For each common protocol the handbook sets actions for policy owners, administrators and library developers. TLS: use TLS 1.3 where hardware allows, with AES-256-GCM or ChaCha20-Poly1305 among the cipher suites, and migrate by pre-shared keys (at least 256 bits, a strict key sharing policy, a list of systems using them and updated key management) or by the hybrid key exchange being standardised. SSH and X.509 certificates: hybrid only, as they do not take pre-shared keys (hybrid certificates in ITU-T X.509 section 9.8 and IETF composite drafts; plan with the certificate authority and check library compatibility). IPsec: pre-shared keys or the hybrid approach. S/MIME and PGP: no production-ready post-quantum versions, so information that must stay confidential beyond the expected arrival of decryption capability is not sent by e-mail, and doing so is treated as a security incident. For every protocol the policy states which systems use the altered version, is updated as drafts change, and sets when and how to move from hybrid or pre-shared keys to fully post-quantum; vendors lacking support are contacted or replaced.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.