Deep Dive Series
PQC Governance: The Complete Program Leadership Guide
Most PQC migration programs don’t stall because of a technical problem. They stall because nobody owns them. Two financial services organizations I worked with in 2026 had the budget, the technical readiness, and the executive awareness, yet still pushed their start dates by nine months because they couldn’t answer a single question: who leads this? This Deep Dive series provides the answer, starting with the governance model that works in practice: one accountable executive, a cross-functional steering committee, a dedicated program office, and specialist execution teams.
The series then examines each governance layer in depth. It covers how boards discharge their PQC risk oversight duties through risk appetite statements and cascading KRIs. It maps six real-world CISO organizational models to determine who should lead in your specific structure. It tackles the cost estimation problem that kills programs in the CFO’s office, addresses vendor and supply chain governance at enterprise scale, and lays out the two-layer execution model that separates infrastructure migration from application-layer work. The final article answers the major objections that CISOs and boards encounter when standing up PQC programs, with evidence and historical precedent.
-
PQC Governance
Board-Level PQC Risk Governance: How Directors Oversee a Migration They Don’t Technically Understand
Directors don't need quantum literacy to govern PQC migration. They need risk appetite statements, cascading KRIs, and the discipline to hold the accountable executive to delivery.
Read More » -
PQC Governance
The CISO’s Role in PQC Migration: Organizational Models, Three Lines of Defence, and the Authority Question
The CISO role varies enormously across organizations. That variation determines whether CISO-led PQC governance works, and this article maps six real-world models to explain when and why.
Read More » -
PQC Governance
Nobody Can Tell You What PQC Migration Costs. Here’s How to Get Budget Anyway.
Every CISO building a PQC business case faces the same problem: no organization has completed a full migration, so no reliable cost model exists. Here's how to build the budget request anyway.
Read More » -
PQC Governance
PQC Vendor and Supply Chain Governance: Managing Third-Party Cryptographic Risk at Enterprise Scale
62% of organizations are waiting for vendors to make them quantum-safe. That mindset is dangerous. Here's how to govern vendor PQC readiness without outsourcing your accountability.
Read More » -
PQC Governance
Executing PQC Migration: Every Domain Where Cryptography Lives Is in Scope
PQC migration is not a two-layer IT project. It reaches every domain where cryptography lives — including domains your CISO has never managed. Here's how to structure execution across all of them.
Read More »