Translating Post-Quantum Cryptography Roadmaps into an Actionable SME Migration Framework
PDF
HTML

Keywords

Post-quantum cryptography
SME cybersecurity
quantum-safe migration
cryptographic inventory
crypto-agility
standards adoption
text analytics
LLM-assisted research

Abstract

Small and medium-sized enterprises (SMEs) face the same quantum-era cryptographic exposure as large organisations, but they often lack the specialised security teams, governance maturity, asset visibility, and implementation budgets assumed by most post-quantum cryptography (PQC) roadmaps developed for governments, public institutions, and large enterprises. This paper addresses this challenge by adopting a structured research process to develop an evidence-based, SME-specific PQC migration framework that translates practical insights from existing roadmaps, standards, practitioner publications, and academic studies into structured actionable guidance. The framework also identifies activities that extend beyond typical SME capabilities into the operational domain of larger enterprises. The research study uses a human-supervised, large-language-model (LLM)-assisted text-analytics workflow based on a comprehensive multi-criteria decision analysis (MCDA). An initial corpus of 52 documents was evaluated for SME relevance, practical usefulness, clarity, and coverage. Seventeen high-value documents were selected for deeper analysis, producing 556 source-linked migration insights. These insights were validated, consolidated, and prioritised into 73 decision-oriented actions organised across four phases: Prepare, Assess, Implement, and Govern. The results show that PQC migration is not simply an algorithm-replacement exercise; it is an organisational transformation process requiring governance, cryptographic visibility, vendor coordination, phased implementation, and continuous monitoring. The contribution is both practical and methodological: a lifecycle-based migration model for SMEs and larger enterprises, and a replicable evidence-to-action analytical process for converting dispersed technical guidance into context-specific organisational action.

https://doi.org/10.13052/qitj2795-0492.215
PDF
HTML

References

National Institute of Standards and Technology, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard, Federal Information Processing Standards Publication 203, U.S. Department of Commerce, 2024. DOI: https://doi.org/10.6028/NIST.FIPS.203.

National Institute of Standards and Technology, FIPS 204: Module-Lattice-Based Digital Signature Standard, Federal Information Processing Standards Publication 204, U.S. Department of Commerce, 2024. DOI: https://doi.org/10.6028/NIST.FIPS.204.

National Institute of Standards and Technology, FIPS 205: Stateless Hash-Based Digital Signature Standard, Federal Information Processing Standards Publication 205, U.S. Department of Commerce, 2024. DOI: https://doi.org/10.6028/NIST.FIPS.205.

Canadian Centre for Cyber Security, Roadmap for the Migration to Post-Quantum Cryptography for the Government of Canada (ITSM.40.001), Communications Security Establishment Canada, June 2025. [Online]. Available: https://www.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001.

Post-Quantum Cryptography Coalition, Post-Quantum Cryptography Migration Roadmap, May 2025. [Online]. Available: https://pqcc.org/wp-content/uploads/2025/05/PQC-Migration-Roadmap-PQCC-2.pdf.

NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, European Commission, June 2025. [Online]. Available: https://securitydelta.nl/media/com_hsd/report/750/document/Roadmap-on-postquantum-cryptography-PzBJxNUYyeuEdVUacWL696DofZQ-117507.pdf.

Australian Signals Directorate, Australian Cyber Security Centre, Planning for Post-Quantum Cryptography, September 2025. Available: https://www.cyber.gov.au/sites/default/files/2025-09/Planning%20for%20post-quantum%20cryptography%20%28September%202025%29.pdf.

DigiCert, The Ultimate Guide to Post-Quantum Cryptography, DigiCert. [Online]. Available: https://www.digicert.com/content/dam/digicert/pdfs/guide/ultimate-guide-to-pqc.pdf.

NCS and IBM, Managing Risks and Opportunities for Quantum-Safe Development: IBM-NCS Quantum Security, Version 1.0, 2024. [Online]. Available: https://www.ncs.co/dam/jcr:81bb243e-0cdd-4c04-92e2-d110c01fa0e8/IBM_NCS_Quantum_Security_v1.0.pdf.

Cryptomathic, A Banker’s Guide to Quantum-Safe Cryptography, Part 3: Roadmap to PQC Migration for Financial Institutions. [Online]. Available: https://www.cryptomathic.com/a-bankers-guide-to-quantum-safe-cryptography-part-3-roadmap-to-pqc-migration-for-financial-institutions-cryptomathic.

AIVD, CWI, and TNO, The PQC Migration Handbook: Guidelines for Migrating to Post-Quantum Cryptography, 2nd ed., December 2024. [Online]. Available: https://publications.tno.nl/publication/34643386/fXcPVHsX/TNO-2024-pqc-en.pdf.

World Economic Forum, Transitioning to a Quantum-Secure Economy, September 2022. [Online]. Available: https://www.weforum.org/publications/transitioning-to-a-quantum-secure-economy/.

