This section identifies the system undergoing migration and catalogs the sensitive data assets it protects. Complete all fields to ensure proper risk assessment and resource allocation.
System Name
System Unique Identifier
System Version
System Owner Full Name
System Owner Email
IT Lead Full Name
IT Lead Email
Primary Deployment Environment
On-Premise Data Center
Private Cloud
Public Cloud
Hybrid Infrastructure
Edge Computing
Geographic Distribution of System Infrastructure
North America
South America
Europe
Asia-Pacific
Middle East
Africa
Global Distribution
System Criticality Level (1=Low, 5=Critical)
Detail the sensitive data assets protected by this system's cryptographic mechanisms. Accurate data classification is essential for determining migration priority and resource allocation.
Sensitive Data Types Handled by System
Personal Identifiable Information (PII)
Financial Records
Health Information (PHI)
Intellectual Property
Classified Government Data
Authentication Credentials
Cryptographic Keys
Other Sensitive Data
Total Data Volume Protected (Terabytes)
Number of Active Data Records (Millions)
Highest Data Classification Level
Public
Internal Use
Confidential
Restricted
Top Secret
Applicable Generic Regulatory Frameworks
Data Protection Standard
Financial Security Standard
Healthcare Data Standard
Government Security Standard
International Privacy Framework
Industry-Specific Security Standard
Maximum Data Retention Period
Retention Period Unit
Days
Months
Years
Number of Directly Interconnected Systems
List All Interconnected Systems and Integration Types
Does System Have External API Dependencies?
Are Third-Party Data Processors Involved?
Are There Data Residency Requirements?
Does System Perform Cross-Border Data Transfers?
Business Criticality Justification for Priority Migration
Document your current cryptographic implementations and specify the target post-quantum cryptographic standards. Provide detailed technical specifications for both current and future states.
Current TLS/SSL Version in Production
TLS 1.3
TLS 1.2
TLS 1.1
TLS 1.0
SSL 3.0
Not Applicable
Current Certificate Authority Provider
Current Certificate Expiry Date
Current Asymmetric Cryptographic Algorithms in Use
RSA
ECC (Elliptic Curve)
Diffie-Hellman
DSA
ECDSA
EdDSA
Other
Current RSA Key Size (bits)
Current ECC Key Size (bits)
Current Symmetric Encryption Algorithms
AES-128
AES-256
ChaCha20
3DES
RC4
Other
Current Hash Functions
SHA-256
SHA-384
SHA-512
SHA3-256
SHA3-512
MD5
SHA-1
Other
Current Key Exchange Mechanisms
ECDHE
DHE
RSA Key Transport
PSK
Other
Primary Cryptographic Libraries Used
OpenSSL
BoringSSL
Bouncy Castle
LibreSSL
Mbed TLS
wolfSSL
NSS
Custom/Proprietary
Is System FIPS 140-2 or FIPS 140-3 Compliant?
Does System Utilize Hardware Security Modules (HSMs)?
Specify your target post-quantum cryptographic standards based on NIST PQC competition results and organizational security requirements.
Target PQC Standard Maturity Level
NIST PQC Round 4 Finalists
NIST PQC Standardized (FIPS 203, 204, 205)
Hybrid Classical-PQC
Experimental/Custom PQC
Selected PQC Key Encapsulation Mechanism (KEM)
CRYSTALS-Kyber (ML-KEM)
FrodoKEM
Classic McEliece
BIKE
HQC
Custom KEM
Selected PQC Digital Signature Algorithm
CRYSTALS-Dilithium (ML-DSA)
Falcon
SPHINCS+ (SLH-DSA)
Rainbow
Custom Signature Scheme
Will System Implement Hybrid Cryptographic Approach?
Target TLS Version Supporting PQC
TLS 1.3 with PQC Extensions
TLS 1.2 with PQC Cipher Suites
Custom PQC-Enabled TLS
Not Determined
Target PQC-Enabled Cryptographic Library
Expected Certificate Chain Size Increase (%)
Cryptographic Operation Performance Comparison
Operation Type | Current Latency (ms) | Projected PQC Latency (ms) | Overhead Factor | |
|---|---|---|---|---|
Key Generation | 5 | 50 | 10 | |
Signature Generation | 1 | 5 | 5 | |
Signature Verification | 0.5 | 2 | 4 | |
Handshake Completion | 20 | 80 | 4 | |
PQC Implementation Strategy
Software Library Update
Hardware Module Replacement
Firmware Upgrade
Full System Replacement
Cryptographic Proxy/Overlay
Will System Support Parallel Cryptographic Operations?
Are Cryptographic Agility Mechanisms Implemented?
