up:: The Human & Organizational Side MOC
Operating Through a Long Hybrid Period
The hybrid period is the years an organization spends running classical and post-quantum cryptography side by side, and for most large estates it will run a decade or more. Programs treat it as an awkward interval between two real states, to be shortened and survived. It is genuinely transitional by construction, since the classical half is exactly what a quantum computer breaks, and pure post-quantum is the destination in every published position. What programs get wrong is the duration, and an interval planned as brief and lived as a decade goes ungoverned for years.
The short version:
- Hybrid is transitional by construction and long-lived in practice, and both halves of that are true. Its classical component is precisely what a quantum computer breaks, so pure post-quantum is the destination in every published regulator position. The duration is what gets underestimated.
- Because it runs for years rather than months, it has to be governed as an operating posture for its own lifetime, rather than left ungoverned on the assumption that it is about to end.
- The in-between period carries real costs that programs rarely name out loud: doubled key material, two failure surfaces, monitoring built for one of them, and a security posture that is temporarily worse than either endpoint.
- People supply their own story for an unexplained period of difficulty, and the ones they generate are corrosive. Give the period a name and an honest account of its length.
- Temporary means having an end condition and a review cadence, rather than ending soon. A 10 year arrangement with a defined sunset and annual re-authorization is genuinely temporary. A 2 year one nobody revisits has already become permanent.
- The anchor is whatever you declare is deliberately holding still: key management discipline, two-person integrity, chain of custody, the standard by which primitives get chosen.
Think of a hospital running two record systems during a records migration. Everyone understands the destination and everyone can see the cost of the crossing: staff check both systems, some information exists in one and not the other, and for a period the risk of a missed record is higher than it was before the project started. What determines whether the staff hold together is whether leadership said in advance how long the double-running would last, what was expected to get worse, and which parts of clinical practice were unchanged throughout.
Why is the hybrid period harder than either endpoint?
Because the difficulty is structural, and it lands on the people who were most competent before.
Running two cryptographic stacks doubles the configuration surface, creates negotiation and downgrade logic that did not previously exist, and puts a less-exercised code path into production next to a well-worn one. Monitoring was built for the old stack. When something breaks, nobody can say quickly which side broke it, including the person who could have answered that instantly 3 years ago. Everyone can see that, including them.
This is where programs lose their most senior practitioners, and the loss is the expensive kind. The person with options finds an ambiguous period clarifying rather than distressing, so the people who leave are the ones who could go, and they are frequently the ones carrying the undocumented knowledge of how the estate is really wired. Losing them slows a migration in the short term and can remove the possibility of completing it at all.
The addition, which the field almost never says out loud: a partially migrated estate is a measurably worse security posture than either the classical estate or the post-quantum one. Implementation immaturity, misconfiguration, downgrade paths, and two code paths where one is less tested all point the same way. Everyone in an engineering seat already knows it, which makes saying it nearly free in credibility terms and valuable in trust terms.
What story are people telling themselves about hybrid?
One of two, and both are corrosive, because a period of sustained difficulty with no explanation attached does not stay unexplained. People fill the gap.
The first is that hybrid is a box being ticked for an event that will never arrive, so the work is going through the motions. The second is darker and more common among the technically strong: that hybrid is what you do while waiting to find out you were already harvested, per harvest now, decrypt later. Both stories are demoralizing and both are available to anyone who was given a roadmap and no account of the crossing.
The replacement has to be true, which rules out the reassuring version. Telling people the disorientation is temporary when it will run a decade spends the credibility needed for everything else. What is both true and durable is that hybrid is a deliberate hedge being run for as long as it takes to retire the classical side safely, and that the ability to run two stacks and swap either one is a capability worth having in its own right, since it is the same capability the next primitive change will need. That account survives a decade because it does not depend on a date, and it stays honest because it keeps pure post-quantum as the destination.
How do you keep a temporary arrangement from becoming permanent?
By attaching an end condition and a review cadence at the moment you create it, rather than relying on the arrangement being short.
This is the reframe that makes a decade-long crossing manageable, and it is worth stating plainly because the usual instinct is the opposite. Duration is the wrong test. An arrangement is genuinely temporary when someone owns it and something forces a decision about it on a schedule. An arrangement that everyone privately knows is provisional and nobody has labeled becomes permanent by default, and other things get built on top of it.
Cryptographic practice has an advantage here that most disciplines lack, and it comes from key management rather than from change management. Key material already carries effective and supersession dates at issue, so the habit of building expiry into an arrangement at creation is native to the profession. Extending it to hybrid architecture reads as rigor.
| Temporary arrangement | The end condition to attach at creation |
|---|---|
| A migration exception to certificate lifetime policy | Named systems, an expiry date, and a person who renews or closes it |
| Temporary authority for a migration team | Defined scope and a stated end, so the authority does not quietly become a permanent function |
| Dual-stack monitoring and failure attribution | Review cadence tied to each protocol’s crossing, retired when that protocol’s classical path is turned off |
| Interim audit evidence formats for a partly migrated estate | Superseded when the estate’s reporting reaches steady state, with a named owner for the transition |
| The hybrid path for a given protocol | The date and condition on which the classical side is turned off, decided when hybrid is enabled |
What is deliberately not changing?
