Infosecurity Europe
8-10 June 2027
Excel London

Building a Quantum-Safe Security Posture: Understanding Crypto Agility 

The countdown to a post-quantum world is no longer a theoretical exercise for cryptographers tucked away in research labs. It is now a boardroom conversation, a procurement requirement and, increasingly, a regulatory expectation.

The reason is simple: quantum computers, once they reach sufficient scale and stability, will be capable of breaking the public-key cryptography that currently underpins much of our digital infrastructure, from TLS connections and VPNs to digital signatures and blockchain wallets.

This is why, in August 2024, the US National Institute of Standards and Technology (NIST) finalised its first set of post-quantum cryptography (PQC) standards, marking a pivotal moment in the field.

The three algorithms are designed to withstand attacks from both classical and quantum computers and include:

  • ML-KEM (based on CRYSTALS-Kyber, for general encryption)
  • ML-DSA (based on CRYSTALS-Dilithium, for digital signatures)
  • SLH-DSA (based on SPHINCS+, also for digital signatures)

The publication of the NIST PQC standards effectively started the clock on a global migration effort that many experts believe will take over a decade to complete.

However, PQC is not a single, one-off upgrade that organisations can install and forget.

The transition is not just about choosing new algorithms, but also about building the capacity to continuously change them as cryptanalysis advances, vulnerabilities are discovered in supposedly "quantum-safe" schemes and standards continue to evolve.

This is where the concept of crypto agility comes in, and it is often described as the core of any credible quantum-readiness strategy.

Crypto Agility: A Definition

Crypto agility refers to a system's ability to switch, update or replace cryptographic algorithms and parameters quickly, without disrupting ongoing operations or requiring major infrastructure redesigns.

These algorithms are not confined to a single point in a network, but embedded across communications protocols, keys, certificates and countless implementations throughout an organisation's environment.

In the context of PQC, crypto-agility means having the architectural, operational and governance capabilities to transition from quantum-vulnerable cryptographic algorithms to post-quantum alternatives as standards, threats and technology evolve.

Crucially, this goes beyond simply adopting a new algorithm. It requires organisations to treat cryptography as a replaceable and manageable component of the technology stack. One that must be supported by accurate cryptographic inventories, clear visibility into dependencies, modular implementations, automated key and certificate management and robust processes for testing and deploying new cryptographic mechanisms.

Done properly, crypto-agility enables organisations to respond to emerging cryptographic threats and future changes in standards without having to undertake costly and disruptive migrations every time a cryptographic algorithm becomes obsolete or unsuitable.

NIST's Guidance on Achieving Crypto Agility

Recognising the scale of this challenge, NIST's Cryptographic Technology working group published a white paper in March 2025 titled Considerations for Achieving Crypto Agility (CSWP 39).

The paper offered an in-depth survey of current approaches and considerations for organisations seeking to build crypto-agile systems, covering everything from inventory management to protocol design.

At the end of 2025, NIST released an updated version of the paper (CSWP 39upd1), reflecting the rapid pace at which thinking in this space is evolving and underscoring just how seriously the standards body is taking the operational, and not just algorithmic, side of the PQC transition.

NCSC's Advice: Payments Industry as a Model for Crypto Agility

The UK's National Cyber Security Centre (NCSC) has also been vocal on this point. During his annual lecture in June 2026, NCSC CEO Richard Horne addressed the issue head-on.

When asked about the urgency for UK organisation to transition to quantum-safe cryptography, he acknowledged the challenge to replace cryptography to "something we know will be resistant to quantum computers."

The NCSC has set out a decade-long timeline for PQC transition, ending with complete migration in 2035. Horne noted that the real challenge in PQC implementation lies in the ability to be able to change the cryptography currently in use in a rapid timeframe.

Horne pointed to the payments industry as a model worth emulating. "Today, we're using different cryptographic algorithms to secure digital payments than were 30 years ago, because they were designed to be updated, and it's that mentality that we need in everything," he said.

In his view, the payments sector's willingness to build systems capable of evolving over decades, rather than locking in a fixed set of standards, is precisely the mindset organisations across all industries now need to adopt.

Horne also struck an optimistic note about the role cloud infrastructure could play in accelerating this shift. He suggested that as reliance on cloud services grows, the migration to quantum-safe cryptography may increasingly happen at the infrastructure level, delivering benefits at scale without each organisation having to act alone.

"The positive is that as we're using more and more cloud services, cloud infrastructure, things will get fixed at that level that then has large scale impact," he explained. Citing a conversation with a company providing content provisioning services, he noted that "about 60% of interactions between devices and cloud infrastructure that they were finding out are using those protocols."

For Horne, this was an encouraging sign that the transition is already under way in parts of the ecosystem, even if organisations are not always driving it directly. 



Crypto Agility in Practice

For vendors and enterprises alike, PQC transition longer an abstract concern. Speaking to Infosecurity, Shane Barney, CISO at Keeper Security, described the company's approach as "a multi-year, phased rollout prioritising crypto-agility over a single cutover event."

So, what does crypto-agility look like in a real environment?

Shahram Mossayebi, co-founder of Crypto Quantique, told Infosecurity: "Right now, starting a PQC transition means a huge pain to go through the whole infrastructure, all your code lines. If 10 years down the line you suddenly have to do this again, you're going to kill yourself.”

“Instead of doing that, some organisations create an abstract layer between the applications and the cryptography libraries. Rather than directly integrating the encryption algorithms into your code, you just send a command to 'encrypt' and the abstract layer connects to a security policy that says, 'For any 'encrypt,' command use this standard with these key parameters.'"

In essence, this means that every time an organisation needs to move from a current cryptographic standard to a new one, it only needs to update its security policy, and the updated encryption method is automatically populated across the entire infrastructure.

Rather than rewriting code and re-engineering systems from scratch, teams simply adjust the rules that dictate which cryptographic method should be applied.

However, not everyone views this approach as a complete solution. Patricia Titus, field CISO at Abnormal AI, cautioned that this kind of fix, while useful, risks giving organisations a false sense of completion.

She explained that such gateways are "going to create a quick fix," after which companies tend to "move on to something else" rather than continuing to address the cryptography embedded deeper within their systems.

An attacker who manages to bypass the gateway through another route would still find unchanged, vulnerable cryptography inside the environment. Organisations may have "just changed the front door keys" without having "actually fixed windows or basement doors," Titus commented.

She also cautioned against the complacency this could breed, suggesting that companies "will think I don't have to invest anymore because I bought this big gateway, and that's going to fix everything."

Continuous Cryptography Investment

Crypto-agility, while powerful, is not a silver bullet. An abstraction layer or gateway can provide a quantum-resistant front door, but if the legacy cryptography lurking deeper within the environment remains untouched, organisations risk a false sense of security.

True crypto-agility must extend throughout the entire technology stack, not just at its perimeter, and must be accompanied by sustained investment, rather than treated as a one-time purchase that "fixes" the quantum problem once and for all.


ADVERTISEMENT


Enjoyed this article? Make sure to share it!



Looking for something else?


Tags


ADVERTISEMENT


ADVERTISEMENT