Unit 4 · Lesson 4.3
45 minutes PQCMM 3 → 4 Migration planning

The 5-year corporate migration roadmap, year by year

Abstract timelines are easy to dismiss. This lesson makes the migration concrete using Vantage Bridge Group (VBG), a fictional multinational modeled on the PKIC Amsterdam blueprint, as the reference organization. The five-year roadmap is not a theoretical exercise. It is a project plan, with workstreams, deliverables, dependencies, and the realistic problems that arise at each stage. Use it as a template for your own organization.
Unit 4 progress
By the end of this lesson you will be able to

Part 1 — The reference organization: VBG
Vantage Bridge Group (VBG) is a fictional multinational used throughout this unit as the migration reference case. It is sized to represent the upper-middle range of enterprise complexity: large enough to have real hardware and vendor dependencies, but not so large that the roadmap becomes inapplicable to most learners.
Vantage Bridge Group (VBG)
Reference organization: PKIC Amsterdam migration blueprint
Employees
12,000 across 14 countries
Internal CA hierarchy
2 root CAs, 6 intermediate CAs
Active certificates
~47,000 (TLS, code signing, client, device)
HSMs deployed
14 (8 CA keys, 6 application keys)
IoT / OT devices
~3,200 (manufacturing / logistics floor)
VPN endpoints
340 (IPsec / SSL VPN mix)
Sector
Industrial logistics and supply chain management, CMMC adjacent
Effective deadline
2032 (sector + internal PKI complexity)

Part 2 — Year by year: the five-phase roadmap
Select each year to see the workstreams, key milestones, and deliverables. The roadmap assumes a 2025 start date, adjust for your organization's actual starting point.

Part 3 — The critical path
Not all tasks are equal. The critical path items are the tasks that gate everything else, if they slip, the entire roadmap slips. For VBG, and for most organizations, these are the five critical path items.
1
CBOM completion: gates all migration prioritization
You cannot sequence a migration you have not inventoried. CBOM discovery is the prerequisite for every other Year 2 and Year 3 activity. Slippage here cascades across the entire roadmap.
2
HSM PQC firmware availability: gates root CA migration
Root CA private keys are HSM-bound. The root CA cannot migrate until the HSM has been updated or replaced to support ML-DSA key generation. This is vendor-dependent and has the longest lead time in the hardware stream.
3
Trust store distribution: gates intermediate CA migration
The new root CA certificate must reach all managed endpoints before intermediate CAs can begin issuing new certificates. MDM/GPO rollout to all devices is slower than expected in most enterprises.
4
Vendor PQC readiness: gates application migration
Applications that depend on third-party libraries or vendor software cannot migrate until the vendor supports PQC. Some vendor timelines are 2–3 years from first contact to supported release.
5
CLM automation: enables certificate replacement at scale
Manually replacing 47,000 certificates is not operationally feasible. CLM automation must be deployed and tested before the mass certificate replacement phase in Years 3–4.
C For IT professionals: the VBG roadmap is a template, not a prescription. Your version will differ in duration and sequence depending on your CBOM size, your HSM vendor's timeline, and your CLM automation maturity. The critical path items above are nearly universal, they apply regardless of organization size. The single most important first action you can take from this lesson is to start your CBOM discovery if you have not already. Everything else waits for it.
B For SMB decision-makers: a five-year roadmap at VBG's scale costs $45–85M. Your organization's equivalent is dramatically smaller, most SMB migrations are primarily vendor-driven (your cloud provider, CA, and software vendors handle the infrastructure layer) with internal effort focused on internal PKI, VPN, and any proprietary systems. The Year 1 discovery exercise still applies: inventory every system that uses cryptography and check each vendor's PQC roadmap.
Regulatory deadlines as migration forcing functions For multinational organizations, regulatory compliance deadlines are often the most effective forcing function for migration budget approval, more effective than technical arguments alone. VBG's European operations create NIS2 supply chain obligations and, for financial sector clients, DORA ICT third-party risk assessment requirements. VBG's Canadian government contracts may create supply chain obligations flowing from ITSM.40.001. The practical approach: use regulatory deadlines as the executive briefing anchor. "We must demonstrate PQC-ready cryptographic practices to retain EU and Canadian government contracts" is a more actionable statement for a CFO than "NIST deprecated RSA in 2030."

Part 4 — The migration checklist tracker
The items below represent the full corporate migration checklist for VBG, mapped to the year in which they are addressed. Check off items as you learn them, this becomes the seed of your Deliverable B annotated checklist.
VBG corporate migration checklist
Primary source references
CCCS ITSM.40.001 (June 2025)
CCCS SPIN (October 2025)
EU NIS2 Directive (2022/2555)
EU DORA Regulation (2022/2554)
G7 G7 CEG PQC Roadmap (January 2026)

Comprehension check
Question 1 of 3
Why is Year 1 of the VBG migration roadmap focused on discovery and assessment rather than deployment of any PQC algorithms?
Question 2 of 3
HSM PQC firmware availability is listed as a critical path item that gates root CA migration. What is the consequence if an HSM vendor's PQC firmware is delayed by 18 months?
Question 3 of 3
At what point in the VBG roadmap does mass certificate replacement begin, and what prerequisite must be met first?