Post-quantum migration begins long before a production cutover. The first hard problem is finding where vulnerable cryptography is embedded.
NIST states that three post-quantum standards are ready to implement and urges organisations to begin migration. Enterprise estates may contain algorithms in TLS, certificates, devices, backups, databases, signing services and vendor products. Long-lived sensitive data adds urgency because it can be collected now and decrypted later.
What good engineering looks like
Build a cryptographic inventory connected to assets and data lifetimes. Identify algorithm, key size, library, owner, vendor dependency and replacement path. Prioritise externally exposed systems, long-lived confidentiality and trust anchors.
-
Discover cryptography in applications, infrastructure and devices.
-
Classify protected data by required confidentiality lifetime.
-
Track vendor and protocol readiness.
-
Design crypto-agility into replacements.
-
Test interoperability and performance before broad rollout.
A practical starting point
-
Select one critical service boundary.
-
Trace certificates, libraries and signing dependencies.
-
Record owners and renewal timelines.
-
Create a migration hypothesis and validation plan.
The decision to make
The immediate decision is not a universal algorithm swap. It is how quickly the organisation can make cryptographic use visible and changeable.