Prioritising What To Migrate First: Shelf Life, Exposure And Migration Time
Not every system can move at once. This article explains a simple scoring method from the financial sector and how to turn inventory findings into a ranked, reviewable plan.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Once an inventory exists, the next question is order. A large organisation may find hundreds of systems that rely on quantum-vulnerable cryptography, and it cannot move them all at once. Prioritisation decides which go first, which wait for a planned upgrade and which need long-term work with suppliers.
This article explains the factors official guidance uses, walks through a practical scoring method published for the financial sector, and shows how to turn raw findings into a review that decision-makers can act on.
What Official Guidance Prioritises
OMB’s memorandum M-26-15 tells US federal agencies to put high impact systems and high value assets first, along with any other system holding highly sensitive data. It specifically includes access control systems built on public-key infrastructure that use vulnerable algorithms, and systems holding data expected to remain sensitive in 2030.1 OMB also sequences the work: key establishment is migrated in its 2028 to 2030 phase, and digital signatures in 2031.1 OMB does not spell out its reasoning, but one likely reason for that order is that recorded traffic threatens confidentiality today, while signature forgery only becomes possible once a quantum computer exists.
The UK National Cyber Security Centre defines priority services as those that process the most valuable or long-lived data. It also asks organisations to identify where they depend on long-lived hardware, since that limits how quickly they can change.2
A Scoring Method From The Financial Sector
In 2026, Europol published a prioritisation framework for financial services, written by contributors from banks, banking and industry associations, an insurer, a central bank, the European Investment Bank and a university, under a CC BY 4.0 licence.3 The summary below is adapted from that report. It scores each business use case on two axes.
The Quantum Risk Score reflects how urgent the use case is. It averages three factors, each rated 1 to 3, and rounds the result to a whole number.3
| Factor | 1 (low) | 2 (medium) | 3 (high) |
|---|---|---|---|
| Shelf life of protected data | Under 2 years | 2 to 5 years | Over 5 years |
| Exposure | Accessed over owned infrastructure only | Limited to specific third parties | Public or easily leaked |
| Severity | Minimal, reputational at most | Relevant business impact | Severe disruption |
The Migration Time Score reflects how hard the change will be, which corresponds to the Y in Mosca’s inequality. It averages solution availability, execution cost and time, and external dependencies, again rounding to a whole number. Each is scored 1 to 3, and external dependencies score 3 when third-party roadmaps are uncertain or longer than three years.3
| Factor | 1 (short) | 2 (medium) | 3 (long) |
|---|---|---|---|
| Solution availability | Available now or in under a year | Expected in 1 to 3 years | Uncertain or over 3 years |
| Execution cost and time | Minor reconfiguration as normal work | Moderate architectural change | Major, uncertain or costly upgrades |
| External dependencies | Minimal or already widely adopted | Third parties with known 1 to 3 year roadmaps | Third parties with uncertain or longer roadmaps |
From Scores To Priority
The two scores place each use case in one of six categories, grouped into high, medium and low priority.3 The flowchart below walks through that grouping. It is our own reading of the categories in the report, not a chart the report publishes.
Is the Quantum Risk Score 3?
- Yes:
High priority. Migrate now if a solution is ready; otherwise plan and budget in the near term and start no-regret preparation.
- No:
Is the Quantum Risk Score 2?
- Yes:
Is the Migration Time Score 3?
- Yes:
High priority. Start long-term planning now, because the dependencies take years to resolve.
- No:
Is the Migration Time Score 1?
- Yes:
Medium priority. Include in routine upgrades.
- No:
Medium priority. Track it, plan the timing and start no-regret preparation.
- Yes:
- Yes:
- No:
Low priority. Address opportunistically through normal modernisation.
- Yes:
The report works through two examples. Public websites score medium risk (shelf life 3, exposure 2, severity 2) and low migration time, because hybrid post-quantum key exchange is already widely supported. Offline card authentication at the point of sale also scores medium risk (shelf life 3, exposure 3, severity 1) but high migration time, because of long terminal replacement cycles and many industry parties. The second example ends up as the higher priority.3 The no-regret moves and payments articles cover both cases.
The authors stress that the insight gained from the exercise matters more than the scores themselves, and encourage each organisation to adapt the framework to its own context.3
From Findings To A Readiness Review
Scoring only works if the inputs are sound. Before a finding goes into the matrix, establish three things: its purpose (what the cryptography is protecting), its owner (who can change it) and its dependencies (which suppliers, protocols or hardware it relies on). Where any of these is unknown, mark the finding for investigation rather than guessing.
A readiness review then brings the scored use cases together for decision-makers. A good review keeps:
- The scope and collection dates of the evidence behind each score, so readers know what was examined and when.
- Assumptions stated openly, such as an expected supplier upgrade date, with a named person to confirm each one.
- A list of open questions, separated from confirmed findings.
- A clear statement of limits. An inventory and a set of scores support decisions. They do not prove that a system is secure or ready to migrate.
Repeat the review as the inventory improves and as suppliers publish roadmaps. Scores will shift as solutions become available, so a use case that scores high on migration time today may become routine work next year.
Footnotes
-
Office of Management and Budget, “Execution of the Migration to Post-Quantum Cryptography” (M-26-15), 24 June 2026. whitehouse.gov ↩ ↩2
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩
-
Europol, “Prioritising Post-Quantum Cryptography Migration Activities in Financial Services”, Publications Office of the European Union, 2026. Contributing authors: Oscar Covers, Thibaud Ecarot, Rebecca Gibergues, Jaime Gómez García, Francis Gorman, Imran Khan, Ivan Makarov, Sarah McCarthy, Michele Mosca, Iván Soto, Leila Taghizadeh and Jelena Zelenovic. Licensed under CC BY 4.0. The two scoring tables are adapted from it, with changes; the flowchart is our own reading of its priority categories. europol.europa.eu ↩ ↩2 ↩3 ↩4 ↩5 ↩6
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.