PQC migration is expensive. Cloud-native organizations spend far less than on-premise heavy ones. SMBs face a different burden than multinationals. This lesson gives you real numbers, a working model, and the honesty to plan with them.
Every PQC migration guide tells you what to do. Almost none of them tell you what it will cost, because the people writing them are not the people approving budgets.
This lesson does not give you a precise invoice, no one can, because costs depend on your existing infrastructure, your timeline, your staffing, and your vendors. What this lesson gives you is a working cost model with honest ranges, the factors that drive cost up or down most dramatically, and the language to have a real conversation with a CFO, board, or budget committee.
The most important thing to understand before you see the numbers: the single biggest cost driver is how much hardware-bound cryptography your organization uses. Hardware Security Modules (HSMs), smart cards, code-signing devices, and IoT hardware all require physical replacement or firmware updates, they cannot be patched with software. Organizations that live mostly in the cloud, using software-based certificates and SaaS-managed keys, face a fundamentally smaller migration burden.
An HSM is a dedicated, tamper-resistant hardware device that generates and stores cryptographic keys. It is used when software-based key storage is not secure enough, in CA root signing, banking systems, government PKI, and high-value code signing. HSMs are expensive to purchase, expensive to maintain, and expensive to replace when the algorithms they support are deprecated. They are the single largest cost item in most large-organization migrations.
Select the organization profile that most closely matches your defined scope. The model reflects estimated total cost for a complete PQC migration over a 3–5 year period, including discovery, remediation, hardware, personnel, and vendor costs.
VBG is the fictional multinational used in the Unit 4.3 roadmap exercise: a 12,000-person industrial logistics and supply chain management company with operations in 14 countries, 3 internal Certificate Authorities, 47 HSMs, 8,000 managed devices, and significant OT/IoT infrastructure. VBG represents the most complex migration scenario in the course.
| Cost Category | Low Estimate | High Estimate | Primary Driver |
|---|---|---|---|
| Cryptographic discovery and CBOM build | $1.2M | $3.5M | Scope of systems; OT environments |
| HSM replacement (47 devices + deployment) | $8M | $18M | Per-unit cost $120K–$200K fully installed |
| CA hierarchy redesign and rebuild | $3M | $7M | Complexity of existing hierarchy |
| Certificate lifecycle management (CLM) platform upgrade | $2M | $5M | Scale of certificate inventory |
| Network protocol migration (TLS, VPN, DNSSEC) | $4M | $9M | Number of endpoints and edge locations |
| IoT / OT device firmware or hardware replacement | $6M | $18M | Device count; vendor support availability |
| Vendor and supply chain migration (software, APIs) | $3M | $8M | Contract renegotiation; vendor readiness |
| Personnel training and upskilling | $1.5M | $4M | Roles requiring recertification |
| Hybrid certificate transition period (parallel ops) | $2M | $6M | Duration of transition window |
| Audit, compliance documentation, evidence packages | $0.8M | $2M | Regulatory environment complexity |
| TOTAL ESTIMATED RANGE | $31.5M | $79.5M | Midpoint ~$55M over 3–5 years |
⚠ These estimates assume a phased migration with no major regulatory deadline forcing compression. A compressed timeline (1–2 years) increases costs by 40–80% due to parallel operations, accelerated vendor contracts, and staff augmentation.
500–5,000 employees. Mix of cloud and on-premise infrastructure. Likely 1–3 internal or outsourced CAs. 2–8 HSMs (or none). Regulated industry (healthcare, finance, legal) or unregulated (tech, professional services). Active CLM platform.
| Cost Category | Low Estimate | High Estimate | Notes |
|---|---|---|---|
| Cryptographic discovery and CBOM | $120K | $400K | Tooling + staff time |
| HSM replacement (2–8 devices) | $300K | $1.5M | If HSMs exist; zero if cloud KMS |
| CA hierarchy update | $200K | $600K | Depends on number of CAs |
| CLM platform upgrade | $80K | $300K | Vendor pricing varies |
| Network migration (TLS, VPN) | $150K | $700K | Scales with endpoint count |
| Personnel training | $50K | $200K | Courses + staff time |
| Vendor and application migration | $100K | $500K | SaaS vendor readiness varies |
| TOTAL ESTIMATED RANGE | $1M | $4.2M | Midpoint ~$2.5M over 3–4 years |
Regulated industries (healthcare under HIPAA, finance under DORA, federal contractors under CMMC) face an additional 20–40% overhead for compliance documentation and third-party audit requirements.
