NIST Publishes the First PQC FIPS Standards
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) are formally published.
Inventory cryptographic assets first, then plan the migration sequence.
CHANGING starts with Crypto Asset Inventory, quantum risk prioritization, and PQC compatibility validation to plan migration paths for PKI, HSM, KMS, CLM, Code Signing, as well as device-side Secure Boot, Firmware Signing, OTA, and Crypto Agility.
Identify where RSA, ECC, and other cryptographic technologies are used, then prioritize risks and assess algorithm-switching readiness.
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) are formally published.
Taiwan and the EU advanced PQC migration guidance, prompting enterprises to begin cryptographic asset inventories and migration prioritization.
Financial-sector guidance focuses on cryptographic asset inventories, risk prioritization, and phased migration, while Taiwan's ACS plans to release a government PQC migration policy by year-end.
Key EU CRA requirements take effect, strengthening expectations for security updates and vulnerability management.
Note: Legal effect and scope vary. Requirements depend on industry, product, and jurisdiction.
If any of these apply, start by mapping cryptographic assets and prioritizing risks for migration planning.
R&D, financial, personal, or critical operational data that remains sensitive for years should be assessed for Harvest Now, Decrypt Later (HNDL) risk.
Extensive use of certificates, TLS, VPN, Code Signing, APIs, or device identity can broaden the migration scope.
Long-lifecycle IoT, industrial, automotive, server, and critical devices must account for future algorithm updates and resource constraints.
Financial services, critical infrastructure, and EU-bound products should prepare migration rationale and records early.
Inventory and POC results help prioritize risks and guide PQC migration decisions.
A Crypto Asset Inventory maps algorithms, keys, certificates, libraries, security hardware, owners, and dependencies for risk assessment and migration prioritization.
TLS、VPN、SSH、Digital Certificates、Root CA
Review long-term sensitive data transmission, certificate chains, protocols, and HNDL risk.
SSO、MFA、JWT、API Authentication、Device Identity
Identify the certificates, tokens, and signing mechanisms used for user, service, and device identities.
Database、File Storage、Backup、Encryption Keys
Review data protection periods, encryption methods, key storage locations, and algorithm configurations.
Crypto Libraries、Code Signing、HSM/TPM、SBOM/CBOM
Map third-party components, cryptographic libraries, signing processes, and hardware support capabilities.
Complete the inventory and technical validation first, then establish Crypto Agility. Define the migration scope and timeline based on standards, product support, and compatibility.
Use Crypto Asset Inventory results to identify long-term sensitive data, critical systems, product lifecycles, and owners, then prioritize pilots and migration based on risk.
Conduct POCs for high-priority items to validate PQC compatibility with the existing environment, performance, and resource requirements before determining the migration approach.
Reduce application dependency on specific algorithms. Use Policy, KMS, CLM, HSM, and shared cryptographic services to manage algorithm changes as standards and algorithms evolve.
Enterprise systems and commercial products differ in lifecycle, computing resources, and update mechanisms. Assess them separately,then align them through a common Crypto Policy and management framework.
Internal PKI, AD CS, TLS, VPN, employee and device certificates, SSO/MFA, ERP/HR/SCM, API/JWT, and Code Signing.
Product PKI、Device Identity、Root of Trust、Secure Boot、Firmware Signing、OTA、HSM/TPM/Security IC、SBOM/CBOM。
CHANGING focuses on PKI, identity authentication, certificate management, and key management, while Ciot extends these technologies to devices, chips, and firmware, supporting PQC migration across enterprise systems and products.
PQC migration varies by industry, depending on data retention, product lifecycles, hardware resources, and regulatory requirements.
Root of Trust, BMC, Firmware Signing, Secure Boot, platform updates, and supply chain compatibility.
TPM, Secure Boot, Firmware Update, device identity, and future algorithm update capability.
ECU/TCU, firmware signing, Secure Boot, OTA, and long-lifecycle product maintenance.
Device Identity, Device Certificate, Firmware Signing, OTA, and MCU resource constraints.
Long-running equipment, existing hardware dependencies, and limited maintenance windows may require phased migration and coexistence.
Quantum risks affecting PKI, TLS, VPN, certificates, Code Signing, APIs, and long-term sensitive data.
Start with a defined PKI, Code Signing, enterprise application, or product platform. Complete the inventory and risk prioritization first, then select an appropriate PQC pilot.
PQC (Post-Quantum Cryptography) refers to cryptographic technologies designed for the quantum computing era. Its primary goal is to reduce the future risk of quantum algorithms breaking widely used public-key cryptography such as RSA and ECC. NIST has published final standards including ML-KEM, ML-DSA, and SLH-DSA.
Usually not. A practical approach is to first identify which systems, products, and data depend on RSA or ECC, then set priorities based on data protection periods, system criticality, vendor support, and product lifecycles.
It is a traceable inventory of enterprise cryptographic assets, recording algorithms, certificates, keys, cryptographic libraries, security hardware, signing processes, system owners, and dependencies as the basis for quantum risk assessment and migration prioritization.
Crypto Agility is the ability of a system to adapt when cryptographic algorithms or standards change. The focus is on reducing application dependency on specific algorithms and managing algorithm changes and related policies through Policy, KMS, CLM, HSM, and shared cryptographic services.
PQC affects not only algorithms but also key generation, certificate formats, signing and verification, hardware support, performance, and system integration. Actual support across HSM, PKI, KMS, CLM, Code Signing, and applications therefore needs to be assessed.
Start with a clearly scoped system or product whose risks can be measured. Build a Crypto Asset Inventory, prioritize risks, and conduct a POC. Validating a defined scope first helps control cost and technical risk.