乌鸦传媒

Skip to Content

Crypto-agility: The unsung hero in the quantum security race

Marco Pereira
Jul 29, 2025

In the global race to secure digital infrastructure against quantum threats, post-quantum cryptography (PQC) often takes the spotlight 鈥 and rightly so. Quantum computing has the potential to break the cryptographic systems that currently protect our data, communications, and national infrastructure.

But there鈥檚 another capability that deserves equal attention 鈥 crypto-agility. Quietly, but powerfully, it is emerging as the foundational layer upon which a truly quantum-resilient future will be built.

What is crypto-agility 鈥 and why it matters

Just as security by design and, more recently, privacy by design have become essential principles in the development of modern IT solutions, it’s time to embrace a new imperative: crypto-agility by design. In a world where cryptographic algorithms can become obsolete overnight 鈥 due to advances in computing power, quantum threats, or newly discovered vulnerabilities 鈥 crypto-agility is no longer optional.

Crypto-agility is the ability to swiftly switch between cryptographic algorithms 鈥 whether in response to a new vulnerability or to adopt an emerging standard 鈥 without disrupting operations. It鈥檚 not about replacing cryptography once; it鈥檚 about building the flexibility to respond again and again as threats evolve, and standards mature.

This proactive approach ensures long-term resilience and trustworthiness, much like how security and privacy are now embedded from the ground up. As digital ecosystems grow more complex and interconnected, crypto-agility must become a foundational design principle 鈥 not an afterthought.

Quantum computing isn鈥檛 the only threat. The recent vulnerabilities in widely used libraries like OpenSSL are stark reminders of how brittle our current cryptographic landscape can be. Yet, our recent CRI research reveals a troubling picture:

  • Only 35% say their organizations maintain a centralized inventory of all cryptographic keys, algorithms, and certificates in use.
  • 54% of organizations operate on legacy infrastructure that lacks compatibility with modern cryptographic standards.
  • Just 40% are prepared to respond effectively to the discovery of a critical vulnerability in a widely used cryptographic library.

These are not just technical blind spots 鈥 they are business risks.

Building crypto-agility: What it takes

Crypto-agility isn鈥檛 a feature you can simply buy off the shelf. It must be intentionally designed into your systems, processes, and organizational culture. Here鈥檚 what that journey looks like:

  • Maintain a live cryptographic inventory: Know which algorithms, keys, and certificates are in use 鈥 and where they reside.
  • Automate key and certificate management: Manual processes cannot keep up with today鈥檚 evolving threat landscape.
  • Design modular, update-ready systems: Avoid hard-coded cryptography. Use configuration files and CI/CD pipelines for rapid updates.
  • Rotate keys regularly: Annual key rotation should be the baseline 鈥 automated rotation is even better.

The barriers are real 鈥 but so are the rewards

Crypto-agility is not just a technical challenge; it鈥檚 an organizational shift. Our CRI research shows that:

  • 67% of organizations struggle with dedicated budget and personnel for crypto transitions.
  • 59% lack the expertise to assess, plan, and implement crypto-agility.
  • 54% operate on legacy infrastructure that鈥檚 incompatible with modern standards.

These numbers reflect inertia 鈥 but they also highlight the opportunity for leaders to act before the curve. As Bernd Meurer, Field CTO at BT Group, notes:

鈥淢any of our customers have done a high-level assessment of systems and communication interfaces, but a full impact analysis for post-quantum readiness is still in draft in many cases.鈥 

This is the reality for many large enterprises 鈥 and a call to action for all.

Some early adopters are embedding crypto-agility into their PQC pilots through hybrid cryptography, which combines classical and quantum-safe algorithms. This allows them to test emerging standards without breaking existing systems.

A strategic advantage in the post-quantum era

Crypto-agility is the bridge between today鈥檚 encryption and tomorrow鈥檚 post-quantum world. It enables resilience not just against quantum, but also against the unknowns that lie ahead in our increasingly complex threat landscape.

At 乌鸦传媒, we believe that crypto-agility is no longer a 鈥渘ice to have.鈥 It鈥檚 a core business capability, and a marker of forward-thinking leadership. Organizations that build it now will gain the flexibility to evolve, adapt, and thrive 鈥 no matter how the future unfolds.

The quantum era is coming.
Crypto-agility will define who鈥檚 ready.

About the author

Marco Pereira

Global Head of Cybersecurity, Cloud Infrastructure Services
Marco is an industry-recognized cybersecurity thought leader and strategist with over 25 years of leadership and hands-on experience. He has a proven track record of successfully implementing highly complex, large-scale IT transformation projects. Known for his visionary approach, Marco has been instrumental in shaping and executing numerous strategic cybersecurity initiatives. Marco holds a master鈥檚 degree in information systems and computer engineering, as well as a Master of Business Administration (MBA). His unique blend of technical expertise and business acumen enables him to bridge the gap between technology and strategy, driving innovation and achieving organizational goals.