Frameworks / NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) / PQC-5 NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
Inventory and Migration
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205) PQC-5: Cryptographic Inventory and PQC Migration Roadmap Establish comprehensive cryptographic inventory per NIST SP 1800-38 covering: algorithms in use + key sizes + storage location + system dependencies + protocol bindings (TLS/IPsec/SSH/PKI/HSMs) + applications + microservices + IoT/OT devices. Develop PQC migration roadmap per CNSA 2.0 timeline (2025 transition for new procurements + 2030 software/firmware/services + 2031 NSS networks + 2033 NSS endpoints + 2035 full transition) + White House M-22-09 federal civilian deadlines + ENISA recommendations + NIST SP 800-208 stateful HBS for current use. Prioritise high-risk systems: long-lived encrypted data + harvest-now-decrypt-later (HNDL) threat + root CAs + identity certificates.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 88 controls across 54 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-19 Certificate management AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection CJIS-8 Media Protection CJIS-9 System and Communications Protection ISO27799-02 ePHI encryption at rest and in transit ISO27799-16 Transmission security and encryption NDPA-1 Applicability, Scope, and Carve-Outs NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-7 Cross-Border Data Transfers and International Cooperation OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse) APPI-A34 Request for Correction, Addition or Deletion ASD37-17 TLS encryption between email servers (Limited) BSI-08 Cryptographic protection of data FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 62351-9 Cyber security key management 27010-10.1 Cryptographic Protection 27011-8.3 Cryptography and key management 27400-6.2 Device Identity and Authentication 29115-7.4 Level of Assurance 4 (LoA4) LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition NAIC-2 Information Security Program (ISP) - Section 4 STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment INV-CRYPTO Build and maintain an inventory of cryptographic assets NHPA-6 Reasonable Data Security and Breach Response NJDPA-7 Data Protection Assessments and Processor Contracts NZISM-3 Personnel Security, Physical Security, and Cryptography NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-3 API Security Standards, mTLS, and Encryption OWASPAPI-6 Security Misconfiguration and Secure API Design AUPRV-4 APP 10-11 Quality, Security of Personal Information IM8-CLD.2 Cloud Security Controls ISMSP-SYS-02 Encryption Implementation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.