Migration / guide

Post-quantum migration starts with a cryptographic inventory

A migration plan begins by locating cryptography, dependencies, owners, and acceptable rollback paths.

Editorial inventory map connecting cryptographic uses, dependencies, system owners, and rollback paths.
Find cryptography and its owners Editorial illustration

Post-quantum migration is not one library upgrade. It is a program of identifying where cryptography appears, which assets it protects, who owns the dependency, and how a change can be tested and reversed. NIST's 2024 announcement of FIPS 203, 204, and 205 makes an important distinction clear: key establishment and digital signatures are different cryptographic roles. An inventory must therefore capture more than a product name or a generic label such as encryption.

Find the cryptographic boundary

Record the protocol, library, version, algorithm role, certificate or key owner, asset protected, and external dependency. Include internal services, client applications, hardware, managed platforms, and long-lived stored data where applicable.

Connect inventory to testing

For each dependency, identify supported alternatives, interoperability constraints, performance or message-size effects, and a rollback path. Vendor support statements can be useful inputs, but they are not a complete security assessment.

Keep urgency evidence-based

Avoid countdown language that skips the organization’s actual exposure and migration capacity. A well-scoped inventory gives a team a defensible next step: test one defined boundary and document what changed.

Sources & evidence

Source material checked Sep 10, 2026. Reporting and analysis distinguish documented facts from company claims.

AI-assisted research and drafting. Approved for publication by Marcus Vale on Sep 11, 2026.

Continue reading