This is the question that makes an indefinite period survivable, and it is the one nobody asks.
In a crossing with a known destination, the stability people hold onto is the destination itself. With no arrival date available, the anchor has to be something you explicitly declare is holding still while the primitives move. In cryptographic practice that list is unusually strong and it is worth naming out loud: key management discipline, two-person integrity, chain of custody, the refusal to invent your own construction, and the standard by which any primitive gets chosen, which is public analysis over time rather than vendor assurance.
The discipline is the constant and the algorithms are the variable. Every practice on that list applies identically to ML-KEM and to RSA, and none of it depreciates when a parameter set changes. Naming it converts an open-ended churn into something a professional can stand on, and it gives the most skeptical people in the room a way to be right, since their caution about new primitives is the same caution that made the old ones trustworthy.
It also answers the identity problem underneath the whole period. The durable expertise is running a migrating estate: knowing where cryptography lives, being able to move it, and treating no primitive as permanent. Anyone building an identity on mastery of a specific successor algorithm has bought the asset that will depreciate next. Plenty of people will learn the new primitives from documentation, and very few can move a real estate.
What do you actually do about it?
- Say what will get worse, with bounds. Named areas, expected magnitude, stated duration. A vague warning that productivity may be affected gives a sponsor nothing to defend, while a specific and bounded forecast demonstrates competence that a reassuring pitch cannot. Agree it before the work starts, because after the first missed quarter it is unobtainable.
- Take migration work off the incident scorecard. An engineer who touches working cryptography and causes an incident absorbs the hit, and one who leaves it alone absorbs nothing, regardless of the risk they are carrying. Until that is carved out, every encouragement to move is contradicted by the number that determines their review.
- Constitute the group, because it does not exist yet. Cryptographic expertise in most enterprises is a scattering of individuals who are each the only person in their unit who understands their corner, and many have never met. A standing cross-unit forum with real decision rights and shared incident review across the hybrid estate builds an identity that does not depend on individual competence, which is exactly what is unavailable to people during a crossing.
- Make a completed crossing mean something turned off. Endpoint counts and percentage-of-traffic figures climb early, are dominated by the easy estate, and prove nothing about whether the organization can finish. One protocol in one environment, fully crossed with the classical path decommissioned, changes what people believe is possible in a way no status report does.
- Use the open estate for the hygiene you have deferred for years. Certificate lifetimes, unowned certificate authorities, shadow cryptography, and pulling crypto out of application code behind an abstraction all become affordable while the code is already being modified, and most of it was never post-quantum work at all.
Common misconceptions
- “Hybrid is a stopgap, so it needs no governance.” Pure post-quantum is genuinely the destination, and the stopgap will run for a decade across most of a large estate. Planning it as a brief interval is what produces arrangements that go unowned for years.
- “The crossing is safer than where we started.” A partly migrated estate carries more configuration surface, more code paths, and less mature implementations. It gets safer at the far end, and the middle deserves an honest account.
- “We can shorten it by moving faster.” Some of the length is your annual capacity for cryptographic change, some of it is vendor timelines you do not control, per Vendor-Controlled Crypto Surfaces, and some of it is embedded hardware that cannot be updated at all.
- “Temporary means we will get rid of it soon.” Temporary means an end condition, an owner, and a review date. Without those three, the arrangement is permanent on the day it is created.
- “Our people will adapt.” They adapt when the period has a name, an honest length, and a stated list of what is holding still. Left unexplained, the strongest of them adapt by leaving.
Questions people ask
How long does the hybrid period actually last? For a large regulated estate, plan on a decade for the bulk of it and accept that some embedded and long-lived segments will still be classical after that. Anyone offering a confident total is selling something.
Is there an arrival at all? There is a change of state rather than an arrival: the point where changing an algorithm is a configuration change instead of a program. That is the destination worth naming, and it does not require any primitive to be final.
Does this mean our security is worse for years? In the migrating segments, temporarily and manageably, and the alternative is an estate whose confidentiality expires on a date you cannot predict. The framing is a bounded and monitored crossing against an unbounded and silent exposure.
How do we keep senior people through it? Give them authorship rather than reassurance. The person losing the most competence is the right person to own the new standard, write the migration patterns, or run adversarial review of the hybrid design, and skepticism about new primitives is the qualification for that last role.
What do we tell the board? That the organization is funding a crossing with a stated cost and a defined capability at the end, rather than a project with a completion date. A board that believes it bought a project will read year 3 as failure.
Should we wait for the standards to settle instead? The selections are made and the standards are published. Waiting is now a posture rather than a technical position, and it converts an engineering problem into an accumulating one, because data captured today is judged by tomorrow’s capability.
How do we know the period is going well? Count what has been turned off, not what has been turned on. Decommissioning is the measure that resists inflation.
Go deeper
- Declaring Classical Cryptography End-of-Life: the decision that has to precede the crossing, and why programs stall without it.
- Change Management for Cryptographic Migration: getting people moving once the period has been named.
- Hybrid Cryptography: the technical construction underneath all of this.
- Crypto-Agility: the capability the crossing is meant to leave behind.
Everything here is the map, given freely. When your team needs the hybrid period designed and governed against your actual estate, that’s the work I do.
Last verified 2026-08-17 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.