Quantify the performance impact of migrating to quantum-resistant algorithms. Provide baseline measurements and projected impacts on latency, computational overhead, and network bandwidth.
Baseline TLS Handshake Latency (milliseconds)
Projected PQC Handshake Latency (milliseconds)
Latency Increase Percentage (%)
Baseline CPU Utilization for Crypto Operations (%)
Projected CPU Utilization Post-Migration (%)
CPU Overhead Increase (percentage points)
Baseline Memory Footprint for Crypto Operations (MB)
Projected Memory Footprint (MB)
Memory Increase Percentage (%)
Baseline Asymmetric Key Generation Time (ms)
Projected PQC Key Generation Time (ms)
Key Generation Overhead Factor
Baseline Digital Signature Generation Time (ms)
Projected Signature Generation Time (ms)
Baseline Signature Verification Time (ms)
Projected Signature Verification Time (ms)
Network Bandwidth Overhead Increase (%)
Migration Phase Timeline and Downtime Estimates
Phase Name | Planned Start Date | Planned End Date | Estimated Downtime (hours) | Risk Score (1-10) | |
|---|---|---|---|---|---|
Assessment & Planning | 1/15/2025 | 2/15/2025 | 0 | 2 | |
Development Environment Migration | 3/1/2025 | 3/31/2025 | 4 | 5 | |
Staging Environment Migration | 4/1/2025 | 4/30/2025 | 8 | 6 | |
Production Migration | 5/1/2025 | 5/31/2025 | 12 | 8 | |
Total Estimated Migration Duration (days)
Aggregate Planned Downtime (hours)
Estimated Rollback Time (minutes)
Parallel Run Duration (days)
Performance Testing Duration (days)
Is Load Testing Required Before Production Deployment?
Performance Acceptance Criteria for Migration Success
Define comprehensive fallback procedures and key management strategies to ensure operational continuity and cryptographic key lifecycle governance during and after migration.
Primary Fallback Strategy if PQC Migration Fails
Rollback to Legacy Cryptography
Switch to Hybrid Mode
Degraded Functionality Mode
Complete System Shutdown
Manual Intervention Required
Automated Rollback Triggers
Performance Degradation >50%
Handshake Failure Rate >5%
System Crash
Key Generation Failure
Certificate Validation Error
No Automated Triggers
Is Manual Rollback Authorization Required?
Is Key Escrow Mechanism Implemented?
PQC Key Rotation Frequency
30 Days
90 Days
180 Days
365 Days
On-Demand
No Rotation Planned
Is Formal Key Generation Ceremony Required?
Primary Key Storage Solution
Hardware Security Module (HSM)
Cloud Key Management Service (KMS)
Software-Based Key Store
Distributed Key Management System
Hybrid Storage
HSM Vendor and Model (if applicable)
Cloud KMS Provider Name (if applicable)
Key Distribution Mechanism Description
Are Zeroization Procedures Documented?
Are Legacy Cryptographic Keys Backed Up Before Migration?
Disaster Recovery Test Frequency (months)
Is Key Compromise Response Plan Documented?
Number of Key Custodians for PQC Master Keys
Shamir Secret Sharing Threshold (M of N)
Key Management Personnel and Responsibilities
Role | Name | Training Completed | Last Certification Date | ||
|---|---|---|---|---|---|
Key Custodian | John Doe | john.doe@company.com | Yes | 10/1/2024 | |
Backup Custodian | Jane Smith | jane.smith@company.com | Yes | 9/15/2024 | |
Is Cross-Training Completed for All Key Custodians?
Documentation Repository URL
Obtain formal approval from the Cryptographic Review Board. Provide evidence of risk assessment, security testing, and compliance verification to support the migration decision.
Form Submission Date to Review Board
Primary Reviewer Name
Primary Reviewer Email
Cryptographic Review Board Members
Is Formal Risk Assessment Completed?
Overall Migration Risk Level
Low Risk
Medium Risk
High Risk
Critical Risk
Is Independent Security Audit Completed?
Is Penetration Testing Completed on PQC Implementation?
Is Compliance Verification Completed?
Compliance Frameworks Verified
Data Protection Standard
Financial Security Standard
Government Security Standard
Industry Security Standard
International Privacy Framework
Is Complete Technical Documentation Submitted?
Is Implementation Timeline Approved by All Stakeholders?
Post-Implementation Review Scheduled Date
Cryptographic Review Board Approval Status
Pending Review
Approved with Conditions
Approved
Rejected
IT Lead Digital Signature
Chief Information Security Officer (CISO) Digital Signature
Chief Technology Officer (CTO) Digital Signature
Final Board Approval Date
Authorized Production Go-Live Date
Post-Implementation Monitoring Period (days)