In Episode 5, I discussed why governance and ownership are where many post-quantum cryptography programs stall. Once you have clear answers to who approves, performs, validates, and accepts risk, the next question is practical: how do you manage the actual migration work over time?
You don't do it with a static inventory report. You do it with an operational migration backlog.
Inventory is static; migration is dynamic
A cryptographic inventory tells you what exists at a specific moment in time. It is a critical baseline, but it is not an execution plan. Environments change, new certificates are issued, applications are updated, and vendor roadmaps shift.
If you treat your inventory as a one-time project list, it becomes outdated almost immediately. A practical PQC program converts discovery data into an active backlog that reflects the current state of every asset in your environment.
The 5 asset dispositions
To turn visibility into execution, every cryptographic asset in your inventory needs an explicit disposition. In practice, assets fall into one of five categories:
1. Ready to Migrate: Algorithms, keys, or certificates where a PQC-compliant drop-in replacement exists today and can be deployed with minimal testing risk.
2. Requires Application/Code Changes: Systems where hardcoded cryptographic libraries, legacy protocols, or custom code must be refactored before new algorithms can be supported.
3. Waiting on Vendor Support: Third-party software, appliances, or SaaS platforms where PQC capability depends entirely on a commercial vendor's release roadmap.
4. Risk Accepted (Temporary/Permanent): Legacy or low-exposure assets where migration cost or disruption outweighs near-term risk, formally documented with an expiration date.
5. Escalate Priority: High-exposure or critical-path assets where blockers (like vendor delays or missing code owners) threaten overall compliance deadlines.
Managing PQC as an ongoing operational queue
Categorizing assets this way shifts the team's mindset from "we have 50,000 certificates to fix" to "we have 1,200 assets ready to migrate this quarter, 3,000 waiting on vendor updates, and 45 high-priority code refactoring tasks."
This structure allows security, PKI, and application teams to work from a single prioritized queue rather than competing spreadsheets.
If you want to evaluate how your current cryptographic inventory maps to these operational dispositions, explore our PQC Readiness solution.
The PQC Playbook Series
Previous: Episode 5: Who Owns PQC Migration? Why Governance Is the Hardest Part


