By NHI Mgmt Group Editorial TeamBased on Keyfactor: “From Kuala Lumpur to Crypto-Agility: Reflections from the PKI Consortium’s PQC Conference 2025” (November 19, 2025)

TL;DR: The PKI Consortium’s PQC Conference 2025 shifted the conversation from algorithm selection to execution, with discovery, inventory, maturity, and automation now treated as the practical starting points, according to Keyfactor’s conference reflections. The real governance challenge is no longer whether post-quantum change is coming, but whether identity and cryptographic programmes can adapt continuously without creating new technical debt.


At a glance

What this is: This reflection from Keyfactor argues that PQC readiness has shifted from algorithm selection to operational execution, with discovery, inventory, maturity and automation now the real starting points.

Why it matters: IAM, PKI and identity teams need to treat crypto-agility as an ongoing governance discipline, because the ability to adapt certificates, keys and policies now defines resilience as much as compliance.

By the numbers:

  • More than 90% of enterprises in Asia Pacific are forecast to treat quantum security as a strategic priority, according to Forrester’s 2026 Asia Pacific Predictions Report cited by Keyfactor.

Context

PQC readiness is becoming an identity and cryptography governance problem, not just a standards question. Once quantum-resistant algorithms are treated as an operational programme, teams have to manage discovery, inventory, certificate lifecycle, vendor dependency and policy change together.

Keyfactor’s conference reflections argue that the real gap is between knowing quantum risk exists and having the operational discipline to respond continuously. That puts PKI, certificate management, and cryptographic asset visibility at the centre of crypto-agility planning, especially where identity systems depend on long-lived trust anchors.

The article frames the current starting point as practical rather than theoretical. That is typical of where most organisations are today: aware that change is coming, but still early in the work of mapping cryptographic dependencies and building repeatable migration paths.


Key questions

Q: How should security teams start a PQC readiness programme?

A: Start with cryptographic inventory, not with algorithm selection. Teams need a complete map of certificates, keys, algorithms, dependencies and owning identities before they can scope exposure or sequence migration. Without that baseline, PQC planning becomes speculative and remediation priorities will be wrong.

Q: Should organisations prioritise crypto-agility before final PQC standards are settled?

A: Yes. Waiting for complete standard stability delays the work that makes migration possible. Organisations can already improve inventory quality, centralise certificate control, and remove manual dependencies. That preparation reduces the risk that future algorithm changes will disrupt authentication, trust chains, or service availability.

Q: Where do PQC migrations usually fail in practice?

A: They often fail in brittle paths such as older stacks, MTU-sensitive links, UDP-heavy protocols, deep proxy chains, and systems with hard-coded size limits. Those are the places where a modest increase in message size or timing variation exposes assumptions the original design never had to confront.

Q: Should hybrid PKI be the default during quantum transition?

A: No. Hybrid approaches can be useful where platform or certification support lags, but they should remain a transitional design choice, not a reason to postpone the programme. Teams should define where hybrid is necessary, where pure PQC is already viable, and when to exit mixed-mode trust.


Technical breakdown

Why discovery and inventory are the real starting line

Crypto-agility begins with knowing where cryptographic dependencies exist. Discovery and inventory cover certificates, keys, algorithms, trust chains and the systems that depend on them. Without that baseline, teams cannot prioritise migrations, estimate blast radius, or sequence changes safely. In practice, inventory is not a one-time audit. It has to keep pace with application growth, cloud sprawl, and certificate renewal cycles, or the programme immediately loses accuracy.

Practical implication: build and maintain a current cryptographic asset inventory before attempting PQC migration planning.

How maturity models change PQC from project to programme

A maturity model matters because PQC is not a single migration event. It gives teams a way to measure readiness across functions, business units and technology layers, and it creates a common language between engineers, risk owners and vendors. That matters in identity and PKI because many organisations still manage cryptography as isolated infrastructure work. A maturity lens forces governance, ownership and sequencing into the same operating model, which is what a long transition requires.

Practical implication: use a maturity model to benchmark current state, assign ownership and track progress over time.

Why crypto-agility depends on automation and lifecycle control

Automation is the mechanism that turns crypto-agility from theory into repeatable change. The article links PQC migration with the automation already used for shorter TLS certificate lifecycles, which means the operational lesson is reuse, not reinvention. The architecture challenge is to make cryptographic change routine across issuance, renewal, policy enforcement and system updates. That reduces manual error and makes it possible to adapt when standards, regulations or supported algorithms shift.

Practical implication: extend existing certificate lifecycle automation to cover PQC transition workflows and policy updates.


  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Crypto-agility is now a governance discipline, not a standards watch exercise. The article shows that the question has moved from which post-quantum algorithms will win to whether organisations can adapt continuously as trust requirements change. That changes the operating model for PKI, certificate management and identity infrastructure. The practitioner conclusion is that crypto-agility has to be owned as an ongoing programme, not a one-time migration.

