By NHI Mgmt Group Editorial TeamBased on Axiad: “Experts Say Quantum Will Break Today’s Encryption by 2029” (January 8, 2026)

TL;DR: Enterprises cannot scope post-quantum cryptography migration without a complete cryptographic inventory, and the article argues that identity-linked discovery is the practical starting point, according to Axiad and cited guidance from Gartner, CISA, and NIST. The real constraint is not algorithm choice, but visibility into where certificates, keys, and machine identities actually live.


At a glance

What this is: This article argues that PQC readiness fails first at cryptographic visibility, because organisations cannot plan migration until they can inventory where certificates, keys, and machine identities live.

Why it matters: IAM, NHI, and PKI teams need shared inventory and ownership data now, because post-quantum migration turns credential sprawl into a governance problem, not just a cryptography upgrade.


Context

Post-quantum cryptography readiness depends on knowing where cryptography exists, who or what depends on it, and which identities carry the associated trust. Without that visibility, migration plans stay theoretical because the enterprise cannot tell which certificates, keys, and machine identities are in scope.

The article frames identity visibility as the practical starting point for PQC migration because cryptographic assets are embedded across PKI, identity systems, applications, cloud services, and machine identities. That makes inventory a governance problem as much as a technical one, especially when ownership and lifecycle data are fragmented.


Key questions

Q: How should security teams evaluate PQC readiness beyond a simple inventory of cryptography?

A: Teams should assess whether the tooling can discover cryptography across the environment and also explain what that cryptography supports. A useful PQC program needs relationships, not just objects. Inventory alone is incomplete if it cannot map certificates, libraries, algorithms, applications, business services, and ownership well enough to support prioritisation and migration planning.

Q: Why does incomplete cryptographic inventory create migration risk?

A: Because teams cannot prioritise remediation when they do not know where vulnerable algorithms are embedded or which identities depend on them. Missing inventory turns PQC migration into guesswork, which increases the chance of blind spots, broken dependencies, and delayed replacement of high-risk trust paths.

Q: What breaks when certificate ownership is not mapped to identities?

A: Ownership gaps break accountability, renewal coordination, and change planning. If a certificate, key, or API credential has no clear identity owner, teams often miss expiration events, fail to coordinate replacement, or overlook dependent systems that will fail when cryptography changes.

Q: How should teams prioritise which cryptographic assets to replace first?

A: Prioritise assets that protect sensitive data, support high-privilege identities, or sit on critical dependencies such as PKI, SSO, federation, and machine-to-machine authentication. Those paths create the largest risk if left on quantum-vulnerable algorithms and usually justify the earliest remediation work.


Technical breakdown

Why cryptographic inventory is the bottleneck in PQC migration

PQC migration is not blocked primarily by the mathematics of new algorithms. It is blocked by incomplete discovery of where RSA, ECC, certificates, keys, and signed trust paths actually exist. In modern environments, cryptography appears in identity systems, application code, network appliances, cloud services, and machine-to-machine workflows. A useful inventory therefore has to connect algorithm type, certificate lifecycle, key length, and owning identity. Without that map, teams cannot assess exposure, sequence remediation, or separate critical dependencies from low-value noise.

Practical implication: build inventory around identity and dependency relationships, not just asset lists.

Why identity-linked discovery matters for certificates, keys, and machine identities

Identity-linked discovery treats cryptographic objects as governed credentials rather than isolated technical artifacts. A certificate belongs to a user, device, application, or service account, and that relationship determines ownership, renewal responsibility, and blast radius when migration begins. The same logic applies to API keys, SSH keys, and service account credentials that authenticate machine identities. When discovery tools fail to correlate those relationships, organizations may find the crypto but still not know what breaks if it changes. That is why visibility has to span identity, entitlement, and cryptographic trust together.

Practical implication: correlate each cryptographic object to a responsible identity owner before migration work starts.

What crypto-agility really requires from enterprise identity programmes

Crypto-agility means applications and infrastructure can move between algorithms without re-engineering every dependent system. That requires current knowledge of algorithm use, certificate chains, expiration dates, and where vulnerable cryptography is embedded in code or infrastructure. It also requires governance because PQC migration is multi-year work, not a one-time patch cycle. The article’s central point is that identity programmes already track credentials and lifecycle events, so they are the natural control plane for cryptographic change management. The migration problem becomes manageable only when discovery, ownership, and lifecycle are managed together.

Practical implication: treat PQC as an identity lifecycle and governance programme, not a standalone crypto project.


NHI Mgmt Group analysis

Identity visibility is the real control plane for PQC readiness: the article is right to place discovery ahead of algorithm migration. Organisations cannot govern what they cannot enumerate, and that is especially true when certificates, keys, and machine identities are distributed across PKI, applications, cloud services, and identity systems. The practical implication is that PQC programmes should start with identity-linked inventory, not with algorithm debates.

