Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)
Step 3: execution – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024) EXEC: Execute the migration carefully and keep in-house understanding

Replacements can introduce new weaknesses through a poor choice of algorithm or a configuration error, and the migration itself widens the attack surface, so the organisation executes with great care, keeps enough internal understanding of post-quantum cryptography to judge trade-offs even when the work is outsourced, keeps the asset inventory current throughout, and may start with high-priority assets while planning continues. Asymmetric cryptography is migrated first: confidentiality mechanisms (encryption, key exchange and encapsulation) are exposed to interception now for later decryption, signatures are not, and systems built to last, such as critical infrastructure, satellites and operational technology, need particular attention; symmetric algorithms and hashes are expected to stay secure, so resources go to larger symmetric keys only after all asymmetric primitives have moved.

Maintained by Gerard Blokdyk

Other controls in Step 3: execution – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.