Skip to main content

Crypto agility and post-quantum governance

Trust Architecture Playbook: Governance pillar

Algorithm inventory

Crypto agility is a governance capability. It depends on accurate inventory, profile constraints, key management standards, automation readiness, owner mapping, and evidence. NIST SP 800-57 provides key-management guidance for cryptographic keying material and policy/security planning. NIST finalized its first post-quantum cryptography standards in 2024 and encouraged administrators to begin transitioning to the new standards; the finalized standards include ML-DSA and SLH-DSA.

  • Maintain inventory views for key algorithm, key size, signature algorithm, issuer, profile, and platform compatibility.

  • Identify certificates with deprecated, weak, unsupported, or non-standard cryptographic settings.

  • Map profile constraints to current approved algorithms and future algorithm transition plans.

  • Track platform support for ECDSA, larger RSA keys, hybrid/PQC test patterns, and trust store limitations.

  • Require governance approval before introducing new cryptographic algorithms into production profiles.

algorithm_chart_pqc.png

Mass-rotation readiness

The same capabilities needed for shorter public TLS validity are the capabilities needed for CA distrust response, key compromise response, algorithm migration, and post-quantum transition. The program should rehearse rotation before it is forced to rotate.

  • Run periodic non-production mass-rotation exercises by profile, CA source, and platform class.

  • Test CA source switching where applicable and validate chain/revocation behavior after the switch.

  • Confirm Tier 0/1 services can rotate within defined recovery objectives without unmanaged manual effort.

  • Review exception populations that cannot rotate on demand and escalate them as crypto-agility risks.

  • Include algorithm transition planning in the profile catalog review and CA source roadmap.