Building a PQC Roadmap Your Board Can Actually Approve

FINMA recommends that supervised institutions draw up a PQC roadmap by mid-2027 at the latest.
But putting “migrate to PQC” on a timeline isn't a roadmap.
A credible roadmap needs scope, milestones, priorities, ownership and target dates for critical and full migration.
And those dates depend on knowing what cryptography exists today.
Start with ownership
A PQC transition crosses security, infrastructure, applications, procurement, risk and third-party management.
That means responsibility cannot sit informally between teams.
Before discovery begins, identify:
Executive sponsor — accountable at governing-body level.
Operational owner — responsible for coordinating the programme.
Technical owners — responsible for affected systems, applications and infrastructure.
Reporting cadence — defining how progress and risks reach senior management.
Discovery comes before the roadmap
FINMA's inventory recommendation covers encryption, signatures and authentication across systems, applications and infrastructure.
No single discovery mechanism will find everything.
A practical approach combines multiple sources, including network scanning, container-image analysis, static source-code analysis and integration with existing CMDB and certificate lifecycle management systems.
Cloud services, legacy systems, embedded environments and third-party systems introduce further blind spots.
That is why discovery should start before the final roadmap is written.
From inventory to CBOM
Finding cryptographic assets once isn't enough.
The inventory needs to remain usable throughout a multi-year migration.
A machine-readable Cryptography Bill of Materials (CBOM) can provide a structured way to document cryptographic dependencies and keep that information queryable.
The campaign plan specifically proposes CycloneDX and integration into CI/CD as the basis for keeping the inventory current rather than relying on a static spreadsheet.
Prioritise instead of migrating everything at once
Not every cryptographic asset carries the same risk.
Prioritisation should consider factors such as:
How long must the data remain confidential?
When could the cryptography protecting it become insufficient?
How difficult is the asset to migrate?
What systems and business processes depend on it?
Long-lived roots, code-signing keys and information requiring long-term confidentiality deserve particular attention.
Crypto-agility changes the roadmap
PQC migration should not simply replace one algorithm with another.
The longer-term objective is to make future cryptographic changes easier.
The practical question therefore becomes:
How long would it take us to execute a fleet-wide algorithm change today?
If certificates are still discovered, renewed and replaced manually, the answer may expose a larger operational challenge.
Automated certificate lifecycle management, policy-based enforcement and repeatable processes become part of building crypto-agility.
Don't leave suppliers until the end
External providers need to be part of the roadmap from the beginning.
FINMA's guidance states that responsibility remains with the outsourcing institution, making supplier timelines an important dependency in migration planning.
Questions about crypto-agility, migration plans and release cycles therefore belong in provider assessments and contracts.
What should ultimately reach the board?
A useful roadmap should allow decision-makers to see:
scope, priorities, target dates, accountabilities, budget requirements, major dependencies, critical migration milestones and progress metrics.
The objective isn't to promise a date before the organisation has enough information.
It's to create enough visibility to make the dates defensible.
Stay informed on PQC & Crypto-Agility
Preparing for the post-quantum transition is an ongoing process. Join the ID Security Community for practical insights, regulatory developments and expert exchange around Post-Quantum Cryptography & Crypto-Agility and Certificate Management & Automation.
JOIN THE ID SECURITY COMMUNITY →
Want to discuss your PQC roadmap?
If you’re assessing your cryptographic landscape, building your roadmap or considering your next steps, our team would be happy to discuss your current position.

