5 min read
Can Your Existing Crypto Estate Help Pay for PQC?
Cryptomathic : modified on 11. August 2026
PQC is entering the budget cycle while banks are increasing investment in AI, cloud and operational resilience.
The transition will require new spending. Cryptographic assets must be identified, applications remediated, infrastructure updated and migration plans tested. But the entire programme does not have to be treated as a new security cost.
In a large, fragmented cryptographic estate, money is already being spent on duplicated infrastructure, repeated integrations and manual administration. Upcoming HSM renewals create another source of expenditure.
Consolidation cannot fund the whole PQC transition. It can help offset the early cost while creating the operating model needed to manage it.
In this context, consolidation does not mean forcing every workload onto one platform or HSM vendor. It means creating a common control and governance model across the bank’s existing cryptographic infrastructure, then reducing duplication where it is technically and commercially sensible.
The Financial Impact Can Be Significant
In one specific large global banking implementation of CrystalKey 360, Cryptomathic’s analysis found:
- 60% annual cost savings
- 70% decrease in HSM requirements
- 75% faster time to market for new applications
These figures should not be treated as a universal benchmark. They come from one implementation, and the actual impact will depend on the bank’s infrastructure, operating model and level of duplication.
They demonstrate that centralising cryptographic services can affect infrastructure demand, operating cost and application delivery at the same time.
For banks developing a PQC business case, three areas are worth examining:
- Infrastructure purchases that could be avoided or deferred
- Operational work duplicated across platforms and teams
- Specialist capacity that could be redirected towards migration
Fragmentation Makes PQC More Expensive
An organisation cannot migrate cryptography it has not identified. Discovery and inventory are essential early steps. But discovery only tells the bank what it has. It does not provide a practical way to govern, migrate and operate those assets.
Over time, banks have accumulated different generations of HSMs, separate key-management systems, cloud-provider services, home-grown cryptographic tools and application-specific integrations. Ownership is often distributed across infrastructure, security, application and regional teams.
Each component may still work. Coordinated change is where the model begins to struggle.
A PQC migration can affect hundreds or thousands of applications, each with its own dependencies, release schedules and risk profile. If every change requires a separate integration and project team, migration becomes slower, more expensive and harder to govern.
Funding lever 1: Avoid Unnecessary Infrastructure Renewal
HSM end-of-life often triggers a straightforward procurement process. The existing hardware is approaching the end of support, so the bank replaces it with a newer model. Sometimes that is the right decision. In other cases, the estate already contains capacity that could support the affected workloads.
A consolidated view allows the bank to assess available capacity, application dependencies, migration feasibility and upcoming end-of-life events across the estate. This leads to a more useful decision:
Does the bank need to replace the HSM, or does it need to move the cryptographic assets currently dependent on it?
If suitable workloads can be moved onto existing infrastructure, the bank may be able to avoid or defer part of the replacement cost. Avoided expenditure can contribute directly to the PQC business case. Deferred expenditure creates near-term budget capacity, although the renewal requirement may return later.
The opportunity must be calculated using the bank’s infrastructure, supplier quotes and migration costs. But the next HSM renewal cycle provides a concrete place to start looking for funding.
Funding lever 2: Reduce Duplicated Operational Work
The cost of cryptographic infrastructure extends beyond hardware and software. Every separate platform can bring its own provisioning process, access model, policy framework, monitoring requirements, backup procedures, application integrations and support cycle.
These costs rarely appear in one budget. An application team funds an integration, infrastructure maintains the hardware, and the crypto team provides specialist support. The total operating cost remains distributed across the organisation.
PQC adds more work to this model. Each platform and integration may require separate assessment, testing and migration. A shared control and governance layer can reduce some of this duplication. It gives the bank a more consistent way to request, access and operate approved cryptographic services across applications.
The benefit may come from retired maintenance contracts, fewer platform-specific processes, shorter onboarding cycles or less manual administration. A sound PQC business case should account for the operating costs the bank can remove alongside the new costs it expects to add.
Funding lever 3: Release Specialist Capacity
Cryptographic expertise is scarce, and many banks depend on relatively small teams to support a growing application estate.
Manual provisioning, repeated integration work, policy administration and platform-specific support all consume specialist time. During a PQC programme, those same people will also be needed for architecture, risk assessment, migration design and testing. Hiring may form part of the answer. It is unlikely to solve the capacity problem on its own.
Standardised services and greater automation can allow the same team to support more applications. The capacity released can then be redirected towards higher-value PQC work. No single ratio captures the complexity of a crypto team’s workload. But tracking managed applications per specialist, alongside onboarding time and automation, can show whether operational capacity is improving.
This is a capacity argument rather than a headcount-reduction argument. The objective is to meet growing demand without creating a larger backlog or increasing operational risk.
Calculate Cash and Capacity Separately
A credible business case should distinguish financial savings, deferred expenditure and operational capacity. Each can support PQC, but they do so in different ways.

Potential net financial contribution
Avoided infrastructure expenditure
- recurring support, licensing and maintenance costs retired
− migration, implementation and testing costs
= potential net financial contribution to the PQC programme
This calculation should use verified supplier quotes, renewal schedules and migration costs.
Potential near-term budget capacity
Infrastructure expenditure deferred
= budget capacity available during the deferral period
Deferred expenditure should not be reported as a permanent saving. The model must show when the cost is expected to return.
Potential capacity contribution
Specialist hours released from routine operations
- integration and onboarding effort avoided
= capacity available for PQC planning and migration
Released capacity becomes a direct financial saving only when it avoids additional hiring, contractors or external services. Otherwise, its value comes from redirecting existing specialists towards PQC work.
Keeping these calculations separate prevents double counting and gives executives a clearer view of how consolidation can contribute.
Four Metrics For The Business Case
1. Infrastructure economics
Track infrastructure expenditure avoided, recurring costs retired and purchases deferred as separate measures.
2. Application capacity
Measure managed applications per crypto specialist alongside application complexity, onboarding demand and automation.
3. Application onboarding time
Measure the time from an approved request to usable cryptographic services.
4. Cost and time required for cryptographic change
Assess the effort needed to update an algorithm, migrate a workload or change infrastructure across the affected application estate.
These measures show whether the organisation is lowering cost while improving its ability to execute cryptographic change.
Build The PQC Business Case From The Estate You Already Have
PQC will still require dedicated investment. Discovery, remediation, application change and testing cannot be financed away.
The business case becomes stronger when the bank combines long-term risk reduction with near-term operational value: avoided infrastructure purchases, lower duplicated operating costs, better use of existing capacity, faster application delivery and a more repeatable model for cryptographic change.
The same fragmented estate that makes PQC expensive may contain part of the funding and capacity needed to begin fixing it. Start with three inputs:
- HSMs and cryptographic platforms due for renewal in the next 24 months
- Current infrastructure, support and operational costs
- The workload and available capacity of the crypto team
These numbers will not replace a full PQC investment plan. They will show whether consolidation can make a meaningful contribution.
Model the opportunity in your cryptographic estate. See how CrystalKey 360 can support PQC readiness, crypto agility and consolidation.
Source: Cryptomathic customer outcome analysis from a specific large global banking implementation. Results are specific to that implementation and should not be interpreted as guaranteed outcomes. Actual impact depends on the current trust-service model, HSM footprint, application estate, lifecycle workload, staffing model and level of duplication.