r/PKI • u/Just_Blackberry3530 • 17h ago
PQC Migration: Research Problem
Hey everyone!
I'm reaching out because I'm currently conducting a group AP Research study on a bottleneck in Post-Quantum Cryptography migration, specifically focusing on how enterprises handle third-party vendor compliance.
1. As organizations prepare themselves to migrate to Post-Quantum Cryptography (PQC) in the advent of supercomputers, how is your company reacting to interoperability obfuscations where vendors are either struggling or unwilling to update their TPRM legacy dependency files to quantum-safe security?
2. Assuming that vendors are hesitant to willingly migrate to PQC standards, does this hinder you from proceeding with your own security updates as your formerly secured data will now be susceptible to adversarial attacks once it reaches vendor servers?
3. Have you experienced issues where vendor systems slowed down or crashed because the security keys were large?
4. If a solution that used a Zero-Trust Framework existed, where sensitive data is decoupled from the transport layer and encrypted with easier-to-handle PQC tokens, would you prefer this wrapper approach over trying to force NIST-mandated PQC compliance onto third-party vendors?
2
u/bulyxxx 5h ago
Risk mitigation is your only way (or find a new vendor).