Build a cryptographic inventory recording algorithms, key lengths and certificate authorities in use across the estate.
Post-Quantum Cryptography Migration Planning for Enterprise Systems
Plan an enterprise migration to post-quantum cryptography, from cryptographic asset inventory through hybrid key exchange to certificate and PKI transition.
Course Overview
A sufficiently capable quantum computer would break the cryptography that currently protects most enterprise data in transit and at rest, and adversaries are already harvesting encrypted traffic today to decrypt once that capability arrives. Migrating an enterprise's cryptography is not a single upgrade but a multi-year programme that touches certificates, protocols, hardware and every application that calls a cryptographic library. This course teaches participants to build a cryptographic inventory recording which algorithms, key lengths and certificate authorities are in use across the estate, and to assess which systems carry the highest harvest-now-decrypt-later risk. Participants plan adoption of standardised post-quantum algorithms for key encapsulation and digital signatures, and design a hybrid transition combining classical and post-quantum algorithms so systems remain interoperable during migration. Sessions cover certificate authority transition planning, updating transport security configurations for hybrid key exchange, and assessing hardware security module support for new algorithm families. A case exercise works through prioritising migration for a long-lived data store against a lower-priority internal system. By the end, participants can build a cryptographic inventory, a migration roadmap and a crypto-agility strategy.
Expected Learning Outcomes
Assess which systems carry the highest harvest-now-decrypt-later risk and prioritise their migration accordingly.
Plan adoption of standardised post-quantum algorithms for key encapsulation and digital signatures.
Design a hybrid transition period combining classical and post-quantum algorithms to preserve interoperability.
Plan certificate authority and public key infrastructure transition steps for a post-quantum migration.
Assess hardware security module, firmware and library support for new post-quantum algorithm families.
Design a crypto-agility strategy that lets the organisation change algorithms again without a full re-architecture.
Who Should Attend
Security architects planning an organisation's post-quantum cryptography migration.
Public key infrastructure and certificate authority administrators preparing for algorithm transition.
Infrastructure engineers responsible for transport security configuration across enterprise systems.
Risk managers assessing harvest-now-decrypt-later exposure for sensitive data stores.
Application security engineers updating cryptographic libraries used in internal systems.
Compliance officers tracking regulatory expectations for quantum-safe cryptography adoption.
Course Modules
Select any module to see its sessions and points.
01Understanding the Migration Challenge
2 sessions · 8 points
Session 1The Quantum Threat to Current Cryptography
- Explain why a sufficiently capable quantum computer would break current public-key exchange and signature algorithms.
- Assess the harvest-now-decrypt-later threat model for data with a long confidentiality lifetime.
- Distinguish which cryptographic functions, key exchange, signatures and hashing, are affected differently by quantum attacks.
- Interpret current guidance and timelines from standards bodies to plan a realistic migration schedule.
Session 2Building the Cryptographic Inventory
- Inventory cryptographic algorithms, key lengths and libraries in use across applications, infrastructure and endpoints.
- Map certificate authorities, certificate lifetimes and renewal processes affected by an algorithm transition.
- Identify hard-coded or vendor-embedded cryptography that cannot be changed without a vendor upgrade.
- Prioritise inventory findings by data sensitivity, exposure and expected system lifetime.
02Adopting Post-Quantum Algorithms
2 sessions · 8 points
Session 1Key Encapsulation and Digital Signatures
- Compare standardised key encapsulation and digital signature algorithm families for enterprise use cases.
- Assess performance and key-size trade-offs of post-quantum algorithms for latency-sensitive systems.
- Select algorithm parameters appropriate to different system classes, from constrained devices to backend services.
- Test post-quantum algorithm implementations against reference test vectors before adopting them in production.
Session 2Designing the Hybrid Transition
- Design a hybrid key exchange scheme that combines a classical and a post-quantum algorithm during transition.
- Plan interoperability testing between systems at different stages of the migration to avoid connection failures.
- Define a sunset criterion for when classical-only cryptography can finally be retired from the hybrid scheme.
- Assess vendor and partner readiness for hybrid cryptography before mandating it in external-facing systems.
03Migrating PKI and Protocol Infrastructure
2 sessions · 8 points
Session 1Certificate Authority and PKI Transition
- Plan a certificate authority transition sequence that reissues certificates without breaking active trust chains.
- Update certificate templates and issuance processes to support post-quantum signature algorithms.
- Coordinate root and intermediate certificate authority updates with all relying parties before enforcement.
- Test certificate validation across client applications that may not yet support new algorithm identifiers.
Session 2Updating Transport Security Configuration
- Update transport layer security configurations to negotiate hybrid key exchange while remaining compatible with legacy clients.
- Assess hardware security module and load balancer firmware support for post-quantum algorithm families.
- Plan a phased rollout of updated protocol configuration across internal, partner and public-facing endpoints.
- Monitor negotiation failures during rollout to catch clients that cannot complete a hybrid handshake.
04Governance and Long-Term Agility
2 sessions · 8 points
Session 1Prioritising and Sequencing Migration
- Sequence migration waves by combining harvest-now-decrypt-later risk with system criticality and complexity.
- Build a migration roadmap with milestones tied to inventory completion, pilot testing and full rollout.
- Track migration progress against the roadmap and report residual risk for systems not yet migrated.
- Coordinate migration timing with vendors and suppliers whose systems interact with the organisation's own.
Session 2Designing for Crypto-Agility
- Design applications to call cryptographic functions through an abstraction layer rather than hard-coding algorithms.
- Establish a governance process that reviews cryptographic standards periodically rather than only during a crisis.
- Document a crypto-agility policy that defines how future algorithm changes will be evaluated and rolled out.
- Build testing practices that verify new algorithm support before it is required for compliance or vendor deadlines.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
