Building Your PQC Team
Staff a post-quantum migration program: the core roles, an estate-driven sizing heuristic, build/borrow/buy sourcing, the four training levels, and the Crypto Champion Program.
Why this matters: A PQC migration plan without a staffing plan is a document, not a program — the FTE math and Crypto Champion network turn 'we should migrate' into 'here's who does it, by when'.
Start here: Enter your estate size in the Team Sizing Calculator: the 1-FTE-per-500-instances heuristic turns it into a programme FTE estimate, then step 2 assigns a crypto champion per platform team.
For your role
- Executive / Business Leader
- Convert the estate size into an FTE estimate with the 1-FTE-per-500-instances heuristic, then build the Crypto Champion roster: who does the migration, by when.
- GRC / Risk & Compliance
- The Team Sizing Calculator and the champion roster with each champion's four readiness commitments are the staffing evidence behind the programme's training and ownership controls.
The Skills Challenge
migration requires a combination of skills that rarely coexists in a single team: deep cryptographic knowledge (algorithms, protocols, PKI architecture), enterprise program management at scale (governance, stakeholder management, multi-year planning), and domain-specific technical expertise (network security, application security, OT engineering, cloud architecture). The market for professionals who combine even two of these is thin.
The realistic approach is not to hire a complete team of PQC specialists. It is to build the program around a small core of cryptographic expertise, supplement it with existing enterprise security and IT staff upskilled on PQC-relevant topics, and augment with external specialists for capabilities the organization cannot develop internally in the required timeframe.
A dedicated nucleus of cryptographic expertise: program management, architecture, and PMO that exists regardless of estate size.
Most engineering capacity comes from security and IT staff you already have, trained on PQC-relevant topics.
Buy in scarce specialists (OT, strategic quantum CTI) you cannot develop in the required timeframe.
Core Roles & FTE Allocation
Seven core roles carry a PQC program. The Quantum-Readiness Program Manager (QRPM), the Cryptographic Architect, and the PMO Analyst are dedicated overhead — you staff them regardless of how large the cryptographic estate is. The remaining roles scale with the work the phases generate.
| Role | Skills Required | Source | NICE work role (v2.2.0) | Typical FTE |
|---|---|---|---|---|
| Quantum-Readiness Program Managercore | Program management; Stakeholder management; Risk governance; Basic crypto literacy; Board-level communication | Internal senior PM with PQC training | OG-WRL-014 Systems Security ManagementOG-WRL-013 Systems Authorization | 1.0 |
| Cryptographic Architectcore | Deep cryptography expertise; PKI architecture; Protocol design; PQC algorithm knowledge; Crypto-agility design patterns | Internal security architect + specialized training; rare external hire | DD-WRL-001 Cybersecurity Architecture | 0.5–1.0 |
| Security Engineers (PQC) | TLS/SSH/IPsec configuration; HSM management; Certificate lifecycle; Library evaluation; Hybrid deployment | Internal security engineers with PQC training | DD-WRL-003 Secure Software DevelopmentIO-WRL-004 Network OperationsIO-WRL-005 Systems AdministrationIO-WRL-005 Systems Administration | 2–4 |
| Application Security Lead | Code review; SAST/DAST tooling; Library management; CI/CD pipeline integration; Crypto-agility patterns | Internal AppSec team with crypto-agility focus | DD-WRL-003 Secure Software DevelopmentIO-WRL-006 Systems Security Analysis | 1.0 |
| OT Security Specialist | ICS/SCADA knowledge; OT network architecture; Safety case management; Vendor coordination | Specialized hire or external partner; very scarce | IO-WRL-004 Network OperationsIO-WRL-005 Systems Administration | 0.5–1.0 (if OT) |
| Vendor / Procurement Lead | Contract negotiation; RFP management; Vendor relationship management; SLA design | Internal procurement with PQC requirements training | OG-WRL-013 Systems AuthorizationOG-WRL-014 Systems Security Management | 0.5 |
| PMO Analystcore | KPI tracking; Reporting; Evidence dossier management; SteerCo coordination | Internal PMO or shared resource | OG-WRL-013 Systems AuthorizationIO-WRL-006 Systems Security Analysis | 0.5–1.0 |
The core badge marks the three dedicated-overhead roles — they are staffed regardless of estate size.
