Back to DashboardExecutiveFoundationsintermediate30 min

Building Your PQC Team

Staff a post-quantum migration program: the core roles, an estate-driven sizing heuristic, build/borrow/buy sourcing, the four training levels, and the Crypto Champion Program.

Why this matters: A PQC migration plan without a staffing plan is a document, not a program — the FTE math and Crypto Champion network turn 'we should migrate' into 'here's who does it, by when'.

Start here: Enter your estate size in the Team Sizing Calculator: the 1-FTE-per-500-instances heuristic turns it into a programme FTE estimate, then step 2 assigns a crypto champion per platform team.

For your role

Executive / Business Leader
Convert the estate size into an FTE estimate with the 1-FTE-per-500-instances heuristic, then build the Crypto Champion roster: who does the migration, by when.
GRC / Risk & Compliance
The Team Sizing Calculator and the champion roster with each champion's four readiness commitments are the staffing evidence behind the programme's training and ownership controls.
Practice in the Simulation

The Skills Challenge

migration requires a combination of skills that rarely coexists in a single team: deep cryptographic knowledge (algorithms, protocols, PKI architecture), enterprise program management at scale (governance, stakeholder management, multi-year planning), and domain-specific technical expertise (network security, application security, OT engineering, cloud architecture). The market for professionals who combine even two of these is thin.

The realistic approach is not to hire a complete team of PQC specialists. It is to build the program around a small core of cryptographic expertise, supplement it with existing enterprise security and IT staff upskilled on PQC-relevant topics, and augment with external specialists for capabilities the organization cannot develop internally in the required timeframe.

Build a small core

A dedicated nucleus of cryptographic expertise: program management, architecture, and PMO that exists regardless of estate size.

Upskill existing staff

Most engineering capacity comes from security and IT staff you already have, trained on PQC-relevant topics.

Augment externally

Buy in scarce specialists (OT, strategic quantum CTI) you cannot develop in the required timeframe.

Core Roles & FTE Allocation

Seven core roles carry a PQC program. The Quantum-Readiness Program Manager (QRPM), the Cryptographic Architect, and the PMO Analyst are dedicated overhead — you staff them regardless of how large the cryptographic estate is. The remaining roles scale with the work the phases generate.

RoleSkills RequiredSourceNICE work role (v2.2.0)Typical FTE
Quantum-Readiness Program ManagercoreProgram management; Stakeholder management; Risk governance; Basic crypto literacy; Board-level communicationInternal senior PM with PQC trainingOG-WRL-014 Systems Security ManagementOG-WRL-013 Systems Authorization1.0
Cryptographic ArchitectcoreDeep cryptography expertise; PKI architecture; Protocol design; PQC algorithm knowledge; Crypto-agility design patternsInternal security architect + specialized training; rare external hireDD-WRL-001 Cybersecurity Architecture0.5–1.0
Security Engineers (PQC)TLS/SSH/IPsec configuration; HSM management; Certificate lifecycle; Library evaluation; Hybrid deploymentInternal security engineers with PQC trainingDD-WRL-003 Secure Software DevelopmentIO-WRL-004 Network OperationsIO-WRL-005 Systems AdministrationIO-WRL-005 Systems Administration2–4
Application Security LeadCode review; SAST/DAST tooling; Library management; CI/CD pipeline integration; Crypto-agility patternsInternal AppSec team with crypto-agility focusDD-WRL-003 Secure Software DevelopmentIO-WRL-006 Systems Security Analysis1.0
OT Security SpecialistICS/SCADA knowledge; OT network architecture; Safety case management; Vendor coordinationSpecialized hire or external partner; very scarceIO-WRL-004 Network OperationsIO-WRL-005 Systems Administration0.5–1.0 (if OT)
Vendor / Procurement LeadContract negotiation; RFP management; Vendor relationship management; SLA designInternal procurement with PQC requirements trainingOG-WRL-013 Systems AuthorizationOG-WRL-014 Systems Security Management0.5
PMO AnalystcoreKPI tracking; Reporting; Evidence dossier management; SteerCo coordinationInternal PMO or shared resourceOG-WRL-013 Systems AuthorizationIO-WRL-006 Systems Security Analysis0.5–1.0

The core badge marks the three dedicated-overhead roles — they are staffed regardless of estate size.

Role → skill-set mappings are anchored to NICE Framework Components v2.2.0 (NIST SP 800-181 Rev. 1) and NIST CSWP.39 (upd1). The role list itself and the FTE figures are this site’s own Skills & Team model, not a NIST publication.

