Post-Quantum Migration Walkthroughs
These walkthroughs show how the Quantumize discovery-to-roadmap methodology applies across three common organizational contexts: financial services, federal agencies, and healthcare. They are illustrative scenarios based on real engagement structures.
The scenarios below describe our methodology applied to common engagement types. They are illustrative examples, not attributed client testimonials. We publish client case studies only with explicit written permission.
Regional Financial Institution
A mid-size regional bank with 400+ customer-facing applications facing board-level pressure to demonstrate quantum readiness before an upcoming regulatory audit cycle. No cryptographic inventory existed, and the compliance team needed a reportable deliverable within 90 days.
The Challenge
- No cryptographic asset register across on-premises and cloud environments
- Mixed legacy PKI and modern TLS across 20+ systems
- 90-day window before external regulatory audit
- Board required a risk-tiered roadmap with compliance documentation
Our Approach
Cryptographic Discovery
Automated and manual scanning of the full application estate, network infrastructure, PKI hierarchy, and third-party integrations. Every RSA, ECC, and Diffie-Hellman instance catalogued with system owner and data classification.
Risk Prioritization
Scored every finding by data sensitivity, confidentiality lifetime, and exposure level. Migration priority mapped against NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) the three post-quantum standards published by NIST in August 2024.
Roadmap Delivery
Phased 18-month migration plan with NSA CNSA 2.0 milestones, per-system remediation playbooks, and a board-ready audit documentation package aligned with regulatory expectations.
Typical Outcomes
- 800+ cryptographic instances catalogued across 20+ systems in 6 weeks
- Migration scope reduced by ~35% through risk-based tiering
- Board-ready roadmap aligned with NIST FIPS 203/204/205
- Audit documentation package delivered within the 90-day window
U.S. Federal Agency
A federal agency subject to OMB M-23-02 (December 2022) needed to inventory all National Security Systems and produce a migration plan before its reporting deadline. No cryptographic asset register existed, and systems spanned both classified and unclassified environments.
The Challenge
- NSS inventory required across classified and unclassified environments
- OMB M-23-02 reporting deadline fixed and non-negotiable
- Required alignment with NSA CNSA 2.0 milestones: 2030 for new systems, 2033 for all NSS
- No baseline cryptographic register or prior assessment
Our Approach
NSS Inventory
Catalogued all National Security Systems per NSA CNSA 2.0 guidance, covering key establishment (ML-KEM target), digital signatures (ML-DSA target), and data-at-rest encryption across classified and unclassified environments.
Compliance Mapping
Mapped every finding against OMB M-23-02 requirements and NSA CNSA 2.0 deadlines. Produced a gap analysis showing current state vs. required state for each NSS and a prioritized remediation sequence.
Roadmap and Reporting
Delivered a migration roadmap with OMB-formatted reporting documentation, executive summary, and per-system-owner guidance. Reporting package ready for submission on the agency's statutory deadline.
Typical Outcomes
- 100% of NSS cryptographic assets inventoried within 8 weeks
- OMB M-23-02 reporting package completed on schedule
- Migration timeline mapped to NSA CNSA 2.0 2030 and 2033 milestones
- Zero operational disruption across classified and unclassified environments
Multi-Site Healthcare Network
A healthcare organization protecting 20+ years of patient records across 6 facilities and 4 cloud environments. Long-lived PHI represents an acute harvest-now-decrypt-later target adversaries collect encrypted records today to decrypt once quantum capability arrives.
The Challenge
- Long-lived PHI with high confidentiality requirements under HIPAA
- 6 facilities, 4 cloud environments, 3 legacy EHR systems
- Zero tolerance for disruption to clinical operations
- No dedicated security engineering capacity for a self-managed migration
Our Approach
Risk-Tiered Discovery
Prioritized systems by data longevity and sensitivity. Long-lived PHI storage and transmission paths flagged as highest priority those most exposed to harvest-now-decrypt-later interception regardless of when quantum hardware matures.
Hybrid Architecture Design
Designed a hybrid ML-KEM (FIPS 203) + classical TLS approach that preserves backward compatibility with existing systems during transition, removing dependency on a single cutover date and keeping clinical systems online throughout.
Phased Migration Plan
12-month phased plan covering all 6 facilities and cloud environments, with crypto-agility built into the architecture so the system adapts to future algorithm updates without another full migration cycle.
Typical Outcomes
- Complete assessment across 6 facilities and 4 cloud environments
- Hybrid ML-KEM (FIPS 203) approach preserves backward compatibility
- 12-month phased migration with crypto-agility architecture
- HIPAA-aligned documentation supporting audit and compliance requirements
Published Case Studies Coming Soon
We publish detailed client case studies with explicit permission. Several are in preparation now.
Regional bank, northeastern U.S.
Full case study in preparation publishing with client permission.
U.S. civilian federal agency
Full case study in preparation publishing with client permission.
Multi-site healthcare network
Case study pending engagement completion.
Frequently Asked Questions
Are these scenarios based on real engagements?
The walkthroughs are illustrative scenarios based on the types of environments and challenges we work with, presented without client-identifying details. They reflect real problem structures, sequencing decisions, and outcome types. Published case studies with explicit client permission are in preparation.
How long does a cryptographic discovery engagement typically take?
For a mid-size enterprise, a complete cryptographic discovery covering applications, network infrastructure, PKI, third-party dependencies, and supply chains typically takes six to twelve weeks. Scope, documentation availability, and environment complexity are the primary variables. The engagement produces a structured Cryptographic Bill of Materials (CBOM) as the primary deliverable.
What does the engagement deliverable include?
A cryptographic discovery and risk assessment produces a Cryptographic Bill of Materials (CBOM) cataloguing every cryptographic asset found, a risk-tiered prioritization of migration scope, and a phased migration roadmap with per-system remediation guidance. For organizations with compliance requirements, deliverables are structured to support audit documentation and regulatory reporting.

