Lewin's model: a change happens when driving forces outweigh restraining forces. Drag any slider (0–5) to re-weight a force, or pick a sector profile. Click a force name for the evidence behind it and the lever that moves it.
Enterprise cryptographic migration | Jon Silvester | v1.0 | August 2026 | Two-track model — working back from the NCSC 2035 deadline
Layered discovery across network, host and source · three parallel inventory tracks · data confidentiality horizon analysis · cryptographic bill of materials as a living record · risk-weighted migration backlog · CBOM secured and access-controlled as sensitive material
Hybrid X25519 + ML-KEM-768 on TLS 1.3 · RFC 9370 hybrid IKEv2 for VPN and IPsec · OpenSSH 9.9+ across the fleet · internal mTLS and service mesh · key wrapping for data at rest · gateway termination for constrained IoT · verify PQC is negotiated, not silently dropped
LMS/XMSS dual-signing for firmware and secure boot now · parallel PQC enterprise PKI with ML-DSA · public Web PKI via Merkle Tree Certificates · identity stack as its own CBOM slice (passkeys, tokens, PKINIT, 802.1X) · signed archives re-anchored · OT firmware and SCADA authentication
HSM and KMS PQC capability assessment and replacement schedule · certificate lifecycle automation ahead of 47-day lifetimes · middlebox and TLS-inspection testing against hybrid handshakes · policy-driven crypto abstraction · defined trigger for retiring traditional algorithms
Structured supplier questionnaires and algorithm-agility contract clauses · counterparty coordination where you cannot compel · published statement of intent · coverage metrics and evidence dossier from day one · SOC detection for classical fallback · residual risk accepted with named owners
2026 · SRO / CISO / Board
Zero float — blocks every downstream activity2027 – mid 2028 · Security architecture / asset management
Zero float — gates the NCSC 2028 milestone2027 · Information governance / risk
~6 months float — but it sets the migration ordermid 2027 at the earliest · External — NIST CMVP
Not within your control — gates regulated production2028 – 2029 · Infrastructure & procurement
Zero float — longest procurement lead time in the plan2028 · Vendor governance / commercial
Limited float — determines what you can actually migrate2032 – 2033 · PKI / identity engineering
Zero float — no quantum-safe authentication until complete2035 · CISO / SRO · evidence dossier closed
Zero float — target completion dateImpact: Traffic intercepted today cannot be un-captured; every day of delay permanently exposes data with a long confidentiality horizon. Mitigation: Start Track A hybrid key exchange on Tier-1 channels immediately, ahead of full discovery; prioritise by data lifetime, not system age.
Impact: No agreed way to carry post-quantum signatures through a decentralised ecosystem of roots, CAs, CT logs and CRL providers; Merkle Tree Certificates change the trust model itself. Mitigation: Invest in ACME automation now; keep plans flexible; track Chrome and CA roadmaps; separate public from internal PKI in the plan.
Impact: 15–40 year lifecycles, resource-constrained or unreachable devices, proprietary protocols never brought to modern cryptographic standards. Mitigation: Decide replace / gateway / isolate / tolerate per class early; align to capital replacement cycles; named exceptions with compensating controls and owners.
Impact: Hybrid TLS on top endpoints looks like success but addresses only confidentiality; an integrity gap accumulates that becomes harder to close as the programme matures. Mitigation: Run two tracks with separate milestones, budgets and reporting; launch Track B within 90 days of Track A.
Impact: Most capability is supplier-delivered, so completion dates are inherited; counterparties you cannot contractually compel gate email, federation and B2B channels. Mitigation: Questionnaires and agility clauses at every renewal; published statement of intent; coordination pattern for non-compellable parties.
Impact: Regulated and national-security environments cannot deploy PQC to production until validated modules exist, compressing an already tight execution window. Mitigation: Classify every system by environment class; pilot in unrestricted and FIPS-aware estates now; track CMVP progress as a formal dependency.
Impact: Without a defined trigger and coverage metrics, transitional hybrid modes persist indefinitely and the migration never formally closes — leaving sole dependence undetected. Mitigation: Define switch-off criteria when hybrid is introduced; quantify PQC client coverage; SOC detection for classical fallback.