Introduction
The QUBIP consortium has successfully completed three practical exercises of system transition to Post-Quantum Cryptography (PQC). The project activities have validated the three Quantum-secure pilot demonstrators, i.e. Internet of Things (IoT)-based Digital Manufacturing, Internet Browsing, and Software Network Environments for Telco Operators, in relevant environments up to Technology Readiness Level (TRL) 6. The details of the building blocks designed and developed in the QUBIP project, their integration in the demonstrators and the obtained results have been presented in previous blog posts. The QUBIP consortium comprehensively addressed the entire chain of activities related to the transition to PQC and ultimately synthesised the lessons learned into a practical and replicable transition process.
This blog post proposes a replicable methodology for transitioning networks and systems to PQC and summarises the main lessons learned and the knowledge acquired through the practical implementation and deployment activities in QUBIP.
Replicable Transition Process
Figure 1 illustrates the methodology proposed by QUBIP for a replicable transition process to PQC.

Figure 1: Proposed methodology for replicable transition process to PQC.
This methodology is designed to provide structured accompanying and practical guidance to relevant industrial stakeholders aiming to initiate this process during the current transition phase and in the near future. Lessons learned during the QUBIP project suggest that big tech players are undergoing their own transition and are actively contributing to standardisation. This process can therefore be of particular benefit to large enterprises from outside the tech field and interested Small and Medium-sized Enterprises (SMEs) during their own transition in this period of rapidly evolving technologies and standards.
The Research and Development (R&D) community is developing new Quantum Computing (QC) technologies, thereby increasing the potential risk related to a future Cryptographically Relevant Quantum Computer (CRQC). At the same time, the cybersecurity community is developing and standardising PQC algorithms and working on their integration into Internet protocols. The outcomes of this process are standards and tangible assets, such as: (1) libraries implementing specific PQC algorithms, (2) libraries implementing relevant PQC-aware protocols, (3) PQC-ready secure Hardware (HW), and (4) PQC-ready agents/applications.
In accordance with this evolutionary process, the proposed methodology consists of two categories of activities that must be carried out in parallel: (i ) the continuous monitoring of relevant developments in the Research and Development and Standardisation (R&D&S) community and (ii ) the implementation of the step-by-step transition process on the target system (e.g., a pre-existing system that uses traditional cryptography).
The first category of activities involves the continuous analysis of recent developments related to QC technologies, the standardisation of PQC algorithms and their integration into Internet protocols, in order to select tangible assets for the transition of the target system. The selection process may also consider the continuous evolution of EU/National policies and recent recommendations from security agencies, as these could impose stringent requirements on the target system depending on the specific use case or application. As the outcomes of R&D&S activities evolve over time, it is important to monitor possible new developments and recommendations, and update the selection of assets and their integration into the target system if needed.
Furthermore, the assets identified by these monitoring activities are crucial to the process depicted in the lower part of Figure 1. This process aims to transition from a pre-existing system based on traditional cryptography to a PQC-ready system. Specifically, the process begins with creating an inventory of all building blocks utilising cryptography that could be vulnerable to a CRQC. Next, each building block should be migrated to PQC, integrating the relevant assets according to their specific requirements. This integration must be flexible enough to comply with a crypto-agile paradigm, facilitating future updates provided by the assets’ developers. The replaced/updated building blocks must be carefully assessed to verify that their performance meets the target Key Performance Indicators (KPIs) and acceptance criteria for the intended functionalities, and to validate their readiness for integration into a complete system prototype. Once successfully integrated into a complete system, a performance assessment must be carried out to measure all relevant metrics at the system-level and compare them with the target KPIs and acceptance criteria. It should be noted that this system-level performance assessment, as well as the previous building-block-level assessment, can potentially result in unsatisfactory outcomes and thus require a return to the previous step to select alternative PQC assets (see the two dashed arrows in the lower part of Figure 1). Conversely, once the two assessments have successfully validated the PQC building blocks and the complete system, the transition process can be considered concluded, resulting in a PQC-ready system.
Finally, the proposed methodology should be considered as a replicable process that can be applied to different target systems and their specific building blocks. Due to the continuous evolution of QC technologies and relevant PQC standards, as well as the availability of novel or updated software and hardware PQC assets, this process may need to be repeated periodically on the target system and its building blocks.
Main Lessons Learned
The most important lessons learned from the design, development, integration and validation of the three demonstrators, as well as from the other supporting activities done in QUBIP, can be summarised as it follows.
First, the Quantum-secure IoT-based Digital Manufacturing pilot revealed that, during this transition period, the key priorities are the monitoring of the compatibility of PQC standards and open-source libraries, and to ensure crypto-agility, possibly at the hardware level. We demonstrated that a hardware/software co-design methodology (e.g., for ML-DSA) and firmware updates can provide crypto-agility at the hardware level within a Secure Element (SE). For a Post-Quantum (PQ) SE, selecting a hardware platform with sufficient resources is crucial for achieving satisfactory performance, especially at high security levels. We also found that host memory constraints can affect IoT performance and scalability, particularly when deploying Post-Quantum/Traditional (PQ/T) hybrid algorithms on constrained Micro-Controller Unit (MCU)-based IoT devices. Furthermore, we proved that quantum-secure integrity verification can be implemented today using software solutions, i.e. firmware Trusted Platform Module (fTPM), Open Portable TEE (OP-TEE), overcoming the current lack of a physical PQ HW Trusted Platform Module (TPM).
Second, the Quantum-Secure Internet Browsing pilot and the achieved experimental results have confirmed that the deployment of PQC is technically feasible on current Web infrastructures, although further optimisation efforts are necessary. We have also learned that proactive participation in Standard Developing Organisation (SDO) activities is crucial to ensure that the needs and constraints of specific use cases are considered in upcoming standards. Furthermore, good cooperation with upstream maintainers has enabled us to coordinate our efforts and incorporate the necessary algorithms into the chosen open-source libraries. During this transition period, we strongly recommend the PQ/T hybrid approach as an efficient solution since, once the PQC algorithms have been properly selected, hybridisation introduces only negligible overhead. We also advise interested stakeholders to start analysing and testing the available PQC implementations as soon as possible, even if they are not yet fully mature (e.g., see Quantum-Secure Anonymous Credentials), to gain a competitive advantage when they become ready for large-scale deployment.
Third, the Quantum-Secure Software Network Environments for Telco Operators pilot has shown that the PQC transition of IP Security (IPsec) presents mainly key management and architectural challenges, rather than simply requiring the replacement of algorithms. The workflows of PQC-enabled mechanisms and orchestration components must be tightly coupled to ensure efficient and reliable operation. Nevertheless, PQC deployment is highly viable today, primarily for offline or asynchronous authentication workflows. When integrity verification of nodes in the software network is required, integrating PQC at the kernel level is a secure and efficient temporary solution for integrity verification while awaiting the availability of a physical PQ HW TPM. Furthermore, PQC/Quantum Key Distribution (QKD) hybridisation has been demonstrated and validated in a telco data centre and is suitable for integration into production-grade network environments.
Finally, the key takeaway is that, while a quantum-secure environment is an immediate technical and legal necessity, a progressive strategy based on modular and flexible architecture, crypto-agility, PQ/T hybrid solutions, and legal risk analysis is required for this transition period.

