Skip to main content

PQC Migration Planning

Applies to:
Migration RoadmapHybrid StrategyPhased RolloutProgress Tracking

The migration model​

DuoKey structures the transition as a four-phase roadmap. Each phase has a status (Planned, In Progress, Completed, Blocked) and a progress percentage, so the overall roadmap rolls up to a single completion figure you can report.

Four-phase migration roadmap
1 · Assessment & Planning
plan
2 · Pilot Implementation
validate
3 · Hybrid Deployment
roll out
4 · Full PQC Transition

Each phase carries a status and a progress percentage that roll up to a single completion figure.

PhaseGoalTypical activities
1 · Assessment & PlanningKnow what you haveInventory all cryptographic assets, identify quantum-vulnerable systems, build the roadmap, secure budget
2 · Pilot ImplementationProve it worksDeploy PQC in a test environment, validate performance, test interoperability, train operations
3 · Hybrid DeploymentProtect without breakingRoll out hybrid (classical + PQC), enable dual-algorithm support, migrate production gradually
4 · Full PQC TransitionReach the target stateDisable quantum-vulnerable algorithms, deploy pure PQC, decommission legacy, monitor continuously

Hybrid strategy​

The recommended path is hybrid first: combine a classical algorithm with a post-quantum one so you gain quantum protection while staying compatible with peers that do not yet support PQC. A hybrid strategy specifies:

ElementMeaning
Classical algorithmThe existing algorithm kept for compatibility (e.g. X25519, RSA)
PQC algorithmThe post-quantum algorithm added (e.g. ML-KEM, ML-DSA)
Deployment orderClassical-first, PQC-first, or parallel
FallbackWhether to fall back to classical if a peer cannot negotiate PQC
Testing criteriaThe checks that must pass before promoting to production
Tip
For key exchange, X25519MLKEM768 (X25519 + ML-KEM-768) is the widely-interoperable hybrid to target on TLS 1.3.

Target algorithms​

UseTarget (NIST)Replaces
Key encapsulationML-KEM (FIPS 203)RSA / ECDH key exchange
Digital signaturesML-DSA (FIPS 204)RSA / ECDSA / EdDSA signatures
Hash-based signaturesSLH-DSA (FIPS 205)Long-lived / firmware signing
Symmetric (already safe)AES-256, SHA-384/512No change needed

From findings to a plan​

Prioritize

Sort findings by severity/priority (P0–P1 first) and by exposure (public, high-value systems first).

Pilot

Validate the chosen hybrid suites on a representative test environment.

Deploy hybrid

Enable hybrid on production endpoints as certificates rotate, with fallback on.

Complete

Once coverage is high and stable, disable the classical-only paths and decommission legacy crypto.

Tracking progress​

Re-scan regularly and watch these move in the right direction:

MetricWhat it shows
Quantum Readiness Score (QRS)Overall posture, 0–100 — should trend up
Endpoints migratedShare of endpoints negotiating hybrid / PQC
Certificate rotationRate of PQC / hybrid certificate deployment
Vulnerable assetsCount of remaining quantum-vulnerable findings — should trend down
Note
The roadmap and per-phase progress are surfaced on the Migration tab of the PQC Readiness dashboard. See Understanding Results and QRS Scoring.

Next steps​