NSA's concrete steps for industry and NSS: set up quantum-resistant certificate authorities, support ML-KEM-1024 in standards and ML-DSA-87 (not HashML-DSA-87). Identity is only as secure as its weakest link: while any identity in a network is quantum-vulnerable the network can be impersonated, so only complete transition, including revoking or expiring quantum-vulnerable credentials, brings quantum resistance; encryption, by contrast, gains protection device by device. NSA's notional schedule: a quantum-resistant root in year 1, quantum-resistant credentials for all new devices in year 2, a switch to fully quantum-resistant protocols by software update and the start of deliberate retirement of equipment that cannot be upgraded in year 3, and turning off the traditional PKI root considered from year 4. The DoW PKI plans a quantum-resistant root in 2027.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.