Crypto-Agility: The Skill That Outlasts Every Standard

Last week I told you to pull your clients’ renewal dates and get a cryptographic inventory on file before their cyber insurer starts asking questions.

I’ve had this asked a few times now…

“What happens when the standard changes? Are we going to have to do  this again in five years?”

Yes. Probably. And that is not a problem. That is the practice.

What Crypto-Agility Actually Means

The term gets thrown around in vendor decks without much behind it. Here is the plain version.

Crypto-agility is the ability to swap cryptographic algorithms across your environment without rebuilding the systems those algorithms protect.

It sounds simple. It is not. Most environments were not designed with algorithm flexibility in mind. Encryption got baked in at the infrastructure layer, at the application layer, at the vendor layer, and nobody thought much about it because RSA worked, ECC worked, and the assumption was they would keep working indefinitely.

That assumption is now a liability. Not just because of quantum. Because the cryptographic landscape has always evolved and the organizations that treated algorithm selection as a permanent decision have paid for it every time a standard got deprecated.

TLS 1.0 went away. SHA-1 went away. MD5 went away before that. Every one of those transitions created an emergency for organizations that had no mechanism for orderly algorithm replacement. Crypto-agility is the organizational and architectural capacity to make that replacement without the emergency.

Post-quantum migration is the forcing function. But crypto-agility is the durable capability.

What It Looks Like in Practice

For your clients, crypto-agility means four things operationally.

Certificate management that is algorithm aware. Not just tracking expiry dates. Tracking which algorithm issued each certificate, what key length, what the issuing CA’s PQC roadmap looks like, and what the replacement path is when the algorithm gets deprecated. Most MSPs track expiry. Almost none track algorithm lineage. That gap is where the emergency comes from.

VPN and firewall configs that can toggle cipher suites without full redeployment. This is a procurement criterion going forward. Any new firewall, VPN concentrator, or remote access gateway that cannot swap IKE proposals and cipher suites at the configuration level without a hardware replacement is a future emergency you are pre-purchasing.

Application dependencies documented, not assumed. Every line of business app, every API integration, every vendor managed service, what cryptographic algorithms does it use, and what is the vendor’s upgrade path? Most of your clients do not know the answer. Most of their vendors will not volunteer it. You have to ask, document, and revisit on a schedule.

A change management process for cryptographic updates. When NIST publishes guidance and they will continue to, your clients need a documented path from “new standard published” to “environment updated” that does not require a crisis to initiate. A runbook. An assigned owner. A quarterly review cadence. Not complicated. Just written down.

Why This Changes How You Price the Work

Here is the shift.

If you are pricing quantum migration as a project, scoped, delivered, closed, you are pricing it wrong. Projects end. Crypto-agility is ongoing. The algorithm landscape will keep moving. Your clients’ vendor ecosystems will keep changing. New systems will get added. Old ones will get deprecated improperly.

The MSP that builds crypto-agility into a managed service line owns that client’s cryptographic posture indefinitely. Not as a liability. As a recurring revenue stream with genuine value behind it.

What that looks like in practice: a quarterly cryptographic review built into the managed services agreement. Certificate inventory updated. Algorithm deprecation notices tracked and flagged. Vendor roadmap status reviewed. New system additions assessed before deployment, not after. Documentation updated for the cyber insurer file.

That is a real deliverable. It is auditable, demonstrable, and when the insurer starts asking specific questions at renewal, it is the reason your client has answers.

Price it accordingly. This is not a line item buried in the flat rate. It is a named service with a named cadence and a named deliverable. Reviewable annually as the scope matures.

The Procurement Conversation You Need to Start Having

One more thing that does not get enough attention.

Every new infrastructure purchase your clients make from this point forward should include a crypto-agility criterion. Before any firewall, VPN, identity platform, or storage system gets approved, one question goes to the vendor: “Can I change the cryptographic algorithms this product uses without replacing the hardware or rebuilding the integration?”

If the vendor cannot answer that question clearly, document it as a risk. If the answer is no, factor in the replacement cost when the algorithm eventually changes, because it will.

You are not asking vendors to be quantum physicists. You are asking them whether they built their product with the assumption that cryptographic standards are permanent. The ones that did are going to cost your clients money in five to ten years. Better to know now.

Monday Morning Move

  1. Pick one client you are already in a migration conversation with. Ask whether their current certificate management process tracks algorithm and key length alongside expiry. It almost certainly does not. That gap is the entry point.
  2. Look at the last two infrastructure purchases that went through your approval process. Did anyone ask about cipher suite flexibility before the PO was signed? If not, add it to your procurement checklist today. One line. Costs nothing.
  3. Draft what a quarterly cryptographic review looks like as a deliverable for that client. One page. What you check, what you produce, what it costs. You do not have to sell it this week. Have it ready.

The migration gets the client to the new standard. Crypto-agility keeps them there through the next one.

Stay sharp.
The Quantum Guy

The information in this post is provided for general informational purposes only and does not constitute professional, legal, technical, or security advice. Readers act on this content at their own discretion and risk; IoTSSA assumes no liability for any loss or damage arising from its use.