Discovery is the named concept that separates preparation from hope. PQC planning fails when teams do not know where certificates, keys and algorithms live across the estate. That is not a tooling problem alone, it is a governance problem because hidden dependencies create unbounded migration scope and delay risk decisions. The practitioner conclusion is that visibility is the prerequisite for every other control in the transition.

Compliance and resilience are converging around cryptographic change. The article correctly treats changing regulations, shorter certificate lifespans and PQC transition pressure as one operational reality. When standards shift, organisations with brittle cryptographic processes absorb the cost repeatedly, while those with adaptable controls can move faster. The practitioner conclusion is to treat resilience as the ability to change cryptography without service disruption.

Automation is becoming the bridge between certificate lifecycle management and PQC migration. The same pipelines that support renewal and issuance today can be reused for algorithm change, policy enforcement and dependency updates. That matters because manual migration does not scale across complex identity estates. The practitioner conclusion is that crypto-agility depends on lifecycle automation being part of the design, not an afterthought.

Hybrid PKI is an interim state, not a destination. The conference reflections acknowledge that hybrid approaches can help where support lags, but they also create the risk of lingering indecision if teams treat them as the end state. That is a useful reality check for identity leaders because parallel trust schemes increase governance complexity. The practitioner conclusion is to use hybrid carefully while keeping the migration path explicit.

From our research library:

What this signals

Discovery now defines the control boundary for PQC programmes. Teams that cannot map where cryptographic assets live will struggle to sequence migration, assess blast radius or prove readiness to leadership. That makes inventory quality a governance issue, not just an engineering task.

Crypto-agility should be treated as a recurring operating model. The article’s strongest signal is that change will not happen once and then stop. Organisations need processes that can absorb repeated shifts in algorithms, certificate lifecycles and policy expectations without redesigning the identity stack each time.


For practitioners

  • Map cryptographic dependencies across the estate Inventory every certificate, key, algorithm and trust anchor across applications, workloads and infrastructure so you can see where PQC change will land first.
  • Assign priority by business criticality Rank systems by operational impact, external exposure and renewal complexity so migration sequencing reflects risk rather than convenience.
  • Reuse certificate lifecycle automation Extend existing issuance, renewal and policy workflows so PQC transition work does not depend on manual change management.
  • Build crypto-agility into procurement and architecture decisions Require new tools and services to support policy change, algorithm transition and cryptographic dependency updates without redesigning the programme each time.
  • Use maturity benchmarks to track progress Measure readiness across discovery, ownership, automation and governance so the PQC programme can be managed as an operating model rather than a project.

Key takeaways

  • The article’s core message is that PQC preparedness is now an operational governance problem, not an abstract standards debate.
  • The practical starting point is discovery, because you cannot migrate cryptographic dependencies you have not mapped.
  • Automation and maturity measurement turn crypto-agility into a repeatable programme that can absorb future change.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-57, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsLong-lived cryptographic trust material is the transition risk discussed throughout the article.
NHI-02 — Secret LeakageDiscovery and inventory only work if cryptographic material is visible and accounted for.
Recommendation — Review long-lived certificates and keys first, then set a migration path for replacing them. Scan for exposed keys and certificates, then reconcile them into a governed inventory.
NIST SP 800-57Part 1 — Key Management LifecycleThe article is fundamentally about planning and governing the cryptographic lifecycle through change.
Recommendation — Apply key lifecycle governance to plan generation, protection, rotation and retirement around PQC change.
NIST CSF 2.0PR.DS-10 — Data-in-transit is protectedPQC transition affects how trust is protected in transit across identity and PKI-dependent systems.
Recommendation — Update transport protection planning to account for algorithm transition and certificate dependencies.
CIS Controls v8CIS-5 — Account ManagementCertificate and key ownership must be assigned clearly to make the PQC programme executable.
Recommendation — Assign accountable owners for cryptographic assets and keep the ownership map current.

Key terms

  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Post-Quantum Cryptography: Cryptographic algorithms designed to remain secure against attacks from sufficiently powerful quantum computers. In practice, PQC is a migration problem as much as an algorithm problem because organisations must replace trust anchors, certificates, and secrets without breaking identity-dependent systems.
  • Cryptographic Inventory: A cryptographic inventory is a continuously updated record of keys, certificates, algorithms, libraries and trust anchors across an organisation. It is not a spreadsheet or one-time audit output. In practice, it links each asset to ownership, usage, lifecycle state and risk so teams can make remediation decisions.
  • Certificate Lifecycle Management: The governance of digital certificates from issuance through renewal and revocation, ensuring certificates are valid, monitored, and rotated before expiry. Expired certificates are a leading cause of outages and unplanned security gaps.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org