Report 07 Oct 2026

Post-Quantum Security, Crypto-Agility, and Machine Identity: Rebuilding the Enterprise Trust Fabric - Market View

Post-quantum cryptography (PQC) is shifting from a standards topic to an enterprise trust, resilience, and transformation issue. NIST’s principal PQC standards are now available for implementation, the EU has established a coordinated transition roadmap, and public TLS certificate lifecycles are becoming much shorter. This means the central challenge is no longer whether organizations prepare, but whether they can identify, prioritize, fund, and replace the cryptographic mechanisms on which their business services depend.

For most enterprises, PQC migration begins with cryptographic discovery and dependency mapping. Algorithms, certificates, keys, libraries, protocols, and trust mechanisms are distributed across applications, infrastructure, cloud services, devices, and third-party products. Structured inventories, such as a cryptographic bill of materials (CBOM), can improve visibility, but they must be linked to business criticality, data confidentiality periods, system lifetimes, ownership, replaceability, and supplier dependencies. These factors determine migration priorities and help translate technical findings into realistic, multi-year migration plans and budgets.

PAC views crypto-agility as a strategic capability that makes this migration manageable and repeatable. Enterprises need continuous discovery, policy control, standardized interfaces, lifecycle automation, and migration orchestration to enable changes to algorithms, keys, and credentials without major application redesign or service disruption. During the transition, classical, hybrid, and post-quantum mechanisms will often coexist. Architectures should support interoperability testing and controlled, auditable rollback where necessary without creating permanent downgrade paths to weaker cryptography.

Machine identity is the operational layer through which this capability must increasingly operate at scale. Workloads, APIs, containers, devices, automation, and AI agents rely on certificates, keys, secrets, tokens, and workload credentials to establish trust. The challenge extends beyond managed identities. Undocumented or shadow AI agents may operate outside established IAM processes, turning discovery, ownership assignment, containment, and onboarding into identity governance prerequisites for effective access control.

Recommended advisory: PAC Leadership Session – IT Resilience & Business Continuity