skills & Team Plan
§6.5What this is for: Foundations staffing plan — core roles + FTE from the framework role model, the 1-FTE-per-500-instances sizing heuristic, and build / borrow / buy per role.
What a good answer looks like: A plan that works with the people you have. Hiring is a dependency, not a mitigation.
Worked example: Enter the instances in scope (for example 2,400): the 1-FTE-per-500-instances heuristic sizes the core roles for years 1–2 and for production rollout, and each role gets build, borrow or buy.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Enter the instances in scope: the one-FTE-per-500-instances heuristic sizes the core roles for years one and two and for production rollout, and each role gets build, borrow or buy.
- GRC / Risk & Compliance
- Record the build, borrow or buy decision per core role and where the sizing comes from: the export is the resourcing evidence behind the training and staffing controls.
Skills & Team Plan
Foundations — size and source the migration team. Core roles and FTE come from the framework role model; the 1-FTE-per-500-then-1000-instances heuristic sizes dedicated effort against your estate.
Cryptographic instances in the CBOM (keys, certificates, library call-sites, protocol endpoints).
Program stageThe heuristic ratio tightens early in the program and loosens once migration reaches production rollout.
How this is sized: the headline is your estate divided by the framework's ratio for the stage you selected. The per-role figures in the table are that single number split across the scalable roles in proportion to the framework's own typical-FTE bands — they are one estimate distributed, not seven independent ones. The QRPM, Cryptographic Architect and PMO Analyst are shown at their fixed bands instead, because the framework treats them as dedicated overhead regardless of estate size, and they sit on top of the headline rather than inside it.
Core roles & FTE
| Role | FTE | NICE work role(s) | Build / Borrow / Buy |
|---|---|---|---|
| Quantum-Readiness Program Manager | 1.0 | Information Systems Security Manager, Risk Manager | |
| Executive Sponsor | 1.0 | Information Systems Security Manager | |
| Cryptographic Architect | 0.5–1.0 | Security Architect | |
| Security Engineers (PQC) | 2–4 | Security Developer, Network Operations Specialist, System Administrator, IAM Specialist | |
| Application Security Lead | 1.0 | Security Developer, Systems Security Analyst | |
| OT Security Specialist | 0.5–1.0 (if OT) | Network Operations Specialist, System Administrator | |
| Vendor / Procurement Lead | 0.5 | Risk Manager, Information Systems Security Manager | |
| PMO Analyst | 0.5–1.0 | Risk Manager, Systems Security Analyst |
QRPM, Cryptographic Architect, and PMO Analyst are dedicated overhead regardless of estate size. The remaining roles show the framework’s illustrative baseline bands until you enter an estate-size estimate above.
Where this sizing comes from
Sizing heuristic and role model: Applied Quantum PQC Migration Framework §5 (Team & Skills), https://pqcframework.com. One dedicated FTE per 500 cryptographic instances for the program's first two years (discovery, CBOM, risk scoring, pilot); the ratio loosens to one per 1000 once the program reaches production rollout. The Quantum-Readiness Program Manager, Cryptographic Architect, and PMO Analyst are dedicated overhead regardless of estate size.
Governance cadence: NIST CSWP 39 §5 (Strategic Plan) — https://doi.org/10.6028/NIST.CSWP.39-upd1.
Skills & Team Plan — Export
Save this plan to your Command Center, or export as markdown / PDF / Word. Roles, FTE, and the 1-per-500-then-1000 sizing all derive from the framework role model.
Try it
Enter 2,400 instances. What sizes the core roles?
Next step
Next in Governance & Policy: Accelerated Execution ProfileAccelerated Execution Profile is the next Governance & Policy tool in the Command Center.