Know where cryptography lives
Map algorithms, certificates, keys, libraries, and dependencies across applications, PKI, network connectivity, cloud services, and infrastructure. Identify the owner of each dependency.

Post-Quantum Cryptography & Crypto-Agility
Understand your cryptographic exposure and plan a practical transition toward quantum-resistant security.
Why preparation matters
A sufficiently capable quantum computer could undermine widely used public-key cryptography. An attacker may collect encrypted information now and attempt to decrypt it later. Long-lived sensitive information deserves attention before that capability exists.
Post-quantum cryptography uses mathematical algorithms designed to resist quantum attacks. It is different from quantum key distribution and does not require a quantum computer to use.
From readiness to a migration plan
Discuss these workstreams with IRIS to agree a scope suited to your environment. Product selection and implementation depend on verified vendor support and technical feasibility.
Map algorithms, certificates, keys, libraries, and dependencies across applications, PKI, network connectivity, cloud services, and infrastructure. Identify the owner of each dependency.
Consider how long data must remain confidential, the consequences of exposure, system replacement cycles, and the effort required to migrate. Start with business impact.
Review supported versions, implementation maturity, interoperability, hardware constraints, and vendor roadmaps. Distinguish available features from future commitments.
Define scope, dependencies, ownership, procurement requirements, and decision gates. Coordinate certificates, applications, infrastructure, and third-party services.
Agree a controlled pilot around supported technologies. Assess handshake sizes, latency, throughput, certificate handling, compatibility, monitoring, and rollback.
Develop crypto-agility through maintained inventories, clear ownership, configurable cryptographic choices, and repeatable testing and certificate lifecycle processes.
Standards, not speculation
NIST finalized three principal PQC standards in August 2024. Their roles differ; migration requires more than replacing one algorithm everywhere.
A key-encapsulation mechanism used to establish shared secrets.
Read the NIST standard ↗A lattice-based digital signature standard.
Read the NIST standard ↗A stateless hash-based digital signature standard.
Read the NIST standard ↗An algorithm standard does not certify a complete product or deployment. Evaluate the actual implementation, protocol support, and operational controls. NIST PQC project and migration guidance ↗
Practical questions
Start with discovery and prioritization. Avoid a blanket upgrade before understanding dependencies, interoperability, and the support status of each platform.
Hybrid approaches may be suitable where supported by the relevant protocol and vendors. Validate the exact implementation and operational impact rather than assuming compatibility.
No. Applicable obligations depend on your jurisdiction, sector, contracts, and systems. NIST standards are a technical reference, not automatic proof of Saudi or Jordanian regulatory compliance.
Your critical applications, PKI and certificate architecture, VPN and network platforms, data retention requirements, vendor landscape, and planned technology refreshes.
Plan your next step
Discuss your environment and priorities with our team to define the appropriate assessment scope.