By NHI Mgmt Group Editorial TeamBased on Keyfactor: “NIST NCCoE Publishes Drafts on Migration to Post-Quantum Cryptography” (September 21, 2025)

TL;DR: NIST NCCoE draft guidance on migration to post-quantum cryptography shifts the conversation from algorithm selection to migration planning, inventory, and cryptographic agility, according to Keyfactor. For IAM, PKI, and workload identity teams, the real issue is not only replacing algorithms but proving where cryptography lives and how fast it can change.


At a glance

What this is: This is Keyfactor’s analysis of NIST NCCoE draft guidance on migrating to post-quantum cryptography, with the key finding that crypto-agility now matters as much as algorithm choice.

Why it matters: It matters because IAM, PKI, and workload identity teams need to know where cryptography exists, how it is governed, and how quickly it can be changed when standards shift.


Context

Post-quantum migration is the process of replacing or adapting cryptographic dependencies so they can survive the arrival of quantum-resistant standards. The practical challenge is rarely just selecting a new algorithm. It is knowing every place cryptography is used, every system that depends on it, and every lifecycle process required to change it without breaking trust.

For identity programmes, that makes crypto-agility part of governance rather than a narrow PKI exercise. Certificates, signing chains, workload identity, and service integrations all need inventory and change control before migration is feasible. Keyfactor’s article frames the issue as a planning and visibility problem, not a simple cryptographic swap.


Key questions

Q: How should security teams prepare identity systems for post-quantum cryptography?

A: They should start with a complete inventory of where cryptography underpins authentication, federation, signing, and encrypted transport. Then they should rank systems by business lifetime and migration complexity, because the most dangerous dependencies are the ones that must remain trusted for years. Crypto-agility matters when replacement can happen without re-architecting the whole identity stack.

Q: How should security teams build cryptographic agility for post-quantum PKI migrations?

A: Security teams should treat crypto agility as a core operating capability, not a one-time project. Start by inventorying every certificate, key, and algorithm in use, then automate renewal, revocation, and replacement workflows. The goal is to swap algorithms without re-architecting services, so when post-quantum standards or compliance deadlines arrive, migration becomes controlled rather than chaotic.

Q: What breaks when organisations do not know where cryptography is used?

A: When organizations do not know where cryptography is used, they cannot assess risk, plan migration, or prove control over their trust estate. That leaves applications, devices, and supply chains exposed during change events such as certificate renewal or quantum-safe transitions. The practical failure is not just technical blind spots, but an inability to prioritize remediation with confidence.

Q: What is the difference between cryptographic agility and cryptographic strength?

A: Cryptographic strength is the inherent resistance of an algorithm or scheme to attack. Cryptographic agility is the organisation’s ability to replace that scheme quickly when confidence changes. Strength protects the math, while agility protects operations. A strong scheme can still become unusable, and an agile environment can still fail if discovery, inventory, and lifecycle control are missing.


Technical breakdown

Why cryptographic inventory is the first migration control

Post-quantum migration fails if organisations cannot map where cryptography exists. That includes certificates, keys, signing dependencies, protocol assumptions, embedded libraries, and external trust relationships. Inventory is not a nice-to-have cataloguing task. It is the dependency map that determines what can be replaced, what must coexist, and where migration risk will surface first. Without that map, teams cannot sequence changes or estimate blast radius. In identity environments, this matters because authentication and signing chains are often distributed across platforms, applications, and devices.

Practical implication: inventory every cryptographic dependency before selecting migration paths or timelines.

What crypto-agility means for PKI and workload identity

Crypto-agility is the ability to change cryptographic algorithms, keys, and supporting trust infrastructure without redesigning the whole environment. In practice, that means certificates, issuance workflows, trust anchors, and application dependencies must be structured so replacements can be introduced without prolonged outages. For workload identity, the challenge is sharper because trust often lives in automated paths that are hard to inspect manually. The real test is whether identities can rotate, reissue, or re-establish trust quickly enough when a cryptographic standard changes.

Practical implication: design certificate and workload identity flows so algorithm changes do not depend on manual rebuilds.

Why migration planning is an identity governance issue

Post-quantum readiness exposes a governance gap because identity teams must prove where cryptography is used, who owns each dependency, and which systems can tolerate change. That is lifecycle management in disguise. If an organisation cannot track ownership, replacement order, and exception handling, it has not governed cryptographic risk. The draft guidance matters because it pushes the discussion from abstract future-proofing into operational accountability across PKI, IAM, and application teams.

Practical implication: assign ownership for cryptographic change management across every identity and trust dependency.


