Frame the risk
Define long-confidentiality data, exposed systems and owners.
Prioritized PQC backlog.NIST PQC migration
NIST published the first finalized PQC standards in 2024. Migration should begin with inventory, then hybrid pilots, before controlled rollout.
Define long-confidentiality data, exposed systems and owners.
Prioritized PQC backlog.Scan TLS, certificates, SSH, code signing, libraries and vendor dependencies.
Maintainable crypto register.Ask for hybrid support, timeline, limits, attestations and rollback plans.
Actionable vendor matrix.Test compatibility, latency, message size, observability and impact on older clients.
Decision records by protocol.Centralize policies, automate rotation and remove hardcoded algorithms.
Repeatable migration.Plan RSA/ECC deprecation according to regulatory deadlines and business constraints.
Trajectory compatible with the NIST transition.Key-encapsulation mechanism standard, derived from CRYSTALS-Kyber, for post-quantum key establishment.
View FIPS 203Primary post-quantum digital signature standard, derived from CRYSTALS-Dilithium.
View FIPS 204Stateless hash-based signature standard, derived from SPHINCS+, useful as a diversity option.
View FIPS 205Draft transition report identifying vulnerable standards, PQC replacements and the removal horizon for vulnerable algorithms.
View IR 8547