Cryptographic inventory is a governance problem, not a tooling problem: the article shows that the hard part is not finding a scanner, but creating ownership, dependency, and lifecycle context for each cryptographic object. That is an NHI and IAM issue because the trust boundary lives with the identity that consumes or presents the credential. Practitioners should expect migration delays wherever ownership is unclear or lifecycle data is incomplete.

Crypto-agility depends on lifecycle discipline across human and machine identities: replacing algorithms at scale only works when certificate renewal, key rotation, offboarding, and dependency mapping are already governed. This is where identity and PKI converge, because a certificate without an owner is an unmanaged trust asset. The implication is that PQC readiness should be measured by inventory completeness and lifecycle control, not by policy statements alone.

Standards guidance converges on the same premise: Gartner, CISA, and NIST all point toward inventory-first transition planning because cryptographic discovery is prerequisite to scope and sequencing. That alignment matters because it validates the operational model: visibility before replacement, then prioritisation by risk and dependency. Practitioners should use that consensus to justify cross-functional ownership across IAM, PKI, and application teams.

Identity-linked cryptographic discovery is the named capability that matters: the article’s strongest contribution is the framing of cryptographic visibility as an identity problem with machine-scale consequences. That concept is more useful than generic PQC readiness because it explains why traditional network scans and isolated PKI tools miss the real inventory. The practitioner conclusion is simple: if identity relationships are absent from the inventory, the migration plan is incomplete.

What this signals

Identity-linked cryptographic discovery: PQC readiness becomes tractable only when cryptographic objects are tied back to the identities and services that depend on them. That changes the programme from an abstract cryptography upgrade into a governance exercise with owners, lifecycles, and dependencies.

PQC migration exposes a familiar control failure: organizations often know they have certificates, but not whether those certificates are complete, current, or still mapped to active services. That gap matters because expired ownership models become migration blockers before algorithm choice ever does.


For practitioners

  • Build an identity-linked cryptographic inventory Map every certificate, key, and algorithm to the identity, application, device, or service that uses it, then record lifecycle state and ownership alongside exposure data.
  • Create a PQC readiness workstream Stand up a cross-functional team that includes IAM, PKI, application owners, cloud teams, and security governance so migration scope is not fragmented by platform.
  • Prioritise long-lived and high-privilege trust paths Start with certificates and keys protecting sensitive data, high-privilege accounts, and machine identities that would create the largest migration blast radius if left unchanged.
  • Track crypto-agility as a lifecycle control Require renewal, rotation, and dependency checks whenever cryptographic assets change, so the inventory stays current as systems are added or modified.

Key takeaways

  • PQC migration is constrained less by cryptography theory than by incomplete visibility into where certificates, keys, and machine identities exist.
  • Inventory gaps create real operational risk because teams cannot scope dependencies, assign ownership, or sequence replacement work with confidence.
  • The practical control is identity-linked discovery plus lifecycle governance, which turns a multi-year cryptography programme into something an enterprise can actually manage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIMachine identities carrying crypto trust paths become high-impact assets when inventory is incomplete.
NHI-07 — Long-Lived SecretsCertificates and keys in long-lived estates mirror the persistence problem PQC migration must unwind.
Recommendation — Inventory machine identities and remove unnecessary privilege from cryptographic trust paths. Shorten cryptographic credential lifetimes where migration exposure is highest.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementIA-5 covers lifecycle control for authenticators and closely matches certificate and key governance.
Recommendation — Apply authenticator management controls to inventory, rotate, and retire cryptographic credentials.
NIST CSF 2.0ID.AM-01 — Physical devices and systems inventoriedPQC readiness depends on a complete inventory of systems and cryptographic dependencies.
Recommendation — Extend asset inventory practices to include cryptographic dependencies and owners.
NIST Zero Trust (SP 800-207)Visibility and continuous verificationZero Trust requires continuous visibility into trust relationships, which PQC migration depends on.
Recommendation — Continuously verify cryptographic trust paths as part of zero-trust operations.

Key terms

  • Identity Discovery: Identity discovery is the process of finding and cataloguing every identity, entitlement, and access path across the environment. In NHI programmes it is foundational because hidden service accounts, tokens, and machine identities create governance gaps that certification and offboarding cannot close.
  • Cryptographic Inventory: A cryptographic inventory is a continuously updated record of keys, certificates, algorithms, libraries and trust anchors across an organisation. It is not a spreadsheet or one-time audit output. In practice, it links each asset to ownership, usage, lifecycle state and risk so teams can make remediation decisions.
  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Quantum-Vulnerable Cryptography: Quantum-vulnerable cryptography refers to algorithms, especially RSA and ECC, that are expected to lose security against sufficiently capable quantum computers. These algorithms still protect many modern systems today, but they represent long horizon risk for cloud environments that need durable confidentiality and trustworthy digital signatures.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org