What Evidence Actually Proves a PQC Migration Is Good

Organisations talk about post-quantum cryptography (PQC) migration as if buying a vendor solution is proof of progress. It is not. Procurement is not evidence. A pilot is not evidence. A press release is not evidence.
Good PQC migration is not defined by activity. It is defined by verifiable outcomes.
The distinction matters because regulators, auditors and boards are starting to ask a harder question: not whether a migration programme exists, but whether it can prove what it has actually achieved. A programme that cannot answer that question with evidence is a programme that has not yet delivered anything.
This is the problem the Cryptographic Transformation Implementation Model was built to solve. Six maturity levels. Eight governance domains. A 36-month roadmap where the evidence bar rises at every stage. The model treats cryptographic modernisation as a governed business transformation, not a technology procurement exercise, and it defines what "good" looks like at each gate.
Here are the seven evidence criteria that separate a credible PQC migration from one that only looks credible on a slide deck.
1. You can prove you know what cryptography you run
A complete, validated cryptographic inventory is the foundation of every credible migration. That means algorithms, key lengths, libraries, protocols, endpoints, dependencies and confidentiality horizons. Not a spreadsheet assembled from memory. Not a guess extrapolated from a network scan.
If an organisation cannot produce a verified inventory that accounts for every cryptographic dependency, including embedded and inherited ones, nothing else in the programme is credible. This is where a Discovery Sprint begins: establishing what exists before deciding what to change.
The output is a Cryptographic Bill of Materials (CBOM) that maps the entire cryptographic estate, including the third-party and supply chain dependencies that procurement alone never surfaces.
2. You can prove your entropy source is strong enough
PQC algorithms consume more entropy than their classical predecessors. Larger key sizes, more complex signature operations and longer handshakes all place greater demand on the random bit generator (RBG). If the RBG is weak, misconfigured or untested, the migration is cosmetic. The cryptography may be post-quantum in name, but the randomness underneath it is not fit for purpose.
Evidence in this domain means documented test results, RBG health checks, entropy source provenance and failure mode analysis. Organisations that cannot demonstrate the strength and reliability of their entropy pipeline are building PQC on a foundation that is already compromised.
This is a structural risk that PQC readiness assessments must explicitly address. Entropy is not a background assumption. It is a testable, auditable control.
3. You can prove your architecture can carry PQC without collapsing
PQC changes the physical characteristics of cryptographic operations. Packet sizes increase. Handshake patterns change. CPU load shifts. Latency profiles move. These are not theoretical concerns. They are measurable impacts that performance testing must quantify before any production deployment.
Evidence means measured results from performance testing across gateways, proxies, load balancers, service mesh layers, API gateways and legacy nodes. It means test data under realistic load conditions, not vendor benchmarks run in isolation. An architecture that has not been stress-tested under PQC workloads is an architecture that has not been validated.
The distinction between deploying PQC and proving it works is nowhere more visible than in architecture validation. A successful handshake in a lab is not evidence of production readiness.
4. You can prove your key management is ready
PQC keys are larger, more complex and require different lifecycle controls than classical keys. Key management systems that were designed for RSA and ECC key sizes may not handle ML-KEM or ML-DSA keys without modification. Rotation logic, storage capacity, auditability and policy enforcement all require review and, in many cases, redesign.
Evidence means updated KMS policies, tested rotation logic, validated storage rules and demonstrated auditability. It means governance over the full key lifecycle, from generation through distribution, rotation and revocation to destruction. Key management readiness is a governance problem, not a marketing claim.
5. You can prove your migration does not break your business
PQC is not a cryptography project. It is an operational transformation. The scope extends far beyond algorithm replacement into every system, service and integration that depends on cryptographic operations.
Evidence means functional testing, regression testing and integration testing proving that critical systems still run, dependencies still resolve, integrations still function and user experience remains intact. Testing must cover the entire estate, not a curated subset chosen because it is likely to pass.
This is where cryptographic agility becomes a prerequisite rather than an aspiration. If the migration cannot demonstrate safe rollback, algorithm substitution and hybrid operation under test conditions, the programme has not established the operational resilience it claims.
6. You can prove your governance is real
A PQC programme without governance is a procurement exercise. It buys technology without establishing the controls needed to operate it, the accountability structures needed to sustain it or the decision rights needed to adapt it when conditions change.
Evidence means documented ownership, accountability, risk classification, decision rights, escalation paths and enforced boundaries. It means the governance controls are not just written but are actively enforced and auditable.
The Quantum Governance Compass, which underpins the Cryptographic Transformation Implementation Model, defines eight domains of governance that a migration programme must address. Partial coverage is not coverage. Governance that exists only in a policy document but is not enforced in practice is not governance.
7. You can prove your migration reduces real risk
The only reason to migrate is to reduce exposure to quantum-enabled compromise. Every other objective, including compliance, modernisation and vendor alignment, is subordinate to that purpose. If the migration does not demonstrably reduce the risk of harvest-now-decrypt-later attacks and future cryptanalytic exposure, it has not achieved its primary goal.
Evidence means mapping data value against retention periods, threat models against realistic adversary timelines and cryptographic drift against confidentiality horizons. It means quantifying the reduction in residual risk, not asserting it.
What good looks like
Not a vendor logo. Not a pilot. Not a press release. Not a slide deck.
Good PQC migration is evidence based, testing led and governance bound. Organisations that can meet these seven criteria have built something defensible. Those that cannot have built something that will not survive its first audit, its first incident or its first board question that asks for proof.
The Cryptographic Transformation Implementation Model provides the structure to achieve this. The PQC Readiness Assessment provides the starting point. The Quantum Trust Assurance Service provides the independent verification.
If you cannot prove it, you have not done it.
SITG-Consulting is an independent advisory firm specialising in post-quantum cryptography transformation, cryptographic governance and quantum risk management. Explore the full methodology, browse the Lexicon or read our Thematic Reviews and White Papers.




Comments