CHANGING PQC Migration Services

Inventory cryptographic assets first, then plan the migration sequence.

CHANGING starts with Crypto Asset Inventory, quantum risk prioritization, and PQC compatibility validation to plan migration paths for PKI, HSM, KMS, CLM, Code Signing, as well as device-side Secure Boot, Firmware Signing, OTA, and Crypto Agility.

Crypto Asset Inventory PQC POC Crypto Agility

PQC Has Moved from Research to Enterprise Migration Planning

Identify where RSA, ECC, and other cryptographic technologies are used, then prioritize risks and assess algorithm-switching readiness.

2024
STANDARD

NIST Publishes the First PQC FIPS Standards

FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) are formally published.

2025
GUIDANCE / ROADMAP

Taiwan and the EU Advance PQC Migration Guidance

Taiwan and the EU advanced PQC migration guidance, prompting enterprises to begin cryptographic asset inventories and migration prioritization.

2026
SECTOR GUIDANCE

Taiwan Advances PQC Migration Policy

Financial-sector guidance focuses on cryptographic asset inventories, risk prioritization, and phased migration, while Taiwan's ACS plans to release a government PQC migration policy by year-end.

2027
REGULATION

Product Lifecycle Security Requirements Take Effect

Key EU CRA requirements take effect, strengthening expectations for security updates and vulnerability management.

Note: Legal effect and scope vary. Requirements depend on industry, product, and jurisdiction.

Which Enterprises Should Start with an Inventory?

If any of these apply, start by mapping cryptographic assets and prioritizing risks for migration planning.

01

Long Data Retention Periods

R&D, financial, personal, or critical operational data that remains sensitive for years should be assessed for Harvest Now, Decrypt Later (HNDL) risk.

02

Extensive Use of PKI and Digital Signatures

Extensive use of certificates, TLS, VPN, Code Signing, APIs, or device identity can broaden the migration scope.

03

Long Product Lifecycles

Long-lifecycle IoT, industrial, automotive, server, and critical devices must account for future algorithm updates and resource constraints.

04

Regulatory or Export Market Requirements

Financial services, critical infrastructure, and EU-bound products should prepare migration rationale and records early.

Define Deliverables Before Technical Planning

Inventory and POC results help prioritize risks and guide PQC migration decisions.

01Crypto Asset InventoryCryptographic Asset Inventory
02Quantum Risk MapQuantum Risk Map
03Migration PriorityMigration Priority
04PQC POC ReportTechnical and Compatibility Validation
05Migration RoadmapPhased Migration Plan
06Crypto AgilityLong-Term Cryptographic Management

First Step to Map Where Cryptography Is Used

A Crypto Asset Inventory maps algorithms, keys, certificates, libraries, security hardware, owners, and dependencies for risk assessment and migration prioritization.

Communication Security

TLS、VPN、SSH、Digital Certificates、Root CA

Review long-term sensitive data transmission, certificate chains, protocols, and HNDL risk.

Identity and Authentication

SSO、MFA、JWT、API Authentication、Device Identity

Identify the certificates, tokens, and signing mechanisms used for user, service, and device identities.

Data and Keys

Database、File Storage、Backup、Encryption Keys

Review data protection periods, encryption methods, key storage locations, and algorithm configurations.

Software and Supply Chain

Crypto Libraries、Code Signing、HSM/TPM、SBOM/CBOM

Map third-party components, cryptographic libraries, signing processes, and hardware support capabilities.

Map Cryptographic Assets and Dependencies Across Enterprise IT and Products

ITPKI / AD CSTLS / VPN / WAFWindows / Linux
ApplicationsERP / MES / CRMJava / .NET / OpenSSLAPI / JWT / CI/CD
CloudAWS / Azure / GCPCloud PKI / KMSPQC Hybrid / POC
OT / ProductSecure BootFirmware / OTADevice Identity / SE
VendorHSM / TPM / Security ICOpen SourceVendor PQC Roadmap

Three-Phase PQC Migration Roadmap

Complete the inventory and technical validation first, then establish Crypto Agility. Define the migration scope and timeline based on standards, product support, and compatibility.

PHASE01

Inventory and Risk Identification

Use Crypto Asset Inventory results to identify long-term sensitive data, critical systems, product lifecycles, and owners, then prioritize pilots and migration based on risk.

Key DeliverablesCrypto InventoryRisk MapPriority ListInitial Roadmap
PHASE02

Architecture Adjustment and Technical Validation

Conduct POCs for high-priority items to validate PQC compatibility with the existing environment, performance, and resource requirements before determining the migration approach.

