By NHI Mgmt Group Editorial TeamBased on DigiCert: “Migros Named Winner of the 2025 DigiCert Quantum Readiness Award” (September 30, 2025)

TL;DR: Post-quantum preparation is increasingly being treated as an operating discipline, with governance, cryptographic visibility, hybrid cryptography, and rapid certificate rotation at the centre of the response, according to DigiCert’s Quantum Readiness Awards highlighting how Migros and NTT DATA are approaching the issue.


At a glance

What this is: This press release frames quantum readiness as a governance problem for certificate estates, showing Migros and NTT DATA treating cryptographic visibility, hybrid cryptography, and rapid certificate rotation as operational priorities.

Why it matters: IAM, PAM, and NHI teams should treat certificate governance as part of identity lifecycle management because post-quantum preparation changes how trust, rotation, and resilience are enforced across digital systems.


Context

Quantum readiness is no longer just a cryptography conversation. In this article, DigiCert treats it as an identity governance problem because certificates, trust chains, and lifecycle controls determine how digital systems stay reliable while cryptography changes underneath them.

That matters to IAM and NHI programmes because certificate governance is really a lifecycle issue: inventory, policy, rotation, and hybrid operation all affect how machine trust is maintained across services, clouds, and enterprise applications. The article’s examples show organisations moving from abstract post-quantum planning to operational control over cryptographic assets.


Key questions

Q: How should security teams prioritise quantum readiness work for certificate estates?

A: Start with the certificates that protect the most sensitive data and the longest-lived trust relationships, then work outward to lower-risk systems. That sequence gives teams the fastest reduction in exposure while also revealing where ownership, renewal, and automation are weakest. Quantum planning should be run as a lifecycle programme, not a one-time inventory exercise.

Q: Why does hybrid cryptography create governance complexity for IAM teams?

A: Because two trust modes have to coexist while policy, automation, and service dependencies remain stable. That means the organisation must manage compatibility, ownership, and change control across a mixed cryptographic estate. For IAM and workload identity teams, the challenge is not only technical adoption but maintaining reliable trust while the underlying controls are transitioning.

Q: What are the warning signs that certificate governance is not ready for post-quantum change?

A: Common signs include incomplete certificate inventories, unclear ownership, long-lived trust paths, manual renewal steps, and no tested process for running multiple cryptographic modes together. If a team cannot explain which assets are most exposed or how quickly renewals can happen, readiness is still immature. Those gaps will slow both PQC adoption and routine trust maintenance.

Q: What should organisations do when certificate rotation is still mostly manual?

A: Treat manual rotation as a readiness gap and test shorter lifecycles in a controlled way to expose where automation, approval paths, or service dependencies will fail. Manual handling scales poorly when trust transitions accelerate. The immediate goal is to prove that renewal can be repeated safely before the environment has to absorb wider cryptographic change.


Technical breakdown

Why certificate inventory becomes the first control surface

Cryptographic visibility means knowing where certificates exist, how long they live, what data they protect, and which flows depend on them. That is a governance problem before it is a cryptography problem, because post-quantum planning fails when organisations cannot map which assets are exposed to Harvest-Now, Decrypt-Later risk. NTT DATA’s emphasis on inventory and prioritisation shows that certificate estates behave like governed identity assets: they need ownership, scope, and lifecycle tracking. Without that baseline, hybrid cryptography is hard to stage and rotation is hard to target.

Practical implication: build a complete certificate inventory before planning quantum migration or rotation policy changes.

How hybrid cryptography changes trust operations

Hybrid cryptography means running classical and post-quantum algorithms together so systems can transition without breaking trust relationships. In practice, that creates a multi-mode operating model that has to be managed across applications, clouds, and policy layers. The key issue is not just algorithm choice, but how trust is enforced while some components remain classical and others move to PQC. For IAM and workload identity teams, this is the same governance challenge seen in other lifecycle transitions: trust must remain intact while the underlying control plane changes.

Practical implication: treat hybrid cryptography as a staged trust transition that requires policy, testing, and ownership across systems.

Why short-lived certificates are a rehearsal for crypto-agility

Crypto-agility is the ability to swap cryptographic methods without redesigning the whole system. NTT DATA’s 47-day certificate lifecycles are a rehearsal mechanism for that capability because they force automation, policy enforcement, and renewal discipline before PQC adoption becomes mandatory. Short-lived certificates reduce the window in which outdated trust assumptions can persist. They also expose whether the organisation has the operational maturity to rotate, validate, and replace trust material at speed. That makes certificate lifecycle management a proxy for broader readiness.

Practical implication: use short certificate lifecycles to test whether renewal, enforcement, and recovery processes can support future cryptographic change.