Team Sizing

Team size depends on the cryptographic estate's complexity more than on revenue or headcount. A 50,000-employee bank with 2,000 TLS endpoints, 15 HSMs, and 200 vendor relationships needs a larger team than a 200,000-employee manufacturer with 500 TLS endpoints concentrated in one ERP platform.

Sizing heuristic: one dedicated FTE per 500 cryptographic instances in the CBOM for the first two years (discovery, CBOM, risk scoring, pilot). This drops to one per 1000 during production rollout as tooling automates repetitive tasks.

< 1,000 instances

A part-time QRPM with consulting augmentation for the Cryptographic Architect role is viable.

Dedicated overhead

QRPM, Cryptographic Architect, and PMO Analyst are staffed regardless of estate size.

> 10,000 instances

Plan a dedicated program office with 8–12 FTEs at peak.

Try the interactive Team Sizing Calculator in the Workshop to convert your own estate size into an FTE estimate.

Build, Borrow, or Buy

Not every capability should be built in-house. The framework recommends a default sourcing model per capability, balancing lasting institutional value against scarcity and risk.

Program managementBuild. Internal QRPM.

Institutional knowledge and continuity matter for multi-year programs. Acceptable to borrow for the first 6 months while identifying an internal QRPM.

Cryptographic architectureBuild if possible; borrow for design.

This capability has lasting value beyond PQC. Use consultants to design the architecture; train internal staff to maintain it.

Discovery and inventoryBuy the tool; run it internally.

Internal staff understand the estate better than any external team. Acceptable to borrow for initial deployment and configuration.

PKI modernizationBuild, augmented as needed.

PKI errors cause outages. Production CA operations require people who understand the production environment. Borrow for architecture design and migration planning.

Vendor governanceBuild. Internal procurement.

Vendor relationships are organizational assets. Acceptable to borrow for developing questionnaire frameworks and assessment criteria.

Strategic quantum CTIBorrow for most organizations.

The skill set (interpreting resource-estimation papers, tracking national quantum programs) is specialized and scarce. Contract quarterly strategic assessments from a qualified provider.

Training Approach: Four Levels

Training operates at four levels, each with a different audience, depth, and outcome. Together they take an organization from informed sponsors to hands-on practitioners and a scaled champion network.

1
Executive education (Half-day to one day)

Audience: SteerCo members, board risk committee, senior leadership

Quantum threat in business terms, regulatory deadlines, program governance responsibilities, KPI interpretation.

Outcome: Informed sponsors who can approve risk-appetite statements and budget commitments.

2
PQC foundations (3–5 days)

Audience: All workstream participants, security engineers, architects, application developers with cryptographic touchpoints

Algorithm overview (ML-KEM, ML-DSA, SLH-DSA, FN-DSA), hybrid deployment mechanics, CBOM concepts, risk-assessment methodology, crypto-agility design patterns.

Outcome: A team that can execute Phase 1–3 activities without constant expert supervision.

3
Deep technical (Ongoing, lab-based)

Audience: Security engineers and architects who configure, test, and deploy PQC

Hands-on hybrid TLS deployment, HSM PQC configuration, CBOM generation with CycloneDX, certificate-lifecycle automation, performance-testing methodology.

Outcome: Practitioners who can run pilots and production deployments.

4
Crypto Champion Program (Standing / quarterly briefings)

Audience: One designated champion per platform or application team

PQC foundations training plus quarterly crypto-agility briefings; champions liaise between the PQC program and their platform team.

Outcome: Champions sign off on crypto readiness in design reviews and shepherd PQC library upgrades — scaling program reach without making every developer a cryptographer.

The Crypto Champion Program

Designate one crypto champion per platform or application team. Champions attend PQC foundations training, join quarterly crypto-agility briefings, and serve as the liaison between the PQC program and their platform team. They sign off on “crypto readiness” in design reviews for new systems and shepherd PQC library upgrades within their domain — scaling the program's reach without requiring every developer to become a cryptography specialist.

Web
Mobile
Data
Infrastructure
OT
Identity

Sustaining capability: after migration, champions become a standing network analogous to security champion programs, and the QRPM role evolves into a permanent Cryptographic Governance Lead within the CISO's function.

Check your understanding

12 questions on Skills & Team Structure, each with its answer and the reason.

Take the quiz

Next step

Produce the artifact: Skills & Team Plan

This module belongs to the Foundations phase; Skills & Team Plan produces a deliverable of that phase in the Command Center.

Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.