HSM & KMSKey generation, storage, and usage processes
PKI / CLMCertificate lifecycle and compatibility with new algorithms
Code SigningSigning and CI/CD integration validation
Device SecuritySecure Boot, Firmware, OTA, and resource testing
Key DeliverablesGap AnalysisPOC ReportAdjustment PlanDeployment Plan
PHASE03

Establish Crypto Agility

Reduce application dependency on specific algorithms. Use Policy, KMS, CLM, HSM, and shared cryptographic services to manage algorithm changes as standards and algorithms evolve.

Policy-based Crypto Control
TraditionalHybridPQC
PKI / CLMKMS / HSMApplication / Device
Key DeliverablesCrypto PolicyAlgorithm SwitchingMonitoringAudit Trail

Enterprise Security and Product Security Require Different Migration Priorities

Enterprise systems and commercial products differ in lifecycle, computing resources, and update mechanisms. Assess them separately,then align them through a common Crypto Policy and management framework.

Enterprise IT Environment

Internal PKI, AD CS, TLS, VPN, employee and device certificates, SSO/MFA, ERP/HR/SCM, API/JWT, and Code Signing.

Assessment FocusMap cryptographic assets and HNDL risk to support migration prioritization and shared cryptographic management.

Products and Devices

Product PKI、Device Identity、Root of Trust、Secure Boot、Firmware Signing、OTA、HSM/TPM/Security IC、SBOM/CBOM。

Assessment FocusAssess device resources, update capabilities, and product lifecycles to plan future algorithm transitions and long-term maintenance.

Assess Cryptographic Infrastructure and Product Security Together

CHANGING focuses on PKI, identity authentication, certificate management, and key management, while Ciot extends these technologies to devices, chips, and firmware, supporting PQC migration across enterprise systems and products.

PKI / HSM / KMSCryptographic infrastructure spanning roots of trust, certificates, keys, and hardware protection.
CLM / Code SigningConnect algorithm transitions with certificate lifecycle and software supply chain processes.
Enterprise + DeviceCover enterprise IT, IoT/OT, Secure Boot, Firmware, and OTA.
PQC R&DObtained Taiwan invention patent I925491 for hash-based post-quantum multi-signatures in 2026.

Different Industries, Different Risk Priorities

PQC migration varies by industry, depending on data retention, product lifecycles, hardware resources, and regulatory requirements.

Servers and Data Centers

Root of Trust, BMC, Firmware Signing, Secure Boot, platform updates, and supply chain compatibility.

Commercial PCs and Endpoints

TPM, Secure Boot, Firmware Update, device identity, and future algorithm update capability.

Automotive Electronics

ECU/TCU, firmware signing, Secure Boot, OTA, and long-lifecycle product maintenance.

IoT and Smart Devices

Device Identity, Device Certificate, Firmware Signing, OTA, and MCU resource constraints.

Industrial and OT

Long-running equipment, existing hardware dependencies, and limited maintenance windows may require phased migration and coexistence.

Financial Services and Enterprise IT

Quantum risks affecting PKI, TLS, VPN, certificates, Code Signing, APIs, and long-term sensitive data.

Start with a Clearly Defined Scope

Start with a defined PKI, Code Signing, enterprise application, or product platform. Complete the inventory and risk prioritization first, then select an appropriate PQC pilot.

Discuss a PQC Pilot

PQC FAQ

What is PQC?

PQC (Post-Quantum Cryptography) refers to cryptographic technologies designed for the quantum computing era. Its primary goal is to reduce the future risk of quantum algorithms breaking widely used public-key cryptography such as RSA and ECC. NIST has published final standards including ML-KEM, ML-DSA, and SLH-DSA.

Do RSA and ECC Need to Be Replaced Immediately?

Usually not. A practical approach is to first identify which systems, products, and data depend on RSA or ECC, then set priorities based on data protection periods, system criticality, vendor support, and product lifecycles.

What is a Crypto Asset Inventory?

It is a traceable inventory of enterprise cryptographic assets, recording algorithms, certificates, keys, cryptographic libraries, security hardware, signing processes, system owners, and dependencies as the basis for quantum risk assessment and migration prioritization.

What is Crypto Agility?

Crypto Agility is the ability of a system to adapt when cryptographic algorithms or standards change. The focus is on reducing application dependency on specific algorithms and managing algorithm changes and related policies through Policy, KMS, CLM, HSM, and shared cryptographic services.

How Does PQC Relate to HSM, PKI, and KMS?

PQC affects not only algorithms but also key generation, certificate formats, signing and verification, hardware support, performance, and system integration. Actual support across HSM, PKI, KMS, CLM, Code Signing, and applications therefore needs to be assessed.

Where Should Enterprises Start with PQC Adoption?

Start with a clearly scoped system or product whose risks can be measured. Build a Crypto Asset Inventory, prioritize risks, and conduct a POC. Validating a defined scope first helps control cost and technical risk.