Replacements can introduce new weaknesses through a poor choice of algorithm or a configuration error, and the migration itself widens the attack surface, so the organisation executes with great care, keeps enough internal understanding of post-quantum cryptography to judge trade-offs even when the work is outsourced, keeps the asset inventory current throughout, and may start with high-priority assets while planning continues. Asymmetric cryptography is migrated first: confidentiality mechanisms (encryption, key exchange and encapsulation) are exposed to interception now for later decryption, signatures are not, and systems built to last, such as critical infrastructure, satellites and operational technology, need particular attention; symmetric algorithms and hashes are expected to stay secure, so resources go to larger symmetric keys only after all asymmetric primitives have moved.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.