Crypto agility and post-quantum governance
Trust Architecture Playbook: Governance pillar
Algorithm inventory
Crypto agility is a governance capability. It depends on accurate inventory, profile constraints, key management standards, automation readiness, owner mapping, and evidence. NIST SP 800-57 provides key-management guidance for cryptographic keying material and policy/security planning. NIST finalized its first post-quantum cryptography standards in 2024 and encouraged administrators to begin transitioning to the new standards; the finalized standards include ML-DSA and SLH-DSA.
Maintain inventory views for key algorithm, key size, signature algorithm, issuer, profile, and platform compatibility.
Identify certificates with deprecated, weak, unsupported, or non-standard cryptographic settings.
Map profile constraints to current approved algorithms and future algorithm transition plans.
Track platform support for ECDSA, larger RSA keys, hybrid/PQC test patterns, and trust store limitations.
Require governance approval before introducing new cryptographic algorithms into production profiles.
![]() |
Mass-rotation readiness
The same capabilities needed for shorter public TLS validity are the capabilities needed for CA distrust response, key compromise response, algorithm migration, and post-quantum transition. The program should rehearse rotation before it is forced to rotate.
Run periodic non-production mass-rotation exercises by profile, CA source, and platform class.
Test CA source switching where applicable and validate chain/revocation behavior after the switch.
Confirm Tier 0/1 services can rotate within defined recovery objectives without unmanaged manual effort.
Review exception populations that cannot rotate on demand and escalate them as crypto-agility risks.
Include algorithm transition planning in the profile catalog review and CA source roadmap.
