A comprehensive, NIST-aligned process organized into seven phases plus continuous crypto-agility. Built on the CISA/NSA/NIST Quantum-Readiness factsheet, the NIST NCCoE Migration to PQC project (SP 1800-38), NIST IR 8547, and NIST CSWP 39 on cryptographic agility.
You can't run a multi-year cryptographic program without an owner and a mandate. The CISA/NSA/NIST factsheet makes this step one.
You cannot migrate what you cannot see. Discovery is the single hardest and most important phase, and it's mandated annually for U.S. federal systems (OMB M-23-02). Catalog every use of cryptography across the estate.
Not everything migrates at once. Rank systems so effort goes where the risk is highest first.
See Mosca's inequality for the scoring rule: if X + Y > Z, the asset is already exposed.
Turn priorities into a sequenced plan, and get ahead of the parts you don't own.
Deploy in a lab before production. The NCCoE practice guide (SP 1800-38C) emphasizes interoperability and performance testing.
X25519MLKEM768) on high-priority TLS/VPN paths — this neutralizes HNDL immediately while keeping a classical hedge.Roll out along the prioritized backlog with change control and rollback plans.
Prove the migration worked and keep it honest over time.
PQC is not a one-time swap. NIST CSWP 39 frames crypto-agility as the durable capability to change algorithms with minimal disruption.
| Need | Replace… | With (NIST) | Enterprise default |
|---|---|---|---|
| Key exchange / establishment (TLS, VPN, SSH) | RSA key transport, ECDH, DH | ML-KEM (FIPS 203) | ML-KEM-768, deployed hybrid with X25519 |
| General digital signatures (certs, tokens, docs) | RSA, ECDSA, EdDSA | ML-DSA (FIPS 204) | ML-DSA-65 |
| Long-lived / firmware & code signing | RSA, ECDSA | SLH-DSA (FIPS 205) or stateful LMS/XMSS (SP 800-208) | SLH-DSA for conservative long-term roots |
| High-assurance / CNSA 2.0 scope | — | ML-KEM-1024 / ML-DSA-87 | Step up parameter sets |
| Bulk data encryption (at rest / in transit) | AES-128 | Symmetric stays — just size up | AES-256; SHA-256/384 for hashing |
Dates reflect published guidance and, for IR 8547, a draft that may change. See the home-page timeline for detail and confirm against primary sources.
Discovery and prioritization are where enterprises stall. The inventory page covers the discovery methods — network and TLS scanning, SIEM and log mining, source and binary analysis, endpoint agents — and how to turn their output into a CBOM.