Skip to main content
Back to insights

Post-Quantum Migration Starts With Cryptographic Inventory

Before replacing algorithms, organisations need to know where cryptography protects data, identities, software and long-lived business records.

  • Software engineering
  • Architecture
  • Modernisation

Arinao Tshamano23 September 20261 min read

Post-quantum migration begins long before a production cutover. The first hard problem is finding where vulnerable cryptography is embedded.

NIST states that three post-quantum standards are ready to implement and urges organisations to begin migration. Enterprise estates may contain algorithms in TLS, certificates, devices, backups, databases, signing services and vendor products. Long-lived sensitive data adds urgency because it can be collected now and decrypted later.

What good engineering looks like

Build a cryptographic inventory connected to assets and data lifetimes. Identify algorithm, key size, library, owner, vendor dependency and replacement path. Prioritise externally exposed systems, long-lived confidentiality and trust anchors.

  • Discover cryptography in applications, infrastructure and devices.

  • Classify protected data by required confidentiality lifetime.

  • Track vendor and protocol readiness.

  • Design crypto-agility into replacements.

  • Test interoperability and performance before broad rollout.

A practical starting point

  1. Select one critical service boundary.

  2. Trace certificates, libraries and signing dependencies.

  3. Record owners and renewal timelines.

  4. Create a migration hypothesis and validation plan.

The decision to make

The immediate decision is not a universal algorithm swap. It is how quickly the organisation can make cryptographic use visible and changeable.

Sources and further reading

Apply the thinking

Working through a related technology decision?

Share the operational context, current systems, constraints, and decision you need to make.

Discuss a requirement