A better mandate would have been “If you see whitelist/blacklist, you should now change it to allowlist/blocklist as you come across it, with teammates holding that bar in PRs. No modifications should be done without also updating the naming”.
Yup! This is how I handled it, along with some other similar language changes in more industry specific language use cases. Only exceptions were user-facing dialogs. Surprise, surprise, everything that needed to be changed happened over the course of a few months anyway.