Using the inventory, regulatory requirements and risk assessment, the organisation estimates the scope and complexity of the migration, the staff and expertise needed (distinguishing what it controls from what vendors manage), the cost of supporting tools and services, the replacement of appliances that cannot or will not support PQC and of hardware too weak for the heavier algorithms, and the cost of potential downtime; it keeps a backup and a robust recovery procedure for its communication infrastructure, and weighs future cryptographic migrations, whose cost current investment in agility can reduce.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.