NewsLayer.com

Building Crypto Agility Across the Enterprise

Most organizations cannot quickly identify every place they use cryptography, much less replace it without disrupting applications and infrastructure. Building that capacity can take years, which is why CIOs and CISOs need to begin…

BankInfoSecurity

Publisher

Sep 21, 2026 at 10:11 PM UTC · 6 min read

Building Crypto Agility Across the Enterprise
Image via BankInfoSecurity

Encryption & Key Management , Security Operations

Building Crypto Agility Across the Enterprise

A Risk-Based Approach Can Turn an Overwhelming Migration Into a Workable Plan Jennifer LawinskiSeptember 21, 2026    

Most organizations cannot quickly identify every place they use cryptography, much less replace it without disrupting applications and infrastructure. Building that capacity can take years, which is why CIOs and CISOs need to begin before post-quantum deadlines force rushed changes.

"Understanding your environment is step one," said Francis Gorman, head of the Security and Resilience Center of Excellence at Bank of Ireland. That includes locating certificates, hard-coded credentials and cryptographic libraries embedded in applications, code repositories and infrastructure.

The migration timeline has been shrinking. NIST finalized its first three post-quantum cryptography standards in 2024 and is calling on organizations to begin using them now, with quantum-vulnerable algorithms scheduled for deprecation and removal by 2035 and high-risk systems expected to transition earlier. In March, Google set a 2029 target for its own PQC migration, citing advances in quantum hardware, error correction and factoring research.