The Hard Parts: PKI, HSMs, Code Signing, Networks, OT And Third Parties
Some areas of post-quantum migration take far longer than others. This article explains why PKI, signing, hardware, network devices, operational technology and suppliers are hard, and how to handle them.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Web traffic is often the easiest part of post-quantum migration, because browsers, libraries and content delivery networks have already done much of the work. Other areas move far more slowly. They involve long-lived hardware, signatures that must stay trusted for years, equipment that only the vendor can change, or ecosystems where many organisations must move together.
This article goes through the areas that usually take longest, explains what makes each one difficult, and ends with a simple way to choose a strategy for systems that cannot simply be upgraded.
Why Some Areas Are Harder
Two things make an area hard: how much of the change you control, and how long the affected assets stay in service. A web server you run yourself scores well on both. A signing key baked into devices that will run for fifteen years scores badly on both.
| Area | Main difficulty | Who controls the change |
|---|---|---|
| Public-key infrastructure (PKI) | Larger post-quantum signatures, many relying parties, long-lived root certificates | Your PKI team, certificate authorities and every system that validates certificates |
| Hardware security modules and key management | Must hold and use both classical and post-quantum keys natively | Mostly the vendor, through firmware and certification |
| Code and firmware signing | Signatures must stay trusted for the life of the device; some roots of trust cannot be upgraded | Your signing team and the device makers |
| Network devices (VPNs, firewalls, gateways) | Every device that terminates TLS or IPsec needs post-quantum key exchange | Mostly the vendor |
| Operational technology and IoT | Decades-long service lives, legacy protocols, limited processing power | Vendors, integrators and asset owners |
| Cloud and SaaS providers | Cryptography sits inside services you do not run | The provider, under the shared responsibility model |
| Multi-party ecosystems such as card payments | Many organisations must agree on standards and timing | Industry bodies and schemes |
PKI And Signatures
Public-key infrastructure is hard partly because of size. An ML-DSA signature is 2,420 to 4,627 bytes depending on the parameter set, many times larger than the elliptic curve signatures in use today.1 SLH-DSA signatures range from 7,856 to 49,856 bytes.2 OMB’s technical appendix warns that ML-DSA signature sizes can strain bandwidth in some uses and that SLH-DSA signs more slowly.3 Certificate chains, handshakes and constrained devices all feel that growth.
PKI also underpins identity. OMB lists access control systems built on public-key infrastructure as a priority for US federal agencies, and announced that the General Services Administration would set up a cross-agency working group to modernise federal identity and access management for post-quantum cryptography.3 The UK National Cyber Security Centre expects certificate-based PKI to become post-quantum ready more slowly than services that protect confidentiality.4
Code and firmware signing needs early attention. NIST’s NCCoE singles out software images on devices whose root of trust cannot be upgraded: if the device only trusts a vulnerable signing algorithm, a future attacker could forge updates it would accept.5 The NSA’s CNSA 2.0 suite, announced in September 2022, sets the future quantum-resistant algorithm requirements for US national security systems.6 The CNSA 2.0 article covers its timeline, including for software and firmware signing. The NCSC also asks organisations to identify any requirement to migrate long-lived hardware roots of trust in their initial plans.4
Hardware, Networks And Key Management
OMB wants key management to be agile as well: key management services and hardware security modules (HSMs) have to hold elliptic curve and post-quantum keys side by side and run the new algorithms natively.3 The zero trust section of the same appendix goes further. Every piece of network infrastructure that ends a TLS or IPsec connection, from firewalls and VPN concentrators to cloud gateways and API proxies, is to support post-quantum key exchange. Device attestation rooted in Trusted Platform Modules, and signed tokens such as JSON Web Tokens, must move to post-quantum algorithms as well.3
As of January 2026, CISA lists networking hardware and software, operating systems, storage, identity and access management software, and hardware security modules among the product categories still transitioning to post-quantum standards.7 For these areas the practical work is supplier engagement: asking for roadmaps, writing post-quantum requirements into renewals and planning around replacement cycles.
Operational Technology And Long-Lived Assets
The NCSC includes IoT and industrial control devices in its discovery scope and accepts that some legacy systems may never support post-quantum cryptography.4 It notes that some industrial control protocols have never been brought up to modern cryptographic standards, and advises timing changes to physical infrastructure to coincide with other planned maintenance where possible.4 The NCCoE gives electricity generation and distribution as an example of components that stay in place for a decade or more.5
Third Parties And Cloud
Much of an organisation’s cryptography runs inside services it does not operate. OMB asks agencies to agree post-quantum responsibilities with their cloud providers under the shared responsibility model, and assigns CISA and the Department of War, with GSA, to lead migration work for cloud services used by more than one agency.3 For private organisations, the equivalent is contract language, supplier questionnaires and tracking each supplier’s published roadmap as part of the inventory.
Choosing A Strategy For Hard Systems
The NCSC sets out the options for systems that do not run on commodity platforms: migrate in place, move to a new platform, retire the service, run it until its planned end of life, or tolerate the risk.4 The NCSC does not rank these options. The flowchart below is our own way of arranging them as a series of questions.
Does the system use quantum-vulnerable public-key cryptography?
- Yes:
Does it run on a commodity platform that the supplier will upgrade?
- Yes:
Rely on routine updates. Track the supplier roadmap and keep the platform current.
- No:
Is it due to be withdrawn on a defined date, before a migration could realistically finish?
- Yes:
Retire or run to end of life. Set and hold a firm retirement date, and deal separately with any retained data or long-lived signatures.
- No:
Can the vulnerable components be replaced with post-quantum equivalents?
- Yes:
Migrate in place. Swap the cryptographic components and test the rest of the system.
- No:
Can the service move to a platform that supports post-quantum cryptography?
- Yes:
Re-platform. Use the move to review the wider architecture.
- No:
Tolerate the risk, with mitigations. Record a formal risk acceptance, isolate the system and review it regularly.
- Yes:
- Yes:
- Yes:
- Yes:
- No:
No action needed for quantum risk. Record the finding and the evidence for it.
Footnotes
-
NIST, FIPS 204, “Module-Lattice-Based Digital Signature Standard”, Table 2, August 2024. nvlpubs.nist.gov ↩
-
NIST, FIPS 205, “Stateless Hash-Based Digital Signature Standard”, Table 2, August 2024. nvlpubs.nist.gov ↩
-
Office of Management and Budget, “Execution of the Migration to Post-Quantum Cryptography” (M-26-15), 24 June 2026. whitehouse.gov ↩ ↩2 ↩3 ↩4 ↩5
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩ ↩2 ↩3 ↩4 ↩5
-
NIST National Cybersecurity Center of Excellence, SP 1800-38B (preliminary draft), “Migration to Post-Quantum Cryptography: Quantum Readiness: Cryptographic Discovery”, December 2023. nccoe.nist.gov ↩ ↩2
-
National Security Agency, “NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems”, 7 September 2022. nsa.gov ↩
-
CISA, “Product Categories for Technologies That Use Post-Quantum Cryptography Standards”, 23 January 2026. cisa.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.