Enterprise security

Post-quantum readiness and cryptographic agility

A migration method based on knowing where cryptography lives, separating policy from implementation, and rehearsing algorithm change before a standard or dependency forces the schedule.

15 minute technical paperApplied engineering paper
Technical note 1

Readiness begins with an inventory

A migration method based on knowing where cryptography lives, separating policy from implementation, and rehearsing algorithm change before a standard or dependency forces the schedule.

A post-quantum programme can easily become a list of new algorithm names. That list is not a migration plan. The first task is to find every place the organisation depends on public-key cryptography: transport security, virtual private networks, code signing, document signatures, certificate authorities, device onboarding, identity tokens, database encryption wrappers, backup keys and partner exchanges. Add algorithms, parameters, libraries, protocols, key owners, certificate lifetimes and replacement procedures.

Inventory must include cryptography hidden inside appliances, mobile applications, firmware, managed services and partner endpoints. Source scanning helps, but configuration and runtime observation are needed too. A service may call a library without naming the algorithm in application code. A load balancer may terminate TLS before traffic reaches the service. Record the data protected and how long that data needs confidentiality or signature validity. Long-lived sensitive records deserve attention before short-lived sessions.

Map algorithms to protocols, data classes, owners and replacement paths.
Include certificates, signatures, key wrapping and partner interfaces.
Record how long confidentiality and authenticity must survive.
Mark systems that cannot change without vendor or hardware replacement.