Building Crypto Agility Across the Enterprise
Most organizations cannot quickly identify every place they use cryptography, much less replace it without disrupting applications and infrastructure. Building that capacity can take years, which is why CIOs and CISOs need to begin…
BankInfoSecurity
Publisher
Sep 21, 2026 at 10:11 PM UTC · 6 min read

Encryption & Key Management , Security Operations
Building Crypto Agility Across the Enterprise
Most organizations cannot quickly identify every place they use cryptography, much less replace it without disrupting applications and infrastructure. Building that capacity can take years, which is why CIOs and CISOs need to begin before post-quantum deadlines force rushed changes.
"Understanding your environment is step one," said Francis Gorman, head of the Security and Resilience Center of Excellence at Bank of Ireland. That includes locating certificates, hard-coded credentials and cryptographic libraries embedded in applications, code repositories and infrastructure.
The migration timeline has been shrinking. NIST finalized its first three post-quantum cryptography standards in 2024 and is calling on organizations to begin using them now, with quantum-vulnerable algorithms scheduled for deprecation and removal by 2035 and high-risk systems expected to transition earlier. In March, Google set a 2029 target for its own PQC migration, citing advances in quantum hardware, error correction and factoring research.
Article Intelligence
Topics
Regulation Signal
in progressUpdated a month ago
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