Role → skill-set mappings are anchored to NICE Framework Components v2.2.0 (NIST SP 800-181 Rev. 1) and NIST CSWP.39 (upd1). The role list itself and the FTE figures are this site’s own Skills & Team model, not a NIST publication.
Team Sizing
Team size depends on the cryptographic estate's complexity more than on revenue or headcount. A 50,000-employee bank with 2,000 TLS endpoints, 15 HSMs, and 200 vendor relationships needs a larger team than a 200,000-employee manufacturer with 500 TLS endpoints concentrated in one ERP platform.
Sizing heuristic: one dedicated FTE per 500 cryptographic instances in the CBOM for the first two years (discovery, CBOM, risk scoring, pilot). This drops to one per 1000 during production rollout as tooling automates repetitive tasks.
A part-time QRPM with consulting augmentation for the Cryptographic Architect role is viable.
QRPM, Cryptographic Architect, and PMO Analyst are staffed regardless of estate size.
Plan a dedicated program office with 8–12 FTEs at peak.
Try the interactive Team Sizing Calculator in the Workshop to convert your own estate size into an FTE estimate.
Build, Borrow, or Buy
Not every capability should be built in-house. The framework recommends a default sourcing model per capability, balancing lasting institutional value against scarcity and risk.
Institutional knowledge and continuity matter for multi-year programs. Acceptable to borrow for the first 6 months while identifying an internal QRPM.
This capability has lasting value beyond PQC. Use consultants to design the architecture; train internal staff to maintain it.
Internal staff understand the estate better than any external team. Acceptable to borrow for initial deployment and configuration.
PKI errors cause outages. Production CA operations require people who understand the production environment. Borrow for architecture design and migration planning.
Vendor relationships are organizational assets. Acceptable to borrow for developing questionnaire frameworks and assessment criteria.
The skill set (interpreting resource-estimation papers, tracking national quantum programs) is specialized and scarce. Contract quarterly strategic assessments from a qualified provider.
Training Approach: Four Levels
Training operates at four levels, each with a different audience, depth, and outcome. Together they take an organization from informed sponsors to hands-on practitioners and a scaled champion network.
Audience: SteerCo members, board risk committee, senior leadership
Quantum threat in business terms, regulatory deadlines, program governance responsibilities, KPI interpretation.
Outcome: Informed sponsors who can approve risk-appetite statements and budget commitments.
Audience: All workstream participants, security engineers, architects, application developers with cryptographic touchpoints
Algorithm overview (ML-KEM, ML-DSA, SLH-DSA, FN-DSA), hybrid deployment mechanics, CBOM concepts, risk-assessment methodology, crypto-agility design patterns.
Outcome: A team that can execute Phase 1–3 activities without constant expert supervision.
Audience: Security engineers and architects who configure, test, and deploy PQC
Hands-on hybrid TLS deployment, HSM PQC configuration, CBOM generation with CycloneDX, certificate-lifecycle automation, performance-testing methodology.
Outcome: Practitioners who can run pilots and production deployments.
Audience: One designated champion per platform or application team
PQC foundations training plus quarterly crypto-agility briefings; champions liaise between the PQC program and their platform team.
Outcome: Champions sign off on crypto readiness in design reviews and shepherd PQC library upgrades — scaling program reach without making every developer a cryptographer.
The Crypto Champion Program
Designate one crypto champion per platform or application team. Champions attend PQC foundations training, join quarterly crypto-agility briefings, and serve as the liaison between the PQC program and their platform team. They sign off on “crypto readiness” in design reviews for new systems and shepherd PQC library upgrades within their domain — scaling the program's reach without requiring every developer to become a cryptography specialist.
Sustaining capability: after migration, champions become a standing network analogous to security champion programs, and the QRPM role evolves into a permanent Cryptographic Governance Lead within the CISO's function.
Related Resources
Size your team from your estate and assign crypto champions across your platforms.
Related modules
Check your understanding
12 questions on Skills & Team Structure, each with its answer and the reason.
Take the quizNext step
Produce the artifact: Skills & Team PlanThis module belongs to the Foundations phase; Skills & Team Plan produces a deliverable of that phase in the Command Center.
Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.