← Latest papers
💻 computer science

Post-Quantum Cryptography Migration Readiness in Global Capability Centres: A Governance Framework for Enterprise Transition

This paper proposes the PQC-GCC Governance Framework (PGGF), a 5-layer, 6-phase model designed to guide Global Capability Centres through post-quantum cryptography migration by addressing the primary barrier of governance readiness through the integration of performance data, cross-jurisdictional compliance, and enterprise alignment standards.

Original authors: Chandrasekar Umapathy

Published 2026-07-30
📖 1 min read☕ Coffee break read

Original authors: Chandrasekar Umapathy

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Technical Summary: Post-Quantum Cryptography Migration Readiness in Global Capability Centres

Problem Statement
The finalization of NIST's Post-Quantum Cryptography (PQC) standards (FIPS 203, 204, and 205) has initiated a critical cryptographic migration. However, enterprise adoption remains low, creating a significant vulnerability for Global Capability Centres (GCCs). GCCs are offshore strategic hubs that process sensitive cross-border data across multiple regulatory jurisdictions. They face a unique "governance deficit" characterized by:

  • Cross-border dependencies: Data encrypted in one jurisdiction and transmitted to another.
  • Governance asymmetry: Migration strategies are set at headquarters but implemented by GCC teams under different regulatory constraints.
  • Regulatory duplication: Indian GCCs alone must navigate over 500 distinct legal obligations.
  • Concentrated risk: As cybersecurity delivery hubs (SOCs, Cyber Fusion Centres), a cryptographic failure in a GCC compromises global security postures.

Current frameworks fail to address the intersection of algorithm performance dependencies, cross-jurisdictional compliance, and parent-subsidiary alignment. Furthermore, the "Harvest Now, Decrypt Later" (HNDL) threat model implies that data secured under current standards is already at risk, violating "Mosca's inequality" (where the time to migrate exceeds the time until a cryptographically relevant quantum computer exists).

Methodology
The study employs a literature-based qualitative research design consisting of two primary components:

  1. Integrative Literature Review (ILR): A systematic collection and synthesis of 72 sources (38 peer-reviewed articles, 18 standards, and 16 industry reports) from 2018 onward. Sources were drawn from Scopus, IEEE Xplore, ACM Digital Library, Web of Science, SpringerLink, and regulatory bodies (NIST, NSA, CISA, etc.).
  2. Thematic Analysis: Following Braun and Clarke's six-phase protocol, the data was coded into four domains (PQC migration challenges, governance mechanisms, GCC characteristics, performance dependencies) to identify 147 initial codes. These were synthesized into five distinct governance themes.

The study explicitly avoids empirical field testing, relying instead on conceptual integration of existing literature to address the fragmented nature of PQC governance research.

Key Contributions
The paper advances cybersecurity governance research by shifting the PQC migration narrative from a purely technical transition to an enterprise governance challenge. Its primary contributions include:

  1. Identification of Five Governance Themes: Derived from the thematic analysis of 72 sources.
  2. Development of the PQC-GCC Governance Framework (PGGF): A novel 5-layer × 6-phase model specifically designed for distributed, multi-jurisdictional GCC environments.
  3. Integration of Performance Evidence: The framework uniquely incorporates empirical multi-layer performance data, treating algorithm selection as a governance decision with measurable operational consequences.
  4. Analytical Evaluation: The framework is evaluated against existing models, design principles, and NIST CSF 2.0 coverage.

Results and Framework Architecture
The study synthesizes the five identified themes into the PGGF, which consists of:

  • Five Governance Layers:

    • Layer 1 (Strategic Governance): Addresses board-level quantum risk, parent-GCC alignment, and "Time-to-React" KPIs.
    • Layer 2 (Cryptographic Asset Governance): Focuses on Cryptographic Bill of Materials (CBOM), Mosca risk classification, and cross-border HNDL assessment.
    • Layer 3 (Technical Migration Governance): Integrates performance-informed algorithm selection. Crucially, it highlights that algorithm rankings shift across protocol layers (e.g., ML-KEM/ML-DSA perform faster on x86 at the primitive level, but ARM architectures show lower end-to-end latency at TLS/VPN levels; HQC exhibits up to 100× higher execution times).
    • Layer 4 (Compliance Governance): Maps regulatory requirements across US (CNSA 2.0), EU (NIS2/DORA), UK (NCSC), and India (DPDP Act 2023).
    • Layer 5 (Talent Governance): Establishes PQC Centres of Excellence (CoE), knowledge transfer, and quantum threat communication.
  • Six Migration Phases:

    1. Initiate: Executive sponsorship and risk assessment.
    2. Discover: CBOM creation and HNDL evaluation.
    3. Strategize: Performance-informed algorithm selection.
    4. Pilot: Multi-layer Proof of Concept (PoC) benchmarking.
    5. Migrate: Phased rollout.
    6. Sustain: Ongoing crypto-agility maintenance.

Evaluation and Claims of Significance
The paper claims the PGGF is the only framework that satisfies eight critical criteria: PQC coverage, GCC specificity, multi-jurisdictional support, crypto-agility, maturity modeling, performance awareness, hardware awareness, and phased progression.

  • NIST CSF 2.0 Alignment: The framework provides complete coverage of all NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover).
  • Design Principles: It adheres to six principles including layered abstraction, evidence grounding, and context sensitivity.

Central Finding
The study concludes that governance readiness, rather than technical capability, constitutes the primary barrier to PQC migration in distributed enterprise environments. The PGGF provides the necessary architecture to bridge the gap between theoretical cryptographic advances and engineering feasibility.

Limitations and Future Work
The authors acknowledge that this is a literature-derived framework, not a field-based study. The findings are based on published sources rather than interviews or case studies, and the geographic focus on Indian GCCs may limit generalizability. Future work is proposed to include expert panel evaluations, pilot case studies across 2–3 GCCs, and sector-specific adaptations for BFSI and healthcare.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →