Where do we actually start?
If you’ve read enough about this to be worried and have no idea what to do on Monday, this is the page.
The honest position: the first 90 days are cheap, small, and mostly not technical. Almost everything expensive comes later and depends on decisions you can’t make yet. Organizations that get stuck here get stuck because they think step one is a migration program. It isn’t. Step one is finding out what you have.
Nothing below requires new budget, new headcount, or a vendor.
The short version:
- Week 1 is one meeting and one email. That’s genuinely the whole first week.
- Nothing in the first 90 days requires a budget request.
- The order matters more than the speed. Doing these out of sequence is what wastes money.
- Two of the 5 moves cost almost nothing and carry most of the value, and both are conversations.
- You’ll finish with 3 numbers, which is what any funding request needs.
- Everything you’re deliberately not doing is listed, so you can stop worrying about it.
What are the 5 moves?
In order. Each depends on the one before it.
| # | Move | Rough effort | What it produces |
|---|---|---|---|
| 1 | Name an owner | 1 meeting | Somebody accountable. Without this, nothing else happens |
| 2 | Sort your data by confidentiality lifetime | 2 to 3 conversations | Whether you have a near-term problem or a distant one |
| 3 | Ask your top vendors the question | 1 email each | The timelines that actually set your schedule |
| 4 | Scope an inventory of your most sensitive systems | Weeks, delegated | Where your cryptography lives, on the systems that matter |
| 5 | Write down the 3 numbers | 1 afternoon | A defensible position for a board or a customer |
1. Name an owner
One person, senior enough to ask other departments for answers, with this written into their objectives. Not a committee.
Ambiguous ownership is the single most common reason this never starts. Every organization that stalls has the same story: everyone assumed somebody else was tracking it.
The owner doesn’t need to be technical. They need to be able to get a straight answer out of procurement, legal, and IT.
2. Sort your data by how long it must stay confidential
This is the step people skip, and skipping it is what makes everything downstream expensive.
Ask the business owners of each major data category one question: if this were published in 10 years, would it still hurt us? Not your engineers. The people who own the records.
You’re sorting into 3 piles:
- Stays sensitive for a decade or more. Intellectual property, legal files, health records, customer personal data, anything under a long retention rule.
- Sensitive for a few years. Contracts, deal material, most business records.
- Stops mattering quickly. Most operational traffic. This is the biggest pile and you’re going to leave it alone.
For a large share of it, the law already sets the clock: records you’re required to retain for 7 years are records with a 7-year exposure you didn’t choose. See What of our company data is at risk.
If the first pile is empty, you have a much smaller problem and the honest answer is that you can move slowly. Most organizations discover it isn’t empty.
3. Ask your top vendors
Most of your cryptography sits inside products you bought, on release schedules the vendor sets, and those schedules govern your timeline regardless of how fast the work moves internally.
Pick your 10 most important vendors by what data they hold. Send each the same email. The template is at What if we are a small business and it works unchanged at any size.
Do this early, because vendor answers take weeks to come back and months to route through their product organizations. It’s the longest-lead item on this list and the cheapest to start.
The highest-value version of this move: put the question into contracts you’re already renewing. No new process, and your leverage is at its maximum at renewal.
4. Scope an inventory, aimed narrowly
Now, and only now, an inventory makes sense, because steps 2 and 3 told you where to point it.
Aim it at the systems carrying the first pile from step 2. Not the whole estate. A time-boxed look at your most sensitive systems answers the question a regulator, auditor, or large customer will ask first: where does your cryptography live, and on what data?
Most organizations discover the estate is bigger and stranger than anyone thought. That discovery is the point, and finding it now is cheaper than finding it against a deadline.
5. Write down the 3 numbers
Whatever you do next, it needs these:
- How many sensitive records sit under encryption scheduled for retirement, from step 4.
- Your earliest binding date, which usually comes from a contract, a certification, or a big customer’s requirements rather than a regulator. See What do regulators expect.
- What the next phase costs, scoped, rather than a whole-program figure you can’t defend.
Those 3 are what a board approves against, what a customer questionnaire wants, and what any outside help would start from. See How do I explain this to my board.
What are we deliberately not doing?
Written out so you can stop carrying it.
- Not migrating anything yet. You don’t know what to migrate.
- Not buying a product. The algorithms are free and no purchase substitutes for the inventory.
- Not hiring. Nothing in the first 90 days needs a new person.
- Not inventorying the whole estate. Aim narrow. The wide version is a multi-year exercise that stalls.
- Not predicting when quantum computers arrive. Your timeline comes from data lifetime and vendor schedules.
- Not fixing the pile that stops mattering quickly. That’s most of your data and it’s genuinely fine.
What if we’re too small for even this?
Then it compresses to about a morning, and the shape is different enough to be worth its own page.
For an organization with no security team, the whole exposure is a vendor list you already have in your billing records. Steps 1, 2, and 3 collapse into one sitting. See What if we are a small business.
What does it look like when this goes wrong?
Three failure patterns, all common enough to name.
Starting with a tool. Buying discovery tooling before knowing which systems matter produces a large report nobody acts on. Tooling helps step 4, after steps 2 and 3 have aimed it.
Inventorying everything. A whole-estate inventory is a multi-year project that outlives the attention funding it. Narrow scope finishes; broad scope stalls.
Treating it as an IT project. It competes with feature work and loses. It’s a governance obligation with a date attached, and framing it that way is what gets it resourced. See Why not wait until AI is under control.
Questions people ask
How long does this really take? The first 3 moves are days of actual work spread over a few weeks. The inventory is the first thing measured in weeks rather than hours.
Do we need outside help? Not for the first 90 days. A capable internal team runs all 5 moves. Outside help earns its cost when the estate is large or vendor-dense, or when an answer has to satisfy a regulator or auditor.
What if we find something alarming? Almost every organization finds systems nobody remembered and vendors with no roadmap. That’s the normal result, not a crisis, and finding it now is the whole point.
Our vendors won’t answer. Silence is an answer, and a useful one. Record it, and weigh it at renewal. A vendor fielding the question from 30 customers moves faster than one fielding it from none.
Can we skip to the inventory? You can, and it’ll cost more and take longer, because you’ll be inventorying everything instead of what matters.
What if this turns out to be overhyped? The inventory retains its value regardless, since it’s a map of where your sensitive data flows and what protects it. Most organizations have never had one. See Is this overhyped.
Where to go next
- What of our company data is at risk is the sorting exercise from step 2, in full.
- What can I not fix myself covers the vendor question from step 3.
- What should I ask my security team is 5 questions that tell you where you already stand.
- Why not wait until AI is under control covers the objection you’ll hear internally.
- For Business Leaders MOC is the full business route.
Go deeper into the technical detail
The technical version, the hands-on execution starter for the practitioner handed this with no idea where to begin, is Start a Migration.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.