Key Takeaways
- Post quantum migration is a phased operational process, not a single event.
- TLS 1.3 adoption is the foundation for successful PQC deployment.
- Crypto agility enables organisations to manage future cryptographic changes safely.
- Legacy infrastructure and customer readiness shape realistic migration timelines.
- Phased rollout strategies reduce operational risk and support long-term resilience.
Crypto Agility at Scale: What Jan Schaumann Wants Security Leaders to Understand About Post-Quantum Migration
“Post-quantum cryptography is really just an overhaul. We are rolling out a new key exchange.” – Jan Schaumann
The conversation around post-quantum cryptography (PQC) often arrives wrapped in urgency and speculation. Headlines focus on future quantum machines, looming deadlines, and theoretical breakthroughs.
Inside real organizations, however, the work looks very different.
It surfaces through protocol upgrades, legacy systems, customer readiness, and decisions about how to change safely without disrupting critical infrastructure.
In this episode of Shielded: The Last Line of Cyber Defense, Jan Schaumann, Chief Information Security Architect at Akamai Technologies and longtime systems educator, joins host Jo Lintzen to unpack how post-quantum migration actually unfolds at internet scale.
Drawing from hands-on experience running large platforms, Jan offers a grounded view of where progress happens, where it slows, and what security leaders should prioritize right now.
Jan brings a rare combination of operational depth, architectural responsibility, and teaching discipline. His perspective reframes PQC away from theory and toward execution, sequencing, and long-term crypto agility.
Post-Quantum Cryptography as Structured Upgrade Work
One of Jan’s core messages centers on reframing how organizations think about post quantum cryptography.
Post-quantum cryptography often sounds exotic because of the word “quantum,” yet the changes introduced by PQC resemble many cryptographic transitions organizations have already lived through.
At its core, PQC introduces new key exchange mechanisms and ciphers. Jan points out that previous transitions, such as moving from TLS 1.2 to TLS 1.3, carried far more operational impact than enabling post-quantum key exchange inside TLS 1.3. The math may be new, but the deployment patterns are familiar.
Why Reframing Matters
When teams treat post quantum migration as a specialized or academic problem, execution slows down.
When teams treat it as disciplined crypto upgrade work, progress becomes:
- Measurable
- Manageable
- Easier to sequence safely
- More aligned with existing infrastructure refresh cycles
The mathematics may be new, but the deployment patterns are already familiar to experienced infrastructure teams.
TLS 1.3 as the Real Foundation for PQC
Throughout the conversation, Jan returns to a foundational prerequisite that continues to shape every PQC discussion: TLS 1.3 adoption.
Why Legacy Systems Slow Migration
These systems evolve slowly, particularly in regulated sectors such as:
- Financial services
- Healthcare
- Government infrastructure
As a result, many organizations believe PQC adoption sits just one configuration away. In reality, significant portions of their environment still require protocol modernization before PQC even enters the picture.
For many enterprises, unfinished TLS 1.3 migration remains the largest blocker to meaningful post quantum migration.
Breaking PQC Into Traffic Paths
Rather than approaching PQC as a single migration, Jan explains how Akamai divided the work into three distinct traffic paths:
- Client to edge
- Edge to origin
- Internal infrastructure
Each path carries a different threat model, operational cost, and upgrade timeline. Client-to-edge traffic represents the largest volume and directly addresses harvest-now-decrypt-later risk.
Edge-to-origin traffic depends heavily on customer readiness and legacy constraints. Internal traffic carries a different attacker profile altogether.
This separation allowed Akamai to prioritize where PQC delivered immediate value while maintaining clarity around longer-term work. It also enabled customers to understand how PQC applied to their environment without forcing a single timeline across very different systems.
Phased Rollout and Safe Change
Jan spends significant time explaining why Akamai chose phased, opt-in rollout rather than enabling PQC everywhere at once.
Many Akamai customers operate critical infrastructure under strict regulatory oversight. For these organizations, stability carries the same weight as security. Akamai’s deployment model relied on canary networks, staged percentages, and gradual expansion to validate behavior before broad exposure.
This approach aligned with customer expectations and reduced the risk of large-scale outages. It also provided flexibility as standards evolved, allowing Akamai to adapt without locking customers into early assumptions.
For Jan, resilience and safe change form a core part of security architecture at scale.
Standards Timing and Avoiding Rework
A quieter but important theme in the episode involves standards maturity. Jan describes how Akamai tracked activity across standards bodies and browser ecosystems while preparing for PQC. This awareness shaped timing decisions around Kyber and the eventual transition to standardized ML-KEM.
The Importance of Timing
Because rollout happened incrementally, Akamai avoided deploying implementations that later required immediate replacement.
