CRYPTOGRAPHY · CRYPTO AGILITY · PQC

Cryptography is changing. Your operating model has to change with it.

The transition is not only about choosing new algorithms. It starts with knowing where cryptography is used, who owns it, what depends on it and how fast it can be changed.

CLASSICAL

RSA · ECC · TLS

Understand the algorithms and certificate dependencies that protect today's services.

PQC

ML-KEM · ML-DSA · SLH-DSA

NIST finalized its first three principal post-quantum standards in 2024 and recommends organizations begin migration work now.

CRYPTO AGILITY

Inventory before migration

A migration plan needs dependency visibility, algorithm inventory, prioritization and repeatable change processes.

WEB PKI

Public TLS is moving to shorter certificate lifetimes.

CA/Browser Forum SC081 reduces maximum public TLS certificate validity to 200 days from March 15, 2026, 100 days from March 15, 2027, and 47 days from March 15, 2029. Domain/IP validation reuse also falls to 10 days in 2029.

15.03.2026≤ 200 days
15.03.2027≤ 100 days
15.03.2029≤ 47 days

Primary references

CA/Browser Forum Server Certificate Baseline Requirements · NIST FIPS 203, 204, 205 · NIST Post-Quantum Cryptography project.