You Don’t Need to Be a Cryptographer to Start Preparing for Post Quantum Security
The first workforce challenge isn’t inventing a new algorithm. It’s finding every place the old ones are hiding.

Ask a security team where the organization uses cryptography and the first answers will probably be obvious: TLS certificates, VPNs, encrypted databases and authentication systems.
Then keep asking.
What about APIs? Code signing? SSH? Embedded devices? Software libraries? Cloud services? Machine identities? Third party applications?
The list gets longer rather quickly.
That matters because NIST is now telling organizations to begin migrating toward post quantum cryptography. Its first three finalized PQC standards have been available since 2024, and NIST says products, services and protocols will need updates as organizations move away from quantum vulnerable public key algorithms. NIST
The workforce problem starts before anyone changes an algorithm.
First, Find the Cryptography
NIST’s Migration to Post Quantum Cryptography project describes cryptographic inventory as a record of cryptography used across systems, applications, services, devices and data flows. It can include algorithms, protocols, keys, certificates and the components that depend on them. NIST Pages
Building that inventory requires more than a specialist who understands the mathematics behind ML-KEM or ML-DSA.
Organizations need people who can:
- Identify cryptography embedded in applications and infrastructure
- Understand TLS, SSH, VPNs, certificates and digital signatures
- Trace which business systems depend on particular cryptographic services
- Assess how long sensitive data must remain protected
- Work with application owners and technology suppliers
- Test whether replacement mechanisms remain interoperable
- Prioritize migration according to risk
Suddenly post quantum readiness looks much more like an engineering and asset visibility problem.
Migration Crosses Team Boundaries
Consider a certificate used by an internal application.
Changing its cryptography may affect the application, identity infrastructure, operating system, network components and other systems that trust the certificate. Older devices may not support the replacement. Performance characteristics may change. A third party dependency might sit somewhere in the chain.
NIST’s June work on post quantum updates for Personal Identity Verification illustrates this transition problem. Its proposed approach includes a dual stack model, retaining existing classical credentials while introducing PQC capabilities to support backward compatibility and gradual deployment. NIST
That’s migration work, not a simple software update.
The people doing it need to understand dependencies, testing and change management alongside security.
Put Cryptographic Discovery Into Training
A useful PQC exercise doesn’t have to begin with advanced mathematics.
Give learners a simulated enterprise containing web applications, certificates, VPN connections, code signing, APIs and several older systems. Ask them to build a cryptographic inventory.
Then introduce a migration requirement.
Which systems should move first? Which dependencies create risk? Where is cryptography controlled internally and where does the organization depend on another provider? What needs to be tested before anything changes?
This is where practical training becomes useful. At ITSEC Cyber & AI Academy, hands on cybersecurity environments can help professionals connect emerging subjects such as post quantum security with the infrastructure, risk and operational decisions they already encounter.
Quantum computing may be an advanced field.
Preparing an organization for it begins with a much more familiar cybersecurity skill: knowing what you actually have.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: NIST: Post Quantum Cryptography · NIST NCCoE: Migration to Post Quantum Cryptography FAQ · NIST: Post Quantum Updates to PIV Standards · ITU Academy: Quantum Communications and Post Quantum Cybersecurity, 14 September–2 October 2026
.png)


