Before starting, the organisation decides which PQC persona or personas it has, using the attack surface, the systems and data it handles, time pressure, dependence on other organisations and the likely threat. Urgent adopters (holders of personal or organisationally sensitive data that must stay confidential for a long time, providers of critical infrastructure, and providers of long-lived infrastructure such as satellites, payment terminals, vehicles and smart meters) should start now; regular adopters can take a more reactive stance for the time being; cryptography experts (standard developers, cryptographic infrastructure providers and providers of cryptography beyond secure communication) carry responsibility for others. An organisation considers its own infrastructure, its cryptographic knowledge and the organisations it supplies, whose personas it inherits down the supply chain; it judges conservatively, treats a borderline case as needing the planning advice, and reassesses the persona each time it starts a new migration step.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.