NHI Mgmt Group analysis

Quantum readiness has become a certificate governance discipline, not a distant cryptography project. The article shows that organisations are already treating trust inventory, lifecycle control, and policy enforcement as the operational work of post-quantum preparation. That moves quantum readiness into the same governance layer as identity lifecycle management, where ownership and timing matter as much as algorithm choice. For practitioners, the important shift is that trust assets now need the same management discipline as other identity-critical credentials.

Cryptographic visibility is the named concept that matters most here. If you cannot see every certificate, dependent flow, and long-lived trust relationship, then you cannot prioritise what needs PQC transition first. DigiCert’s article makes clear that readiness depends on mapping risk across current certificates, especially where data sensitivity and lifecycle length intersect. The practitioner conclusion is straightforward: inventory is the prerequisite to any credible quantum transition plan.

Hybrid cryptography is a governance bridge between today’s trust and tomorrow’s trust. It lets organisations keep services running while they transition algorithms, but it also increases operational complexity because policy must coordinate two cryptographic modes at once. That complexity is why executive sponsorship and central governance show up in the article as core enablers. For identity leaders, the lesson is that dual-mode trust requires explicit ownership, not informal technical migration.

Short-lived certificates expose whether an organisation can actually operate crypto-agility. A 47-day lifecycle is not just a security setting, it is a governance test of whether renewal, automation, and policy enforcement work under pressure. If teams cannot rotate certificates quickly now, they will not be ready when post-quantum change accelerates. Practitioners should read this as evidence that certificate lifecycle management is already a readiness benchmark.

Quantum preparedness extends the NHI model because machine trust is the entry point to digital resilience. Certificates, service trust, and cloud governance are all non-human identity issues when viewed through lifecycle and entitlement control. The article’s examples show that quantum readiness is not separate from identity governance, it is one of its next operating constraints. The implication for practitioners is to fold PQC planning into the same governance model used for machine identities and trust infrastructure.

What this signals

Quantum readiness will increasingly be judged by whether organisations can inventory trust dependencies, not by whether they have a roadmap slide for post-quantum cryptography. Teams that already manage certificates as governed assets will find the transition easier because they can see ownership, expiry, and exposure clearly.

Cryptographic visibility gap: the hardest part of post-quantum preparation is often not algorithm selection but knowing which certificates, services, and data flows actually depend on them. That is why lifecycle governance now belongs in the same conversation as cryptographic planning.


For practitioners

  • Map the certificate estate first Create an authoritative inventory of certificates, their owners, expiry dates, and the systems or data flows they protect before planning PQC transition work.
  • Prioritise long-lived trust paths Rank certificates and dependent services by data sensitivity, exposure duration, and business criticality so the highest-risk trust paths move first.
  • Run hybrid cryptography in controlled stages Test classical and post-quantum modes together in production-like conditions so teams can validate compatibility, resilience, and rollback behaviour.
  • Shorten certificate lifecycles to prove agility Use shorter renewal windows to test whether automation, policy enforcement, and approval processes can support rapid rotation without service disruption.

Key takeaways

  • Quantum readiness is being operationalised as a governance problem for certificates, trust chains, and lifecycle control rather than as a standalone cryptography task.
  • The strongest preparation patterns in the article centre on inventory, hybrid operation, and shorter certificate cycles, which together make crypto-agility measurable.
  • For IAM and NHI programmes, the practical implication is to manage certificate estates with the same discipline used for other identity assets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-57 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsLong-lived certificates create the exposure window this article warns about.
NHI-05 — Overprivileged NHICertificate trust paths can grant broader machine access than the workload needs.
Recommendation — Shorten certificate lifecycles and retire persistent trust material before PQC migration accelerates. Review certificate-scoped trust and remove unnecessary access paths from machine identities.
NIST SP 800-57Part 1 — Key Management LifecyclePost-quantum preparation here is fundamentally about lifecycle management of cryptographic assets.
Recommendation — Apply lifecycle controls to keys and certificates so rotation and replacement can be executed at scale.
NIST CSF 2.0PR.DS-01 — Data-at-Rest Confidentiality and IntegrityThe article frames PQC as protection for cryptographic assets and sensitive data flows.
Recommendation — Protect sensitive data flows with stronger crypto governance and transition planning.

Key terms

  • Quantum Readiness: Quantum readiness is the programme of preparing identity, trust, and infrastructure systems for cryptographic change before current algorithms or certificates become unsafe. It combines discovery, migration planning, dependency mapping, and governance so trust can be updated without service disruption or hidden exposure.
  • Hybrid Cryptography: Hybrid cryptography uses a classical algorithm and a post-quantum algorithm together in one exchange. The goal is to preserve compatibility and confidence during migration while reducing dependence on any single cryptographic method that may later prove insufficient.
  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Cryptographic visibility: Cryptographic visibility is the ability to see where keys, certificates, and algorithms exist, who owns them, and which services depend on them. It turns hidden trust dependencies into governed assets. Without it, teams cannot reliably assess exposure, prioritise remediation, or prove control effectiveness across identity and workload systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 25, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org