Why Post-Quantum Migration Starts Years Before A Quantum Computer Exists
Replacing cryptography takes many years, and some data stolen today will still matter later. Here is why preparation has to begin long before the threat arrives.
Cryptographic inventories, crypto-agility and practical steps for moving to post-quantum cryptography.
Replacing cryptography takes many years, and some data stolen today will still matter later. Here is why preparation has to begin long before the threat arrives.
The UK, EU, Canada and US have published post-quantum migration dates. They differ in detail but share one shape, which makes them useful for planning.
Post-quantum migration spans years, teams and budget cycles. This article sets out who should own what, what a migration plan should contain and how to keep costs down.
A cryptographic inventory links each algorithm, key and certificate to a system, an owner and the data it protects. Here is what to record and why a list of algorithms is not enough.
Network scans, code analysis, host inspection and supplier questionnaires each see part of your cryptography. Here is what each method finds, where it is blind and how to combine them.
A CBOM records cryptographic assets and their dependencies in a standard, machine-readable format. Here is what it contains, how it links to an SBOM and why policy now names it.
Not every system can move at once. This article explains a simple scoring method from the financial sector and how to turn inventory findings into a ranked, reviewable plan.
Crypto-agility is the ability to change algorithms without rebuilding systems. This article explains what NIST means by it and the design choices that make it practical.
Some post-quantum work can start now at low cost. This article explains hybrid key exchange in TLS 1.3, where it is already available and which cleanup tasks pay off regardless.
Some areas of post-quantum migration take far longer than others. This article explains why PKI, signing, hardware, network devices, operational technology and suppliers are hard, and how to handle them.
Where quantum risk sits in card payments, why point-of-sale migration needs early planning, and the practical work PCI DSS teams can start now.
The most common misunderstandings that slow post-quantum programmes down, and what official guidance actually says about each one.