CISA, NSA and NIST push post-quantum cryptography roadmaps
Roadmap language sounds soft until vendors, primes and subs need visibility into quantum-vulnerable cryptography across inherited systems.
TL;DR
The Cybersecurity and Infrastructure Security Agency, National Security Agency and National Institute of Standards and Technology released “Quantum-Readiness: Migration to Post-Quantum Cryptography,” urging early planning before NIST’s first PQC standards, planned for 2024. Critical infrastructure operators, federal contractors, primes, subs and technology vendors are being told to inventory public-key cryptography, engage suppliers and assess reliance on quantum-vulnerable systems. The warning is early, but operationally concrete: without the inventory, no one knows what has to move.
The joint factsheet does not set a migration deadline. It points to the place where the deadline will hurt once it arrives: the inventory. CISA, NSA and NIST say organizations should build a quantum-readiness roadmap, identify application and functional dependencies on public-key cryptography, engage technology vendors and assess supply-chain reliance on quantum-vulnerable cryptography in systems and assets. NIST’s first post-quantum cryptography standards are planned for release in 2024, which makes this a planning notice rather than a control change.
For federal contractors and critical infrastructure suppliers, that is still real work. Primes need to know which products and services depend on public-key cryptography. Subs and independent software vendors need answers for the customer questionnaires that tend to follow federal guidance. Security and contracting teams need a defensible order for replacing or updating assets. Much of the dependency map will live outside the buyer’s own inventory, which is why the vendor guidance matters.
The open question is the mandate. CISA’s release gives no federal contractor migration timeline and no enforcement trigger for critical infrastructure operators. That is normal at this stage, but it limits the value of waiting. Once NIST finalizes the standards, the slow part will be finding where legacy cryptography is embedded and whether the vendor, prime or sub can move it.
What practitioners do now is prosaic and useful: create the roadmap, build the cryptographic inventory, identify systems and assets using quantum-vulnerable public-key cryptography, and ask vendors how they plan to support forthcoming NIST standards. That work is exactly the kind that cannot be compressed at the end.
Published ·Deep Fathom