  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
  • SpotBugs token leak 2025: A SpotBugs maintainer's PAT, stolen via a pull_request_target workflow in 2024, started the reviewdog and tj-actions supply chain attack.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Crypto-agility is now an identity governance requirement, not a specialist PKI project. The draft guidance pushes organisations to treat cryptographic change as a cross-programme control issue that touches identity, trust, and dependency management. That shifts ownership beyond security engineering into lifecycle governance, where changes can be tracked, reviewed, and enforced. The practical conclusion is that post-quantum readiness belongs in identity programme planning, not in a separate technical silo.

Cryptographic inventory is the named concept that determines whether migration is even possible. The important question is not which post-quantum algorithm to prefer, but whether the organisation can identify every certificate, key, signing dependency, and trust anchor that would need to change. If the inventory is incomplete, crypto-agility is only an aspiration. Practitioners should read that as a governance boundary: undocumented trust cannot be migrated cleanly.

Post-quantum migration exposes the same lifecycle weakness that affects certificate management more broadly. Systems that cannot reissue, rotate, or replace trust material quickly will struggle whenever standards change, whether the trigger is PQC, compromise recovery, or routine renewal. That makes migration planning a test of operational maturity, not a one-time project milestone. The conclusion for IAM and PKI teams is to measure change readiness, not just cryptographic strength.

Identity teams should expect cryptographic change to become a board-visible resilience issue. Once post-quantum planning is framed as dependency visibility and change control, it affects outage risk, trust continuity, and compliance evidence. That broadens the audience for the work and raises the bar for evidence. Practitioners need a defensible migration posture, not a theoretical promise that replacement will be possible later.

What this signals

Cryptographic inventory is the control that determines whether post-quantum planning is actionable. If an organisation cannot see every trust dependency, migration becomes guesswork and identity teams cannot establish realistic sequencing. That is why crypto-agility should be measured as a governance capability, not as a theoretical readiness statement.

Post-quantum readiness will increasingly separate organisations that can change trust material from those that can only discuss it. For IAM and PKI teams, the near-term task is to prove reissue paths, ownership, and exception handling before standards pressure arrives.


For practitioners

  • Map cryptographic dependencies Build a complete inventory of certificates, keys, signing paths, libraries, and external trust dependencies across production and non-production systems.
  • Define crypto-agility owners Assign accountable owners for each trust domain so algorithm change, reissuance, and exception handling have named governance responsibility.
  • Test certificate reissue paths Validate that certificate replacement and trust-anchor updates can be executed without redesigning the surrounding identity or application workflow.
  • Prioritise high-friction trust chains Focus first on environments where identity trust is embedded in automation, signing, or device flows that would be hardest to update under new standards.

Key takeaways

  • Post-quantum migration is not only about choosing new algorithms. It is about whether organisations can locate, govern, and replace every cryptographic dependency that identity and trust systems rely on.
  • The hardest part of readiness is usually visibility and change control, not cryptographic theory. Hidden trust chains and manual reissue processes create the real migration risk.
  • IAM, PKI, and workload identity teams should treat crypto-agility as an operational governance requirement. If trust cannot be changed quickly, it is not yet migration-ready.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-57, CSA Cloud Controls Matrix and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-57Part 1 — Key Management LifecyclePost-quantum migration is fundamentally about governing key and trust-material change across the lifecycle.
Recommendation — Inventory key lifecycles and update migration plans around replaceable trust dependencies.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementIdentity trust and certificate-driven access are central to the migration planning problem.
Recommendation — Map identity trust dependencies to the IAM domain and verify reissue paths before standards change.
NIST CSF 2.0PR.DS-10 — Data-in-Transit ProtectionCrypto migration affects the protective mechanisms securing trust channels and exchanges.
Recommendation — Review transport and trust protections for cryptographic replaceability under PR.DS-10.
ISO/IEC 27001:2022A.8.24 — Use of CryptographyThe article concerns how organisations govern cryptographic use and change readiness.
Recommendation — Apply cryptography governance controls to document and review all trust dependencies.

Key terms

  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Cryptographic Inventory: A cryptographic inventory is a continuously updated record of keys, certificates, algorithms, libraries and trust anchors across an organisation. It is not a spreadsheet or one-time audit output. In practice, it links each asset to ownership, usage, lifecycle state and risk so teams can make remediation decisions.
  • Trust anchor: A trust anchor is the root authority that signs federation metadata and establishes the policies other participants inherit. In practice, it controls who can join, what cryptographic rules apply, and how trust is delegated across an ecosystem. The security posture of the whole federation depends heavily on this layer.
  • Post-Quantum Migration: Post-quantum migration is the process of moving cryptographic systems away from algorithms expected to be vulnerable to quantum computing. It requires discovering where legacy cryptography exists, prioritizing high-risk dependencies, and sequencing replacements carefully. The goal is to preserve trust and service continuity during a long transition.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org