Quick answer: A PQC program needs ten defined roles with explicit RACI (Responsible, Accountable, Consulted, Informed) assignments: accountable executive, crypto/PQC program lead, PKI team, application teams, infrastructure and network teams, procurement, legal and compliance, risk management, vendor management, and internal audit. The most common governance failure is not missing roles, most organizations can name people who could plausibly fill each one, it’s the absence of explicit RACI assignment for specific decisions, which leaves genuinely important calls, like algorithm parameter selection or migration sequencing, without a clear decision owner until a deadline forces an ad hoc one. This guide defines the roles and maps RACI across the program’s key decision points.
Most PQC roadmap content mentions “clear ownership” as a success factor without defining what that ownership structure actually looks like. This guide is the structure: specific roles, and specific RACI assignments across the decisions a real program has to make.
Key Takeaways
- Ten roles, spanning executive sponsorship, technical execution, and organizational governance, cover the full scope a PQC program actually touches.
- The most common governance gap is not an unfilled role but the absence of explicit RACI assignment for specific decisions, leaving them without a clear owner until forced.
- Legal, risk, and audit roles are frequently under-engaged in PQC programs relative to their eventual importance, since compliance evidence and contractual obligations become material only later in a program’s life.
- A single accountable executive, not a committee, should own final decision authority for the program overall, even where technical decisions are delegated.
The Ten Roles
- Accountable executive: typically the CISO or equivalent, holds final decision authority for the program’s scope, budget, and timeline, and is the single point of accountability to the board or leadership.
- Crypto/PQC program lead: the day-to-day technical and program owner, responsible for the inventory, risk scoring model, migration roadmap, and coordination across every other role.
- PKI team: owns certificate authority migration, parallel hierarchy deployment, template configuration, and certificate lifecycle execution.
- Application teams: own remediation of hardcoded algorithm dependencies and application-layer TLS and cryptography configuration within their own systems.
- Infrastructure and network teams: own HSM, VPN, network device, and endpoint-layer PQC configuration and rollout.
- Procurement: owns vendor evaluation process execution, RFP administration, and contractual terms tied to PQC readiness commitments.
- Legal and compliance: owns regulatory obligation mapping and interpretation, and reviews vendor contractual language for PQC-specific commitments and liability.
- Risk management: owns the risk scoring model’s governance and validates that migration sequencing decisions align with the organization’s overall risk tolerance.
- Vendor management: owns the ongoing relationship and readiness tracking for critical vendors post-procurement, distinct from procurement’s initial evaluation role.
- Internal audit: owns independent verification that the program’s evidence and reporting match its actual state, and validates compliance-readiness claims before they reach external auditors or regulators.
RACI by Key Decision
| Decision | Responsible | Accountable | Consulted | Informed |
|---|---|---|---|---|
| Cryptographic inventory scope and methodology | Crypto/PQC lead | Accountable executive | PKI, infrastructure, application teams | Risk, audit |
| Algorithm and parameter set selection | Crypto/PQC lead | Accountable executive | PKI team, legal/compliance | Application teams, vendor management |
| Migration risk scoring and sequencing | Crypto/PQC lead | Risk management | Application, infrastructure teams | Accountable executive, audit |
| Vendor selection and RFP evaluation | Procurement | Accountable executive | Crypto/PQC lead, legal, PKI | Vendor management, risk |
| HSM/hardware refresh budget approval | Infrastructure team | Accountable executive | Crypto/PQC lead, procurement | Risk, audit |
| Parallel CA hierarchy deployment | PKI team | Crypto/PQC lead | Infrastructure, application teams | Accountable executive |
| Regulatory obligation mapping | Legal/compliance | Accountable executive | Crypto/PQC lead, risk | Audit |
| Compliance evidence and audit readiness | Crypto/PQC lead | Internal audit | Legal/compliance, risk | Accountable executive |
| Production cutover approval | Infrastructure/PKI teams | Accountable executive | Application teams, risk | Legal, audit |
The Roles That Get Engaged Too Late
Legal, risk, and internal audit are consistently the three roles most PQC programs under-engage relative to how important they become later. Early program work looks purely technical, inventory, algorithm selection, pilot testing, which makes it easy to treat these three roles as downstream reviewers rather than active participants from the start. That ordering causes real friction: a migration roadmap built without risk management’s input on scoring methodology gets challenged after the fact rather than validated up front, and compliance evidence assembled without audit’s input on format and completeness gets rejected or requires rework when it finally reaches an external auditor. Engaging all three roles at the RACI design stage, not just at reporting time, avoids both problems.
What We’d Actually Recommend
Name a single accountable executive for the program overall, not a committee, even where individual decisions are delegated to specific role owners. Formalize the RACI table for your specific program in writing and review it at each major program milestone, since roles and decision ownership tend to drift informally as a multi-year program progresses. Engage legal, risk, and audit from the program’s earliest stages, not as downstream reviewers, to avoid rework when their input surfaces gaps after key decisions are already made.
How Encryption Consulting Can Help
Our PQC Advisory Services help organizations formalize this governance structure against their specific organizational chart, running the RACI design as a facilitated workshop that surfaces role gaps and decision ambiguity before they cause delays mid-program.
Where the crypto/PQC program lead role needs the underlying data to actually make sequencing and scoring decisions, CBOM Secure provides that inventory foundation, and our platforms support the audit-ready evidence internal audit and compliance roles ultimately need to sign off on.
Ownership Named, Not Assumed
Most organizations starting a PQC program can name people who could plausibly own each of the ten roles this guide defines. Far fewer have written down, explicitly, who is responsible versus accountable versus consulted versus informed for the specific decisions the program actually has to make, algorithm selection, migration sequencing, cutover approval, compliance evidence. That explicit RACI structure, reviewed and maintained across a multi-year program rather than assumed once at kickoff, is what keeps a program’s decisions moving without ad hoc ownership disputes at exactly the moments a deadline makes speed matter most.
Frequently Asked Questions
Should a PQC program have a single accountable executive or a governance committee?
A single accountable executive, typically the CISO or equivalent, even where individual technical and operational decisions are delegated to other role owners. A committee structure for final accountability tends to slow decision-making exactly when a program needs speed.
Why are legal, risk, and audit roles commonly under-engaged in PQC programs?
Because early PQC program work looks purely technical, which makes it easy to treat these roles as downstream reviewers rather than active participants. This causes rework later when compliance evidence or risk scoring methodology gets challenged after key decisions are already made without their input.
What is the difference between the crypto/PQC program lead and the PKI team’s roles?
The program lead owns overall program coordination, the inventory, risk scoring, and roadmap across every domain. The PKI team owns the specific technical execution of certificate authority migration, one important domain among several the program lead coordinates.
How often should a PQC program’s RACI structure be reviewed?
At each major program milestone, since role ownership and decision authority tend to drift informally over a multi-year program as teams reorganize, staff change, and the program’s actual scope evolves beyond its initial design.
Does vendor management have a different role from procurement in a PQC program?
Yes. Procurement owns the initial evaluation, RFP process, and contract execution. Vendor management owns the ongoing relationship and readiness tracking after a vendor is selected, which is a distinct, longer-running responsibility across a multi-year migration.
