Where do you start, and what changes on the wire?
What Shor's algorithm takes and what it leaves, the two families of replacement (lattices and hashes) and what they weigh, and the order in which a real system moves. This is the section the tools on the post-quantum page put into practice.
Migration is three jobs in a fixed order. First, find out what you use: every certificate, every key, every protocol, and which algorithm each uses for what. This is harder than it sounds, because cryptography is spread through libraries, devices and vendors, and a certificate hides two algorithms (topic 06). Second, decide what goes first, using the clock of topic 06: whatever is being recorded and must stay secret for years, then whatever signature lives a very long time. Third, change it without a flag day, which means building the ability to swap an algorithm before you need to.
The way the field has chosen to start is the hybrid. A connection performs two key exchanges at once, one classical and one lattice-based, and mixes the two secrets so that the result is safe if either holds. A classical flaw in the new algorithm cannot hurt you, because the old one still covers you. A quantum attack on the old one cannot hurt you, because the new one covers you. The cost is bandwidth: the handshake grows, and a growing handshake can stop fitting in the first flight a server sends.
Underneath all of it is crypto-agility: algorithm names that are configuration rather than code, so that the next change, and there will be a next change, is a setting. The organisations that do best are the ones that treat this migration as the first of several.
The sizes. In the hybrid X25519MLKEM768 exchange the client sends an X25519 public key (32 bytes) and an ML-KEM-768 public key (1,184 bytes), and the server answers with a 32-byte X25519 share and a 1,088-byte ML-KEM ciphertext:
client: 32 + 1,184 = 1,216 bytes server: 32 + 1,088 = 1,120 bytes X25519 alone: 32 + 32 = 64 bytes
The hybrid's client share is 1,216 bytes against 32 for X25519 alone, 38 times as much, and the full exchange, 1,216 + 1,120 = 2,336 bytes, is about 36.5 times X25519's 64. A TCP sender may put an initial window of 10 segments of 1,460 bytes, 14,600 bytes, on the wire before an acknowledgement (RFC 6928), and the server's certificate chain, which may itself carry larger post-quantum signatures, has to fit in the same room. That is why the Size Cliff measures real handshakes.
Mosca's inequality as a plan. You are exposed if X + Y > Z (topic 06). The migration time Y is the one number in your control, and it is longer than people expect because the inventory step comes first. The Sequencer turns a list of systems, their dependencies and a capacity per quarter into a schedule; Q-Day Command is the same decision as a game, with the best order proven over every possible order.
The dated deadlines that governments have set for finishing the move are listed with their sources on the post-quantum page rather than repeated here, because a date copied into a course goes stale and a date with a link does not.
On the open web, now The hybrid key exchange is already offered by current browsers and by large content networks, and OpenSSL 3.5 negotiates it by default (the desk measured that in August 2026, while building a probe). A Quick Check on any endpoint tells you whether it will.
What is left Key exchange is the easier half, because it can be hybridised without changing certificates. Signatures are harder: the post-quantum ones are much larger, certificate chains grow, and the roots and the update keys of topic 06 have to move on their own schedules. That is the part of the migration that will take the longest, and it is where an early inventory pays.
The one-line summary of the course Symmetric cryptography and hashing survive with longer keys. Public-key cryptography built on factoring and discrete logarithms does not, and the replacements, lattices and hashes, cost bytes. What to do is find, rank, hybridise and stay agile.
Check yourself
Why does a hybrid key exchange keep the classical exchange as well as adding the new lattice one?
Both shares go in and the two secrets are mixed. A flaw found later in the new algorithm cannot hurt you because the old one still holds, and a quantum attack on the old one cannot hurt you because the new one still holds.