10–500 employees. Cloud-first or cloud-hybrid. Certificate management through Microsoft 365, Let's Encrypt, or a basic CLM subscription. No HSMs. Limited internal IT staff. PKI decisions made by a generalist IT person or outsourced.
| Cost Category | Low Estimate | High Estimate | Notes |
|---|---|---|---|
| Cryptographic discovery (light CBOM) | $5K | $25K | Mostly staff time; basic tooling |
| HSM | $0 | $0 | Typically none: use cloud KMS |
| Certificate management platform | $3K/yr | $15K/yr | SaaS CLM subscription |
| Web/email certificate migration | $2K | $10K | Let's Encrypt handles most automatically |
| VPN and remote access migration | $5K | $30K | Vendor/ISP-dependent |
| Microsoft 365 / Google Workspace | $0 | $0 | Platform vendor migrates on their timeline |
| Staff awareness training | $2K | $8K | This course covers this category |
| External consultant (if needed) | $10K | $50K | Optional; for regulated SMBs |
| TOTAL ESTIMATED RANGE | $27K | $138K | Midpoint ~$80K over 2–3 years |
The SMB number is dramatically lower because the most expensive items: HSMs and CA hierarchy redesign, typically do not apply. Most SMB cryptographic exposure migrates when the cloud vendors migrate. Your primary cost is awareness, planning, and vendor selection.
No on-premise infrastructure. All compute in public cloud (AWS, Azure, GCP). Certificates managed by cloud provider KMS. No HSMs. No internal CA. Certificate lifecycle managed by platform or Let's Encrypt automation.
| What Migrates | Who Does It | Your Cost |
|---|---|---|
| TLS certificates (AWS ACM, Azure Key Vault) | Cloud provider | $0: happens when provider updates |
| SSH keys for server access | Your team | $5K–$20K (staff time) |
| Code signing keys | Your team + signing service | $5K–$30K |
| API authentication (JWT, OAuth) | Library vendor + your team | $5K–$40K (dev time) |
| VPN / Zero Trust platform | Vendor | Covered by subscription upgrade |
| Training and awareness | This course | Course cost |
| TOTAL ESTIMATED RANGE | $15K–$90K (mostly staff time) |
Cloud-native organizations have the lightest migration burden of any category. Most of the heavy cryptographic lifting is done by cloud providers on their own timelines. Your migration work is primarily: (1) auditing what your applications do that falls outside the cloud provider's scope, (2) tracking vendor library updates, and (3) training the team to recognize when a dependency is not yet migrated.
Two organizations of the same size can face wildly different migration costs. These five factors explain most of that variance:
Every HSM, smart card reader, physical token, or IoT device running a fixed cryptographic algorithm is a hardware replacement problem, not a software update. Hardware cannot be "patched" to support a new algorithm after manufacture unless the vendor specifically provides a firmware upgrade path. Most HSMs manufactured before 2023 do not support ML-KEM or ML-DSA natively. Budget accordingly.
Your migration cannot move faster than your slowest vendor. If you use a payroll system, ERP, or clinical software that relies on RSA and has no published PQC roadmap, you either wait for them to migrate or you build an encryption gateway, which is expensive. Understanding your vendor readiness map (started in the Unit 3 CBOM exercise) is prerequisites to cost planning.
A phased 5-year migration costs significantly less than a compressed 18-month migration driven by a regulatory deadline or a breach response. Parallel operations, running classical and post-quantum systems simultaneously, double operational costs for the duration of the transition window. The longer the parallel period, the higher the cost.
Organizations with thousands of certificates that are manually tracked in spreadsheets face a proportionally higher migration cost than those with an automated CLM platform. The first cost of migration for these organizations is often buying and deploying a CLM platform, before any PQC-specific work begins.
Federal contractors (CMMC), healthcare organizations (HIPAA), EU-regulated businesses (DORA, NIS2), and financial institutions (DORA, PCI-DSS v4) face mandatory timelines, third-party audit requirements, and evidence documentation obligations that add 20–40% to base migration costs. Unregulated private companies have more flexibility in pacing.
Cost literacy is part of your professional value. When you engage with PKIC working groups or consult independently, clients will ask you "what will this cost us?" Being able to identify the five cost drivers, hardware, vendor readiness, timeline, certificate volume, regulation, and apply them to a specific context makes you more useful than someone who can only recite algorithm names.
Your migration cost is probably between $30K and $150K, concentrated in staff time and vendor selection rather than hardware. The most important things you can do right now are: (1) confirm whether your software vendors have published PQC migration timelines, and (2) make sure your web hosting, email, and VPN providers are using CLM that will handle the certificate transition automatically. For most SMBs, the vendor ecosystem does the heavy work, your job is to know when they do it.
When building a business case for migration budget, lead with the hardware inventory. The number of HSMs, the number of non-upgradeable devices, and the number of systems with hard-coded algorithm dependencies are your highest-dollar line items. Quantifying those three things before you walk into a budget conversation gives your estimate credibility. "We have 4 HSMs at $150K each to replace" is a number a CFO can react to. "PQC migration will be expensive" is not.
These cost ranges are directionally accurate, not precise. Four things make precise estimation difficult:
Present these numbers to leadership as order-of-magnitude estimates to frame the resource conversation, not as numbers to put into a capital expenditure proposal. The purpose is to establish that migration is a real cost, that it scales with infrastructure complexity, and that planning now is less expensive than compressing later.
Three questions. Select the best answer and check your thinking.