Skip to content

Convert

Remediation backlog prioritization by deadline tier

Migration planning fails when backlog items lack owners, effort estimates, and deadline-tier ordering. Convert ties remediation to framework clocks and re-scan proof.

Remediation backlog prioritized by compliance deadline tier.

Prioritize by three axes

  1. Deadline tier — NSM-10 (2035), CNSA 2.0 (2030–2033), NIST IR 8547 (2030), CMMC (2026–2030)
  2. Data shelf-life — HNDL exposure for long-lived records
  3. Blast radius — external TLS, code signing, VPN concentrators first

ECC may break before RSA

Recent research suggests ECC-256 — widely used in TLS and VPNs — may fall on an earlier timeline than RSA-2048 for offline attacks. Tag both algorithm families in your inventory; do not assume RSA migration always comes first.

Convert workflow

  1. Import prioritized backlog from Assess or Monitor scan.
  2. Assign owners, target dates, and dependency ordering.
  3. Apply fixes in your environment.
  4. Run verification scan and attach proof to each item.
  5. Export board pack with live workflowStatus.

What auditors see

Signed reports remain verifiable at /verify. Convert merges Postgres remediation status into auditor JSON exports — evidence the fix stayed fixed.

Continue on the Q-Day hub: Convert tier overview

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-03

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.