up:: For Business Leaders MOC

What does this cost?

The replacement encryption is free. NIST publishes it as an open standard, and anybody can download a working implementation today at no charge.

What costs money is finding every place in your organization where the old encryption is running, replacing each one without breaking what depends on it, and waiting on the vendors who control the parts you can’t touch. That work is measured in staff years and vendor negotiations, and it’s why no honest advisor can quote you a price before you’ve looked.

The short version:

  • The algorithms cost nothing. They’re free public standards, so the budget is labor and coordination from end to end.
  • Nobody can price it before the inventory. The number comes out of finding where your cryptography lives, which is itself the first funded piece of work.
  • The one credible anchor is governmental. The U.S. projects about $7.1 billion to migrate priority federal civilian systems between 2025 and 2035.
  • Old hardware is usually the biggest single line. Equipment with encryption built into the chip or firmware often can’t be updated and has to be replaced.
  • A large share of the bill belongs to vendors. You’re paying to chase roadmaps and rewrite contracts for products you can’t modify.
  • Starting late raises the price of identical work, because a compressed schedule pays overtime, loses vendor leverage, and can’t be spread across budget years.

What are we actually paying for?

Six categories, and most first-pass estimates only capture the second one.

Line itemWhat generates the costWhat makes it bigger or smaller
Finding itLocating every place encryption runs across applications, networks, certificates, and purchased productsEstate size, sprawl, and how much documentation already exists
Replacing itSwapping algorithms, reconfiguring protocols, reissuing certificates, and testing each changeHow much of the estate your own engineers built and control
Replacing hardwareEquipment with encryption fixed in firmware that can’t be upgraded and has to be bought newThe age of your operational, industrial, and embedded equipment
Vendor coordinationChasing supplier roadmaps, writing requirements into contracts, and waiting on release schedulesHow much of the estate you bought rather than built
TestingConfirming the larger post-quantum messages travel end to end without breaking older equipment in the pathOlder network gear and constrained links choke on bigger handshakes
Running the programA named owner, project management, and coordination across teams for several yearsOrganization size and how many teams have to be involved

The categories a shallow estimate forgets are hardware replacement, vendor coordination, and multi-year program management. Those 3 usually dominate the real bill, while the algorithm swap on a modern system your own team built is the cheap part.

The U.S. government’s own report on the transition names legacy systems with encryption embedded in hardware or firmware as the most difficult and expensive to migrate, precisely because they often can’t be updated and have to be replaced outright.

Source: Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, OMB PQC Report.

Is there a real number we can anchor to?

One, and it’s worth understanding exactly what it covers before quoting it.

The Office of Management and Budget projected that migrating priority federal civilian information systems to post-quantum cryptography between 2025 and 2035 will cost approximately $7.1 billion in 2024 dollars. OMB describes this as an initial projection carrying “a high, but expected, level of uncertainty,” because agencies were still building their inventories when it was produced.

Source: Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, OMB PQC Report.

Three qualifiers travel with that figure:

  1. It excludes national security systems. Defense and intelligence migration sits outside it, so the whole-of-government cost is higher than the published civilian number.
  2. It covers a decade across an entire federal civilian government. There’s no ratio that scales it down to one company.
  3. It was produced by inventory, then costing. OMB directed agencies to submit a prioritized inventory of their cryptographic systems and then an assessment of what migrating them would require. The $7.1 billion is the sum of those agency assessments.

Source: Office of Management and Budget, “Migrating to Post-Quantum Cryptography,” Memorandum M-23-02, November 18, 2022, OMB M-23-02.

The third qualifier is the useful one for a private company. The government arrived at its number the same way you’ll have to arrive at yours: count what you have, then price it.

Why won’t anyone quote us a price?

Because the cost depends on 3 facts about your organization that nobody knows until somebody looks.

  1. How big and how tangled the estate is. Encryption lives in applications, network equipment, certificates, databases, backups, and purchased products. Most organizations have never counted it at the algorithm level.
  2. How much old hardware you own. A company running mostly modern cloud services and a company running a 20-year-old plant floor have completely different bills for identical revenue.
  3. How much of it belongs to vendors. For most enterprises, the majority of cryptographic surfaces sit inside products a supplier owns and updates. That share of the migration is priced by somebody else’s release schedule.

A vendor quoting you a per-organization figure before running discovery on your estate is quoting a number with nothing behind it. Treat that as an estimate to challenge rather than a plan to fund.

Why does waiting make the same work cost more?

Three mechanisms, all of them mundane.

  1. Compression pays a premium. Finding and replacing encryption across a large estate takes years. Doing the same work in fewer years means more parallel effort, more contractors, and more overtime for an identical result.
  2. Late buyers have no leverage. The moment to get a supplier to commit to a dated migration timeline is at purchase or contract renewal. A company chasing that commitment a few months before a deadline has nothing to trade for it.
  3. A late start can’t be phased. Beginning early lets the spend spread across several budget years, where it’s easier to fund and easier to absorb. A late start forces it into one narrow window, competing with everything else in that cycle.

The data itself adds a fourth. Information copied off your network today is exposed retroactively once the machine exists, so the years you spend deciding are years of records you’ve already committed to leaving readable. See Is someone stealing my data right now.

What should we fund first, before we know the total?

The inventory. It’s the smallest defensible request in the entire program, and it’s the thing that produces every number after it.

A scoped, time-boxed inventory answers one question: where does quantum-vulnerable encryption live, and what data is behind it. From that you get a records-at-risk count, a ranked list of what moves first, and a cost estimate somebody can actually defend under questioning.

StageWhat you’re fundingWhat comes out of it
1. Scoped inventoryA time-boxed search of your most sensitive systemsWhere the encryption is, and on what data
2. QuantificationTurning that inventory into exposure and cost figuresThe number your board asked for
3. Sequenced programThe migration itself, ordered by consequence and deadlineThe multi-year spend, phased

Funding stage 1 commits you to nothing except knowing where you stand, which is why it’s the request most likely to get approved in the room. See How do I explain this to my board.

Questions people ask

So what’s the range for a company our size? There isn’t a defensible published range, because the drivers vary more between 2 similar-revenue companies than the revenue does. The honest sequence is inventory, then estimate.

Do we have to buy the new encryption? No. ML-KEM, ML-DSA, and SLH-DSA are free open standards published by NIST, and working implementations are freely available.

What’s the single most expensive part? For most large organizations, replacing equipment with encryption embedded in hardware or firmware that can’t be upgraded.

Can our cloud provider absorb this for us? Partly, and less than most teams expect. Providers migrate their own infrastructure, and a substantial share of the encryption in a cloud estate is still configured and owned by the customer. See What can I not fix myself.

Is this a one-time cost? The migration is, and building the ability to change algorithms without another full program is a separate investment that reduces the cost of every future transition. That capability is the cheapest line in the budget over a 20-year horizon.

Isn’t it cheaper to wait until the equipment ages out naturally? For some categories, yes, and that’s a legitimate strategy where the replacement cycle lands before your deadline. It fails where the equipment has a 20-year service life or the data behind it has to stay confidential for decades.

What if we just do nothing? Three consequences follow: long-lived records copied today become readable later, you miss a dated obligation your own contracts already point at, and you lose contracts whose buyers inherit a post-quantum requirement. See What do regulators expect.

Where to go next

Go deeper into the technical detail

The technical cost model, with every driver weighted, is What a PQC Migration Costs and The Inventory-First Cost Build.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.