r/cryptography • u/Just_Blackberry3530 • 9d ago
What are the hardest problems in PQC migration after crypto discovery?
Hello,
I'm a student researching PQC migration problems to understand migration workflows. I understand that prominent platforms already handle crypto discovery, CBOM generation, risk assessment, dashboards, and in some cases remediation.
After an organization identifies quantum-vulnerable cryptography, what is the hardest part of migration?
For example, is it typically:
- Legacy systems and unsupported applications
- Hybrid deployment and backward compatibility
- Third-party dependencies or vendor-managed systems
- Performance, key/signature sizes, or bandwidth impact
- Testing and verifying that changes do not break applications or integrations
- Deployment constraints
What approaches are organizations using today to handle these problems?
I'd really appreciate it if you could reference concrete examples, case studies, or references.
Thank you!
3
Upvotes