Standards / news

NIST's final crypto-agility paper broadens the migration task

The December 2025 white paper treats cryptographic change as an operational capability spanning software, hardware and organizations.

Abstract document illustration representing cryptographic change across systems and organizations.
Build the ability to change cryptography Editorial illustration

NIST published the final Considerations for Achieving Crypto Agility: Strategies and Practices on December 19, 2025. The white paper, CSWP 39, addresses the ability to change cryptography while keeping systems secure and operating.

For post-quantum migration teams, its significance is the breadth of that task. The primary paper considers protocols, implementations and organizational planning. An algorithm choice is only one part of the transition.

A useful change in the planning question

An inventory can identify a cryptographic dependency. It does not automatically provide a way to replace that dependency. A team may know that a product uses an older algorithm yet still lack a supported upgrade, an owner for the change or a representative compatibility test.

Our interpretation is that CSWP 39 gives teams a useful reason to examine those missing capabilities. The practical planning question becomes whether the organization can make and verify a change, rather than merely name the desired replacement.

Consider a hypothetical service with a current library but a separate appliance that controls its external connections. Updating the library alone would not establish the appliance's behavior. A migration plan needs an accountable owner and evidence for each relevant component.

How to use the publication

The paper is a final NIST white paper, not a certification of a particular product or a claim that every migration follows an identical sequence. Its publication record and PDF are two references to the same underlying work, not independent corroboration.

A useful reading session would bring together application, infrastructure and security owners. Each can identify a place where a cryptographic change becomes another team's responsibility. Those boundaries are often where an apparently simple upgrade becomes an operational project.

The immediate outcome should be a list of change capabilities that require work: supported replacement paths, test evidence, observation of deployed behavior and ownership of exceptions. These are our suggested planning outputs, rather than quoted requirements from NIST. They make the paper's broader framing concrete without mistaking guidance for proof that an organization's migration is complete.

Sources & evidence

Source material checked Sep 11, 2026. Reporting and analysis distinguish documented facts from company claims.

AI-assisted research and drafting. Approved for publication by Marcus Vale on Sep 11, 2026.