Planning for post-quantum cryptography – Part 1: Know what you have

Planning for post-quantum cryptography – Part 1: Know what you have

A cryptographically relevant quantum computer (CRQC), when it becomes available, will threaten the security of systems that rely on traditional (also known as classical) asymmetric cryptographic algorithms.

Preparing for post-quantum cryptography (PQC) starts long before the quantum threat arrives. To help organisations take practical steps now, our LATICE framework provides a structured approach to transitioning to PQC.

This article is part of an ongoing series exploring each phase of the framework:

  • LOCATE and inventory the use of traditional asymmetric cryptography.
  • ASSESS the value and sensitivity of systems and data protected by traditional asymmetric cryptography.
  • TRIAGE systems using traditional asymmetric cryptography and prioritise individual systems for transition.
  • IMPLEMENT post-quantum cryptographic algorithms throughout systems.
  • COMMUNICATE with vendors and stakeholders, and EDUCATE and train relevant stakeholders on the PQC transition.

The Australian Signals Directorate will continue to update its guidance as standards, technologies and the quantum threat landscape evolve. For our latest quantum-related cyber security advice, visit cyber.gov.au/quantum

Part 1 of LATICE: Locate and inventory cryptographic dependencies

If the transition to PQC is a journey, the locate phase is where every organisation must begin.

Before systems can be assessed or prioritised for transition, organisations need a clear answer to the question: where is traditional asymmetric cryptography actually used today?

In practice, this can prove more difficult than it seems.

Cryptographic algorithms are the foundation for authentication, digital signatures and encrypted communications. However, their use is often not captured in a single place.

Gaining visibility of all cryptography used across an information technology (IT) environment can be challenging, as it may be:

  • tightly coupled to, or hard‑coded into, bespoke applications
  • embedded in operational technology or hardware
  • packaged within vendor platforms and cloud services
  • buried inside protocols, libraries or compiled binaries.

This lack of visibility is precisely why locating and inventorying cryptographic dependencies is a crucial first step in our LATICE framework.

Locating cryptography matters

The transition to PQC is a significant migration that will affect IT environments of all shapes and sizes. Such a widespread change can take time, even where the transition path is straightforward, and in some cases may require replacing existing products entirely.

Many organisations operate on multi‑year refresh cycles, and long-lived legacy systems can limit how quickly organisations are able to change or upgrade. Without early discovery, critical dependencies can remain hidden until late in an organisation’s PQC transition, increasing risk, cost and disruption.

It’s also important to consider the long-term protection of data and digital signatures. Data that must remain confidential, and trust services that rely on authentication and must remain trustworthy, for many years may already be at risk of future compromise from a CRQC. This includes risks to confidentiality through ‘harvest now, decrypt later’ attacks, as well as risks to integrity and trust through ‘trusted now, forged later’ scenarios.

Understanding where asymmetric cryptography protects sensitive data and underpins trust services is essential to managing this risk.

What to initially focus on

The locate phase doesn’t need to be perfect from the start, but it should be deliberate, systematic and ongoing. Organisations should start by identifying:

  • where cryptography is implemented, including across applications, public key infrastructure, certificates, network devices, cloud services and embedded systems
  • which asymmetric algorithms are in use, including key sizes and parameters
  • what data and systems are protected, particularly those with long‑term confidentiality requirements
  • who owns or is responsible for each dependency, including system owners, vendors and lifecycle constraints.

A cryptographic bill of materials (CBOM) provides a practical way to document cryptographic dependencies at both environment and system levels. While an organisation’s initial CBOM may be high-level and simple, it provides a crucial foundation for ongoing assessment and prioritisation.

Progress beats perfection

Even for organisations that have mature management of software supply chains and software bill of materials (SBOM), it’s unlikely that any single tool will provide an organisation with complete visibility of their estate. Cryptographic discovery, and the building of an inventory and an initial CBOM, will likely consume data from a range of sources. This includes:

  • SBOM and software supply chain management systems
  • automated asset discovery and vulnerability management tools
  • configuration management tooling or static configuration files
  • systems that manage your certificates and keys, such as Public Key Infrastructure and key management
  • software, security and architecture reviews
  • engagement with vendors and system owners.

While undertaking this cryptographic discovery as part of the locate phase, organisations may identify instances where existing cryptographic implementations don’t meet intended security goals, or where data that should be cryptographically protected is not. These insights are valuable to uplifting existing security posture while preparing for the transition to PQC.

The key for organisations is to start early and iterate. A planned, partial cryptographic inventory maintained over time is more valuable than a perfect one attempted too late.

Looking ahead

The locate phase underpins every step that follows in the transition to PQC. Once cryptographic dependencies are visible, organisations can move beyond discovery and begin to understand which systems, data and implementations matter most.

Next, we’ll explore the assess phase which uses this cryptographic visibility to evaluate risk, business impact and transition urgency.

For more information, refer to our publication on planning for post-quantum cryptography.

Its a good overarching approach. I've looked to work in other similar frameworks, tools and templates to help guide more detail, decision making and land it into long term operations and governance.

Like
Reply

Great advice ASD, I see LATICE as a sound iterative risk management methodology leading to better crypto security.

Like
Reply

Love this! The same methodology can be applied to protective security by industry to LOCATE what is valuable and what is vulnerable. Fabulous comms, ASD 👏

Like
Reply

Locate is the step most organisations underestimate, you can't assess or prioritise a migration for cryptography you don't know exists across your environment. Asymmetric cryptography tends to be buried in places nobody thinks to audit, legacy certificates, embedded firmware, third-party libraries nobody's touched since deployment. My work experience has taught me that discovery is always the slowest and least glamorous phase of any large migration, and it's also the phase that determines whether every later step actually works. A framework that starts with an honest inventory rather than jumping straight to remediation is the right sequencing for something this foundational. 𝘈𝘭𝘭 𝘷𝘪𝘦𝘸𝘴 𝘦𝘹𝘱𝘳𝘦𝘴𝘴𝘦𝘥 𝘢𝘳𝘦 𝘮𝘺 𝘰𝘸𝘯 𝘢𝘯𝘥 𝘥𝘰 𝘯𝘰𝘵 𝘳𝘦𝘱𝘳𝘦𝘴𝘦𝘯𝘵 𝘵𝘩𝘦 𝘈𝘶𝘴𝘵𝘳𝘢𝘭𝘪𝘢𝘯 𝘈𝘳𝘮𝘺, 𝘵𝘩𝘦 𝘈𝘶𝘴𝘵𝘳𝘢𝘭𝘪𝘢𝘯 𝘋𝘦𝘧𝘦𝘯𝘤𝘦 𝘍𝘰𝘳𝘤𝘦, 𝘰𝘳 𝘵𝘩𝘦 𝘕𝘚𝘞 𝘎𝘰𝘷𝘦𝘳𝘯𝘮𝘦𝘯𝘵.

Like
Reply

To view or add a comment, sign in

More articles by Australian Signals Directorate

Others also viewed

Explore content categories