# SP-040 Post-Quantum Cryptography and Quantum Readiness

Status: active. Release 26.02. Modified 2026-02-09. Licence: CC BY-SA 4.0.

Scope: Architecture pattern for migrating enterprise cryptographic infrastructure to post-quantum algorithms. Covers crypto agility, cryptographic inventory (CBOM), hybrid key exchange, PQC certificate migration, HSM readiness, and phased migration planning aligned with NIST FIPS 203/204/205, CNSA 2.0, and NCSC timelines.
Use when: Any organisation handling data with long-term confidentiality requirements (government, financial services, healthcare, legal, IP-intensive industries). Organisations subject to CNSA 2.0 (US government contractors, defense), NCSC guidance (UK regulated entities), or BSI recommendations (German/EU regulated entities).
Not when: Organisations with exclusively short-lived data and no regulatory cryptographic requirements may defer migration planning, though crypto agility investment still provides value against classical algorithm compromises.

## Controls (26, NIST SP 800-53 ids)
- Critical (6): SC-12, SC-13, SC-17, CM-08, SC-08, SI-07
- Important (13): SA-08, SA-17, SA-04, SR-03, SR-04, SR-05, IA-05, SC-28, CM-14, PL-02, CP-02, CA-07, PM-05
- Standard (7): PM-01, PM-14, AU-06, AC-03, AC-06, SC-07, SC-23

## What each critical control mitigates (6)
- SC-12 Cryptographic Key Establishment and Management: T-40-001, T-40-002, T-40-007
- SC-13 Cryptographic Protection: T-40-001, T-40-002, T-40-004, T-40-008, T-40-009, T-40-011
- SC-17 Public Key Infrastructure Certificates: T-40-002, T-40-007
- CM-08 System Component Inventory: T-40-003
- SC-08 Transmission Confidentiality and Integrity: T-40-001, T-40-010
- SI-07 Software, Firmware, and Information Integrity: T-40-008

## Threats and the controls that mitigate them (12)
- T-40-001 Harvest Now Decrypt Later (HNDL) — Nation-state adversaries archive encrypted traffic for future quantum decryption, exposing data with long-term confidentiality requirements: SC-08, SC-12, SC-13
- T-40-002 Cryptographically Relevant Quantum Computer (CRQC) emergence — Shor's algorithm breaks RSA, ECDSA, ECDH, EdDSA, DH, rendering all classical asymmetric cryptography obsolete: SC-12, SC-13, SC-17
- T-40-003 Incomplete cryptographic inventory — Unknown algorithm usage across the estate prevents systematic migration, leaving quantum-vulnerable endpoints undiscovered: CM-08, PM-05, SA-04
- T-40-004 Hard-coded cryptography — Applications with algorithm choices embedded in source code resist agile migration, creating persistent quantum-vulnerable endpoints: SA-08, SA-17, SC-13
- T-40-005 Supply chain cryptographic dependency — Vendor products using quantum-vulnerable algorithms with no firmware upgrade path, blocking migration of dependent systems: SR-03, SR-04, SR-05, SA-04
- T-40-006 Legacy system stranding — OT/ICS and embedded systems with 15-30 year lifecycles and non-upgradeable firmware that cannot support PQC algorithms: SR-03, SC-07, CP-02
- T-40-007 Certificate infrastructure disruption — PKI unable to issue, distribute, or validate PQC or hybrid certificates, breaking authentication chains during migration: SC-17, IA-05, SC-12
- T-40-008 Signature forgery and non-repudiation loss — Quantum computers forge digital signatures on contracts, code, firmware, and regulatory filings, undermining legal and operational trust: SI-07, CM-14, SC-13
- T-40-009 Premature PQC algorithm compromise — A selected algorithm (e.g., lattice-based) is cryptanalytically broken before migration completes, requiring emergency fallback to alternative mathematical families: SC-13, CP-02, SA-08
- T-40-010 Migration window exhaustion — Data shelf life plus migration time exceeds time until CRQCs (Mosher equation: X+Y > Z), meaning sensitive data is already irrecoverably exposed: PL-02, PM-01, SC-08
- T-40-011 Performance degradation from PQC overhead — Larger key sizes, signature sizes, and handshake payloads degrade performance on constrained devices, high-throughput systems, and bandwidth-limited channels: SA-08, SC-13, CA-07
- T-40-012 Regulatory non-compliance — Failure to meet CNSA 2.0, NIST IR 8547, NCSC, or BSI PQC migration deadlines, resulting in loss of operating authority, contract disqualification, or regulatory sanction: PL-02, CA-07, PM-14

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-040/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-040/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 23 KB: /api/v1/patterns/SP-040
- Page for people: /patterns/sp-040/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-032 Modern Authentication; SP-033 Passkey Authentication; SP-039 Client-Side Encryption and Data Privacy; SP-029 Zero Trust Architecture

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