Canadian Forum for Digital Infrastructure Resilience, Canadian National Quantum-Readiness: Best Practices and Guidelines, July 7, 2021. [Online]. Available: https://quantum-safe.ca/wp-content/uploads/2022/01/CFDIR-Prati-Tech-Quant-EN.pdf.

Canadian Centre for Cyber Security, Preparing Your Organization for the Quantum Threat to Cryptography (ITSAP.00.017), February 2025. [Online]. Available: https://www.cyber.gc.ca/en/guidance/preparing-your-organization-quantum-threat-cryptography-itsap00017.

D. Joseph, R. Misoczki, M. Manzano, J. Tricot, F. D. Pinuaga, O. Lacombe, S. Leichenauer, J. Hidary, P. Venables, and R. Hansen, “Transitioning organisations to post-quantum cryptography,” Nature, vol. 605, no. 7909, pp. 237–243, 2022. https://info.quintessencelabs.com/hubfs/2022-05-11_Nature_Transitioning%20organizations%20to%20post-quantum%20cryptography%20(1).pdf.

N. von Nethen, A. Wiesmaier, N. Alnahawi, and J. Henrich, “PMMP-PQC Migration Management Process,” in Proceedings of the 2024 European Interdisciplinary Cybersecurity Conference, pp. 144–154, 2024. https://arxiv.org/pdf/2301.04491.

INSECM, “Preparing for Post-Quantum Cryptography: Impacts on the Classical Cybersecurity Operations of SMEs,” April 3, 2025. [Online]. Available: https://insecm.ca/en/newsletter/preparing-for-post-quantum-cryptography-pqc-impacts-on-the-classical-cybersecurity-operations-of-smes/.

I. Kong, M. Janssen, and N. Bharosa, “Realizing quantum-safe information sharing: Implementation and adoption challenges and policy recommendations for quantumsafe transitions,” Government Information Quarterly, vol. 41, no. 1, article 101884, 2024. DOI: https://doi.org/10.1016/j.giq.2023.101884.

K. C. Dekkaki, I. Tasic, and M. Cano, “Exploring post-quantum cryptography: A review and directions for the transition process,” Technologies, vol. 12, no. 12, article 241, 2024. DOI: https://doi.org/10.3390/technologies12120241.

D. Chawla and P. S. Mehra, “A roadmap from classical cryptography to post-quantum resistant cryptography for 5G-enabled IoT: Challenges, opportunities and solutions,” Internet of Things, vol. 24, article 100950, 2023. DOI: https://doi.org/10.1016/j.iot.2023.100950.

D. Ott, D. Moreau, and M. Gaur, “Planning for cryptographic readiness in an era of quantum computing advancement,” in Proceedings of the International Conference on Information Systems Security and Privacy, pp. 491–498, 2022. https://www.scitepress.org/PublishedPapers/2022/108860/pdf/index.html.

S. A. Käppler and B. Schneider, “Post-Quantum Cryptography: An Introductory Overview and Implementation Challenges of Quantum-Resistant Algorithms,” in Proceedings of the Society 5.0 Conference 2022-Integrating Digital World and Real World to Resolve Challenges in Business and Society, EPiC Series in Computing, vol. 84, pp. 61–71, 2022. Available: https://irf.fhnw.ch/server/api/core/bitstreams/37e2bb44-2600-4e6a-bfe6-0571089b7253/content.

N. Abdelkafi, R. Bekkers, R. Bolla, A. Rodriguez-Ascaso, and M. Wetterwald, Understanding ICT Standardisation: Principles and Practice, European Telecommunications Standards Institute, 2021. [Online]. Available: https://acrobat.adobe.com/id/urn:aaid:sc:EU:ea05cb13-45ab-4f40-80cc-e82a263817ff.

M.-C. Idris and A. Durmuşoğlu, “Innovation management systems and standards: A systematic literature review and guidance for future research,” Sustainability, vol. 13, no. 15, article 8151, 2021. DOI: https://doi.org/10.3390/su13158151.

G. van de Kaa, “Standards adoption: A comprehensive multidisciplinary review,” Heliyon, vol. 9, no. 8, article e19203, 2023. DOI: https://doi.org/10.1016/j.heliyon.2023.e19203.

N. Schwitter, “Using large language models for preprocessing and information extraction from unstructured text: A proof-of-concept application in the social sciences,” Methodological Innovations, vol. 18, no. 1, pp. 61–65, 2025. DOI: https://doi.org/10.1177/20597991251313876.

D. Xu, W. Chen, W. Peng, C. Zhang, T. Xu, X. Zhao, X. Wu, Y. Zheng, Y. Wang, and E. Chen, “Large language models for generative information extraction: A survey,” Frontiers of Computer Science, vol. 18, article 186357, 2024. DOI: https://doi.org/10.1007/s11704-024-40555-y.

Downloads

Download data is not yet available.