The Office of Management and Budget has set a firm deadline for compliance officers. High-value assets for key establishment must transition to post-quantum cryptography by 2030, with digital signatures following in 2031. If you're waiting for "more guidance," you're already behind the pilot program deadline of December 31, 2027.
This template provides a structured way to inventory, prioritize, and track your PQC migration work. It's based on the requirements in the recent executive order and assumes you're working within federal agency constraints or under 48 CFR flow-down requirements as a contractor.
Purpose of the Template
You need a living document that maps every cryptographic asset in your environment to a migration decision. This isn't a one-time audit. It's an ongoing tracking mechanism that lets you answer three questions at any point:
- What cryptographic systems do we operate or depend on?
- Which ones face quantum risk and when?
- What's our migration path and current status?
This template structures that work as a spreadsheet with decision logic included. You'll track assets, classify risk, assign owners, and log migration actions. The output becomes your evidence trail when OMB or your agency CISO asks for proof of progress.
Prerequisites
Before you populate this template, ensure you have:
- Designated PQC migration lead. Agencies must assign a named individual. Without one, this work stalls at the first cross-team decision.
- System inventory access. You can't migrate what you can't see. Pull your Authority to Operate packages, system security plans under NIST SP 800-37, and any Common Control Provider inheritance statements. You need read access to configuration management databases and network diagrams.
- Cryptographic standards baseline. Know which systems currently use FIPS 140-2 validated modules, where you're using X.509 Certificates for authentication, and what your Public Key Infrastructure topology looks like. If you're running classified systems, confirm your Committee on National Security Systems Instruction No. 1253 categorization.
You don't need to have picked your PQC algorithms yet. NIST has published the first standards, but vendor implementations are still maturing. What you need is the asset list and risk classification so you can act when validated modules become available.
The Template
Create a spreadsheet with these columns. Each row represents one cryptographic system or dependency:
Asset Identification
- System Name / Identifier
- Authorizing Official (or system owner if pre-ATO)
- Current ATO Date / Expiration
- Impact Level (FIPS 199 or DoD Cloud Computing Security Requirements Guide Impact Level 2/Impact Level 4/Impact Level 5)
Cryptographic Profile
- Cryptographic Function (key establishment, digital signature, encryption at rest, encryption in transit)
- Current Algorithm(s) (RSA-2048, ECDSA P-256, AES-256, etc.)
- FIPS 140-2 Module Name/Certificate Number
- Key Management Method (manual, automated via PKI, hardware security module)
Quantum Risk Assessment
- Quantum-Vulnerable? (Yes/No, if it relies on integer factorization or discrete log problems, it's yes)
- Data Sensitivity Classification (CUI Basic, National Security System, classified, public)
- Harvest-Now-Decrypt-Later Risk (High/Medium/Low, based on data lifespan and adversary interest)
- Migration Deadline (2027 pilot, 2030 key establishment, 2031 digital signature, or agency-specific)
Migration Plan
- Migration Strategy (hybrid dual-stack, rip-and-replace, decommission system, accept risk with documented rationale)
- Planned PQC Algorithm (CRYSTALS-Kyber/ML-KEM, CRYSTALS-Dilithium/ML-DSA, or TBD)
- Dependencies / Interoperability Constraints (list external systems, allied government connections, contractor integrations)
- Assigned Migration Owner
- Status (Not Started, Planning, Pilot, In Progress, Completed, Deferred)
- Target Completion Date
- Blocker / Notes
Add a summary tab that rolls up counts by status, deadline, and risk level. You'll use that view in program reviews.
Customizing the Template
For Civilian Agencies: Add a column for OMB MAX ID or FISMA system identifier to cross-reference with your annual FISMA reporting. Tag systems that inherit controls from a Common Control Provider, you'll need to coordinate migration timing with that provider or risk breaking inheritance.
For Defense Contractors: Replace "Authorizing Official" with "Government Contracting Officer" or "Program Office POC." Add a column for contract number and DFARS 252.204-7012 applicability. If you handle International Traffic in Arms Regulations data, flag those systems, you may face additional export control constraints on PQC implementations.
For National Security Systems: Add Committee on National Security Systems Instruction No. 1253 overlay requirements and confirm whether you need Type 1 Encryption or Commercial Solutions for Classified approval for your PQC approach. Those paths have separate timelines and validation processes.
For Pilot Participants: Add columns tracking test environment setup, performance benchmarking results, and interoperability test outcomes. The December 31, 2027 pilot deadline means you need data, not just a plan.
Adjust the "Migration Strategy" options based on your operational model. Some teams will run hybrid crypto (quantum-safe and classical in parallel) for years. Others can't afford the performance overhead and need a flag-day cutover. Document your rationale in the notes field.
Validation Steps
Once you've populated the template:
Cross-check against your system inventory. Every system with an active Authority to Operate should appear. If it's not here, you're missing cryptographic dependencies.
Verify FIPS 140-2 certificate numbers. Go to the NIST Cryptographic Module Validation Program database and confirm your modules are still active. Expired certificates mean you're already out of compliance, and PQC migration won't fix that.
Test your deadline logic. Filter for all "2030" deadline rows. Those are your key establishment systems. Now filter for dependencies, do any of those systems rely on a Common Control Provider or external PKI that isn't on the same timeline? That's your coordination risk.
Run a tabletop exercise. Pick three high-risk systems and walk through the migration plan with the assigned owner. Can they actually execute what's documented? Do they have budget, vendor support, and test environment access? If not, your template is aspirational, not operational.
Brief your Authorizing Official. Show them the summary tab. They need to see total system count, percentage at each risk level, and how many systems hit the 2027 pilot deadline. If that number is zero, you're not participating in the pilot, and that's a decision that should be documented.
Update this template quarterly at minimum. As NIST publishes additional PQC standards and vendors release FIPS 140-3 validated modules, your "Planned PQC Algorithm" and "Status" columns will change. The executive order didn't give you a static compliance target. It gave you a moving migration program that runs through 2031.
Your job is to turn that mandate into a trackable work plan. This template is how you prove you're doing it.



