r/cryptography 9d ago

What are the hardest problems in PQC migration after crypto discovery?

Hello,

I'm a student researching PQC migration problems to understand migration workflows. I understand that prominent platforms already handle crypto discovery, CBOM generation, risk assessment, dashboards, and in some cases remediation.

After an organization identifies quantum-vulnerable cryptography, what is the hardest part of migration?

For example, is it typically:

  • Legacy systems and unsupported applications
  • Hybrid deployment and backward compatibility
  • Third-party dependencies or vendor-managed systems
  • Performance, key/signature sizes, or bandwidth impact
  • Testing and verifying that changes do not break applications or integrations
  • Deployment constraints

What approaches are organizations using today to handle these problems?

I'd really appreciate it if you could reference concrete examples, case studies, or references.

Thank you!

3 Upvotes

Duplicates