Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)
Step 3: execution – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024) IMPL: Use evaluated, production-ready implementations and track implementation weaknesses

A sound algorithm can be undermined by its implementation, so the organisation decides how far each application must resist side-channel analysis, fault injection and differential fault analysis (resistance to timing attacks is essential, with constant-time code), leaves implementation to experts, and deploys production-ready implementations that have passed security evaluation, such as FIPS 140 or ISO/IEC 19790 module validation, Common Criteria (ISO/IEC 15408) or the Dutch BSPA, performed by accredited laboratories; reference implementations and the Open Quantum Safe libraries are stand-ins for development, not production. Integrators follow standards and certification developments and published vulnerabilities throughout the product life cycle, consider combining software and hardware solutions, and consider reconfigurable hardware where field updates are needed.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • P-EVAL P-EVAL Products protecting NSS evaluated or validated under CNSSP 11 or NSA guidance; NSA-approved solutions for classified data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Step 3: execution – Netherlands PQC Migration Handbook (AIVD, CWI, TNO, 2nd Edition 2024)

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.