up:: The Human & Organizational Side MOC

Post-Quantum as Forced Renewal

Post-quantum migration is usually presented as an external shock arriving at a healthy practice. It reads better, and it is more accurate, as the forced renewal of a discipline that settled into maintenance roughly 15 years ago and would have stayed there indefinitely without one. That reframing matters commercially as well as intellectually, because every argument built on a date is hostage to the date moving, and this one holds whatever the timeline does.

The short version:

  • Cryptographic practice reached a stage where the governing question became “can we demonstrate compliance” rather than “is this still the right primitive.”
  • In that stage the strengths that got the discipline here start working against it, since nobody touches working cryptography and exceptions become the governance model.
  • The migration is the occasion on which a practice that stopped self-examining resumes doing so, which explains why the deferred-hygiene list uncovered by a migration is so long.
  • It also explains why the resistance is rarely about lattices. It is the ordinary difficulty of a settled discipline being asked to reopen itself.
  • This argument survives a timeline revision, which the harvest-now case does not, and boards hear renewal more readily than they hear threat.

Think of a bridge inspection regime that has run cleanly for 20 years. Every inspection passes, every form is filed, and the process has been refined until it is efficient. The refinement is real and it is also how the regime slowly stopped asking whether the inspection criteria still match how the bridge is actually loaded. A forced re-examination is disruptive and it is the only thing that surfaces the question.

What stage is cryptographic practice actually in?

Late maturity, on any reading of an organizational life cycle. William Bridges sets out the stages in Managing Transitions as dreaming the dream, launching the venture, getting organized, making it, becoming an institution, closing in, and dying, with the claim that most organizational trouble comes from a stage’s own strengths persisting past their usefulness.

Run cryptographic practice against it:

StageWhat it looked like in cryptography
DreamingPublic-key cryptography as an academic proposition
LaunchingThe commercial web needing transport security at all
Getting organizedPKI, certificate authorities, and the trust apparatus around them
Making itUbiquitous TLS, encryption as an assumed property of the internet
Becoming an institutionStandardization, validation regimes, compliance mappings, procurement checklists
Closing inNobody touches working cryptography, exceptions are the governance model, and the operative question becomes whether compliance can be demonstrated

The closing-in stage is where most enterprise cryptographic practice has been for roughly 15 years. That is a description rather than an accusation, and the behaviors that define it were correct responses to their moment. Stability in cryptography is genuinely valuable, an exception process is a reasonable way to govern a high-risk change surface, and demonstrating compliance is a real obligation.

Source: William Bridges with Susan Bridges, Managing Transitions: Making the Most of Change, chapter 6.

Why does this explain the resistance better than fear does?

Because it locates the difficulty in the discipline rather than in the individuals.

A settled practice has spent years building the rule that working cryptography is left alone, and that rule has prevented a great deal of harm. Asking it to reopen every primitive at once is asking it to suspend its most successful governing principle, and the objections that come back are the practice defending the thing that made it trustworthy. Reading that as a confidence problem or as fear of obsolescence misses most of what is happening, and it also misses the part that is substantively correct.

It explains a second thing that puzzles migration programs. The deferred-hygiene list a migration uncovers is always longer than anyone expected, because a discipline in the closing-in stage accumulates exceptions rather than resolving them. Certificate sprawl, unowned certificate authorities, shadow cryptography, the hierarchy nobody rationalized. The migration exposes those rather than creating them, and programs frequently get blamed for problems they merely revealed.

Why is renewal a better board argument than threat?

Because a threat argument depends on a date, and every date in this field is contested.

The harvest-now case is real and it is the correct technical framing, and it carries a structural weakness in a boardroom: it rests on an estimate of when a capable machine arrives, and any revision to that estimate reopens the whole decision. A board that approved on a 2030 estimate will reasonably ask to revisit when the estimate moves, and the program spends its credibility re-arguing a timeline instead of executing.

