Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that a cryptography roadmap…
Governance, Ownership & Risk

What are the signs that a cryptography roadmap is not keeping pace with quantum risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Warning signs include no inventory of where encryption is used, no timeline for testing post-quantum options, and no prioritisation for long-lived sensitive data. If teams only discuss quantum as a future concern, or if software and hardware owners are not aligned, the organisation is already behind. The absence of a migration plan is itself a clear signal.

What a stale crypto roadmap looks like in practice

A roadmap that is not keeping pace with quantum risk usually looks organised on paper but empty in execution. The signal is not just that post-quantum cryptography is mentioned, but that the organisation cannot show where encryption is used, what must move first, or who owns each dependency. For a useful reference point on migration scope, see Post-Quantum Readiness for Identity and PKI.

In mature programmes, the roadmap is tied to asset inventory, data retention, certificate and key lifecycle work, and a testing plan for candidate algorithms. Where those elements are missing, “quantum readiness” is usually still an awareness topic, not an operational programme.

Which gaps usually expose the problem first?

The earliest warning signs are practical, not theoretical. If teams cannot name the systems that use long-lived encryption, have not separated short-term fixes from migration work, or have no prioritised list for data that must remain confidential for years, the roadmap is probably lagging. That is especially visible in certificate-heavy environments, where crypto changes have to be coordinated with lifecycle automation and ownership. The lifecycle side is often easiest to miss, so Machine Identity, PKI and Certificate Lifecycle Guide is a useful companion for checking whether operational ownership exists.

Another sign is false confidence: teams talk about quantum as a distant future issue, but there is no testing timeline, no migration sequencing, and no decision on where to start with high-value or long-lived secrets. If software owners, infrastructure owners, and security leaders are not aligned on the same inventory and milestones, the roadmap is not really a roadmap yet.

Why the absence of a migration plan matters now

The biggest failure mode is waiting for the quantum threat to become urgent before doing the hard preparation work. That is too late for cryptography, because inventory, algorithm replacement, vendor coordination, and certificate or key turnover all take time. Long-lived sensitive data is the clearest pressure point: if it must stay protected for many years, the organisation needs to assume today’s encryption choices may not survive the full confidentiality window.

Good planning also depends on key-management discipline, because quantum risk is not only about which algorithms are selected, but how quickly they can be retired, rotated, and replaced. For a control-oriented view of that lifecycle, NIST SP 800-57 Key Management remains a strong reference for lifecycle thinking. At the governance level, ISO/IEC 27001:2022 Information Security Management is useful where cryptography decisions must be managed as part of a broader security programme rather than as a one-off technical change.

Risk and Threat Considerations

The main risk is not that encryption fails overnight, but that organisations keep accumulating protected data, certificates, and dependencies that cannot be migrated quickly enough once post-quantum timelines tighten. That creates exposure in two directions: legacy data may remain decryptable in the future, and rushed migration can introduce outages, compatibility failures, or mismanaged trust relationships.

Failure mechanism: The roadmap has no live inventory, no tested migration path, and no ownership for prioritising systems with long confidentiality life, so hidden dependencies are left to age in place until change becomes disruptive.

Impact: Sensitive data, signatures, and trust chains can remain on vulnerable cryptography longer than intended, while the eventual move to new algorithms becomes harder, costlier, and more operationally risky.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-57 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-57Key Management RecommendationsQuantum risk here depends on key and algorithm lifecycle planning.
Recommendation — Define key rotation and retirement timelines that support post-quantum migration.
ISO/IEC 27001:2022A.8.24 — Use of cryptographyCryptography roadmap gaps directly affect how cryptographic controls are selected and maintained.
A.5.15 — Access controlEncryption roadmaps often fail when access, trust, and protected assets are not inventoried together.
Recommendation — Review cryptographic controls and migration plans under the ISMS. Map protected assets and access dependencies before changing cryptography.

Practitioner Guidance

What to verify: Ask whether the organisation can produce a cryptographic inventory that maps where encryption, signing, and certificates are used, which data depends on them, and which systems have the longest protection horizon. If that inventory does not exist, the quantum programme is already behind.

Decision rule: If the team cannot name a tested migration milestone for high-value or long-lived data, treat the roadmap as incomplete even if executive awareness is high. Prioritise systems where confidentiality, integrity, or signature validity must outlast current algorithm assumptions.

Practitioner takeaway: The strongest indicator of readiness is not a statement that quantum is being watched, but evidence that the organisation knows what must change first, by when, and under which operational owner.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org