Careful standards tracking helped:
- Reduce engineering complexity
- Avoid unnecessary rework
- Improve long-term interoperability
- Simplify future migration stages
This measured approach demonstrates why post quantum migration requires patience alongside technical readiness.
Crypto Agility as the Outcome of Real Migration Work
As the conversation moves toward the later stages of PQC adoption, Jan returns to a pattern he sees repeatedly across large systems.
Cryptographic transitions never arrive as one-time events.
Each one exposes how well an organization understands:
- Where cryptography exists
- How protocols are negotiated
- Which dependencies are long-lived
- How upgrades move through production environments
In Jan’s experience, PQC work forces teams to inventory protocols, identify long-lived dependencies, and confront assumptions about how easily systems change. That work matters beyond post-quantum timelines. The same processes will be required again for certificate transitions, DNSSEC signatures, protocol deprecations, and future cryptographic shifts that have yet to surface.
Jan describes PQC less as an endpoint and more as a moment of alignment. Teams that build visibility, tooling, and repeatable upgrade paths during this transition reduce the operational burden of every cryptographic change that follows. The value compounds through preparedness rather than speed.
Practical Steps Security Leaders Can Take Today
Jan’s guidance focuses on actions teams already control and can sequence safely.
Practical steps that move PQC forward:
- Complete TLS 1.3 adoption across edge, origin, and internal systems. Post-quantum key exchange depends on this foundation, and lingering TLS 1.2 dependencies slow progress long before algorithm choices matter.
- Enable post-quantum key exchange through service providers that already support it. This step reduces long-term exposure for large volumes of traffic without forcing immediate changes to certificates or PKI.
- Map cryptographic dependencies across environments to identify legacy clients and long-lived systems that shape realistic timelines.
Jan emphasizes that PQC unfolds in stages.
Confidentiality upgrades come first. Certificates, signatures, PKI, and DNSSEC follow as standards and implementation guidance mature. Each phase benefits from the same operational discipline established early.
The Future of Post Quantum Migration Depends on Preparation
Jan Schaumann brings an operator’s perspective to post-quantum migration, shaped by years of running internet-scale infrastructure.
PQC appears as a sequence of manageable upgrades guided by protocol readiness, customer constraints, and safe-change practices.
Key points to carry forward:
- Post-quantum cryptography progresses through staged upgrades rather than a single migration.
- TLS 1.3 adoption sets the foundation for any meaningful PQC work.
- Customer readiness and legacy systems define realistic timelines, especially at the origin layer.
- Phased rollout and validation protect stability across regulated and high-risk environments.
- Crypto agility emerges as the durable outcome, preparing teams for future transitions beyond PQC.
Organizations that invest in visibility, phased deployment, and adaptable infrastructure today will be far better positioned for future cryptographic change.
Start Your Post Quantum Migration Journey Today
Preparing for quantum-safe security requires more than adopting new algorithms. It demands operational visibility, safe migration strategies, and long-term crypto agility across your infrastructure.
You can hear the full conversation with Jan Schaumann is available on Shielded: The Last Line of Cyber Defense on Apple Podcasts, Spotify, and YouTube Podcasts.
Contact PQShield today to learn how your organisation can accelerate post quantum migration, strengthen cryptographic resilience, and prepare for future security standards with confidence.
About Jan Schaumann
Jan Schaumann is Chief Information Security Architect at Akamai Technologies, where he guides cryptographic strategy, infrastructure security, and safe-change practices across one of the internet’s most critical platforms.
He previously served as Principal Architect at Akamai and has held senior security roles at companies including Yahoo, Twitter, and Etsy. Jan is also an Adjunct Professor of Computer Science at Stevens Institute of Technology, where he has taught graduate-level systems and Unix programming since 2001.
He is a long-time developer with the NetBSD Foundation and describes himself, accurately, as an actual human on the internet who refuses to grow up.
Frequently Asked Questions
What is post quantum migration?
Post quantum migration is the process of transitioning systems, protocols, and cryptographic infrastructure to quantum-resistant technologies designed to withstand future quantum computing threats.
Why is TLS 1.3 important for post quantum migration?
TLS 1.3 provides the foundation for implementing post-quantum key exchange mechanisms. Organisations still relying on TLS 1.2 or legacy protocols may face significant barriers to PQC adoption.
Why do legacy systems slow post quantum migration?
Many enterprise environments still rely on outdated infrastructure, embedded systems, and third-party dependencies that do not support modern cryptographic protocols. These systems often require significant modernisation before PQC adoption becomes possible.
How can organisations begin preparing for post quantum migration?
Organisations can start by completing TLS 1.3 upgrades, creating cryptographic inventories, mapping dependencies, assessing vendor readiness, and implementing phased migration strategies aligned with operational risk.