The renewal argument has no such dependency. A practice that stopped examining its own primitives has a problem today, regardless of when anything is broken, and the remedy is the same either way: know where cryptography lives, be able to change it, and stop treating any algorithm as permanent. That case is unaffected by a timeline revision in either direction, and it converts the deliverable from an insurance policy into a capability the organization keeps.

It also lands better with the audience. Boards fund renewal and modernization routinely, and they have learned to discount threat presentations, particularly in a field saturated with countdown material.

What does this tell you about your own organization?

Which stage your cryptographic practice is in predicts what kind of program you can actually run, and it is worth diagnosing honestly before committing to one:

  • A practice still in the making-it stage migrates fast, somewhat sloppily, and tends to leave no agility behind, because speed came from individual capability rather than from structure.
  • A practice in the becoming-an-institution stage produces excellent documentation, thorough assessments, and very little movement, since its instinct is to describe the problem completely before touching anything.
  • A practice in the closing-in stage, where most regulated enterprises sit, treats the migration as a compliance object. It will produce a roadmap, an inventory, and a reporting cadence, and it will retire almost nothing unless renewal is named as the actual goal.

The diagnostic question that separates them is simple to ask and revealing to answer: at the end of this, can the estate be moved again cheaply, or will the next primitive change require another decade-long program? An organization that answers “execute this one” is running a project. An organization that answers “build the capacity” is running a renewal.

Common misconceptions

  • “This is a soft, philosophical framing.” It produces different concrete decisions. A project buys a migration, and a renewal buys crypto-agility, a maintained inventory, and an owner, which are the things that determine whether the next change costs a decade.
  • “Renewal means the threat is overstated.” The threat case stands on its own evidence. Renewal is an argument that holds even for a reader who discounts the timeline, which makes it additive rather than a replacement.
  • “Our practice is modern, so the life-cycle read does not apply.” The tell is governance rather than technology. If changing a cryptographic primitive requires an exception, and if the last review of the approved algorithm list predates the current standards, the practice is in the stage described here.
  • “Renewal means starting over.” Renewal recovers something from an earlier stage rather than advancing to a later one, and here what gets recovered is the original purpose: data stays confidential and verifiable for as long as it matters.
  • “This is just change management with a nicer name.” The claim is specific and checkable. Look at your exception queue, the date of your last algorithm-list review, and how many cryptographic changes completed in the last 5 years, per The Capacity Question.

Questions people ask

Is this argument honest, or is it a way to sell a bigger program? It is checkable, which is the test. If an organization comes out the other side able to change an algorithm as a configuration change, the renewal happened. If it comes out with a migrated estate and the same exception-driven governance, it bought a project and the next primitive change will cost the same again.

How do I open this with a board? Lead with the governing question rather than the threat: whether the organization can change a cryptographic primitive without a multi-year program, and what it costs that it currently cannot. The quantum timeline then becomes context rather than the load-bearing claim.

Does this replace the harvest-now case? It sits beside it. Use Harvest Now, Decrypt Later (HNDL) for the technical audience and for anyone asking why the deadline is real, and use renewal for the audience that funds multi-year capability.

What if leadership genuinely believes cryptography is settled? That belief is the thing to address first, and it is the same one that has to be given up before any roadmap takes, per Declaring Classical Cryptography End-of-Life.

Why 15 years specifically? It marks roughly when ubiquitous TLS, mature validation regimes, and compliance mappings made cryptographic choice feel closed for most enterprises. Treat it as an approximate marker of a stage rather than as a dated event.

Does the life-cycle model apply to a young company? Yes, and usually with a different answer. Younger organizations tend to sit in the making-it stage, where the risk is a fast migration that leaves no capability behind rather than a slow one that leaves no motion.

What is the single strongest sentence for a skeptical executive? That the reason to retire this cryptography is the same reason it was deployed, since primitives are chosen on the best public analysis available and are always understood to have a service life.

Go deeper


Everything here is the map, given freely. When your team needs the renewal case built for your board and the program structured to leave a capability behind, that’s the work I do.

Last verified 2026-08-19 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.