← Blog

Post-Quantum Migration Starts with a Cryptographic Asset Inventory

Find certificates, keys, protocols and supplier dependencies before choosing replacement algorithms.

Post-Quantum Migration Starts with a Cryptographic Asset Inventory

Know where public-key cryptography is used

NIST approved FIPS 203, 204 and 205 in 2024 for post-quantum key establishment and digital signatures. Approval of standards does not mean an enterprise can replace every certificate or device at once. First identify internet-facing services, internal TLS connections, VPNs, code signing, identity systems, firmware updates and long-lived protected records. Record the algorithm, protocol, key length, owner, vendor, renewal date and the data lifetime for each use.

Map dependencies and priorities

A certificate may be generated by one team, stored in another platform and consumed by many applications. Link each cryptographic asset to the service it protects and the supplier that must support an upgrade. Prioritize data that must remain confidential for many years, critical communications and hardware with long replacement cycles. Validate whether suppliers offer interoperable implementations and whether current monitoring can identify algorithm use. This is an inventory and planning exercise, not a claim that a quantum computer is breaking current production systems today.

Plan migration as a programme

The UK NCSC recommends completing discovery and an initial plan by 2028, the highest-priority activities by 2031 and migration by 2035. These are UK guidance milestones, not universal legal deadlines. An enterprise can set its own timetable after risk assessment, test representative systems, preserve rollback options and update procurement requirements. Revisit the inventory whenever certificates, software or suppliers change.