Crypto-agility now, quantum-safe by 2027.
NIST finalised the first PQC standards in 2024 (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA). FlyttGo runs a public crypto-agility programme migrating every public-key surface to hybrid classical + PQC ahead of the harvest-now-decrypt-later horizon.
Four anchors for the post-quantum migration.
- PQ.PR.01
NIST FIPS 203/204/205 alignment
Targeting NIST-finalised primitives — ML-KEM (Kyber, FIPS 203) for key establishment, ML-DSA (Dilithium, FIPS 204) for signatures, SLH-DSA (SPHINCS+, FIPS 205) as a hash-based fallback signature. ETSI / ENISA profile guidance tracked alongside.
- PQ.PR.02
Hybrid classical + PQ first
No primitive swap-and-pray. Every PQ-vulnerable surface migrates through a hybrid stage where the classical algorithm and the PQ algorithm are both in force. Withdrawal of the classical algorithm only after the PQ algorithm has matured in production.
- PQ.PR.03
Crypto-agility by construction
Algorithm identifiers are first-class throughout the platform — TLS suite registry, JWS algorithm header, Sigstore signature manifest. Adding or retiring a primitive is a config change, not a redeploy. New NIST onramps are absorbed as they land.
- PQ.PR.04
Harvest-now-decrypt-later defence
Long-confidentiality data (audit logs, identity records, regulated payments) gets PQ-resistant transport priority. The window for an adversary to capture-and-store traffic against a future cryptographically-relevant quantum computer closes first on the highest-stakes flows.
Eight cryptographic surfaces, one migration plan.
Each row tracks where a primitive lives today, what it migrates to, and what stage it's at. Symmetric primitives (AES-256-GCM, SHA-2/3) are already PQ-resistant; only public-key surfaces need the migration.
| Code | Surface | Current | Target (PQ-hybrid) | Status | Target |
|---|---|---|---|---|---|
| PQ.M01 | TLS · transport security | TLS 1.3 · X25519 + secp256r1 | TLS 1.3 + X25519MLKEM768 (hybrid) | In flight | Q3 2026 |
| PQ.M02 | mTLS · service-to-service | TLS 1.3 + mutual auth | TLS 1.3 + ML-KEM hybrid + ML-DSA certs | In flight | Q4 2026 |
| PQ.M03 | Code-signing · Sigstore releases | ECDSA P-256 + RSA-2048 | Hybrid ECDSA + ML-DSA (Dilithium) | In flight | Q3 2026 |
| PQ.M04 | JWT / signed agent tokens | EdDSA Ed25519 | Ed25519 + ML-DSA (hybrid JWS) | Planned | Q4 2026 |
| PQ.M05 | Webhook signatures | HMAC-SHA256 | HMAC-SHA256 + ML-DSA optional layer | Planned | Q1 2027 |
| PQ.M06 | Identra · qualified signatures | ECDSA P-256 / RSA-2048 | Hybrid ECDSA + ML-DSA (eIDAS-aligned) | Planned | Q2 2027 |
| PQ.M07 | At-rest encryption (KMS keys) | AES-256-GCM · KMS-managed | AES-256-GCM (already PQ-resistant) | Live | n/a |
| PQ.M08 | BYOK · sovereign tenant keys | KMIP / PKCS#11 RSA-2048 | KMIP / PKCS#11 with ML-KEM key wrap | Planned | Q2 2027 |
- PQ.RG.01
NIST FIPS 203/204/205
Final standards (2024) — ML-KEM, ML-DSA, SLH-DSA. Reference primitives for the migration.
- PQ.RG.02
NSA CNSA 2.0 · 2030 / 2035
NSA Commercial National Security Algorithm Suite 2.0 — full transition by 2030 for software/firmware signing, by 2035 for everything else.
- PQ.RG.03
CNSSP 15 · classified networks
Committee on National Security Systems Policy 15 — PQ migration mandate for US national-security workloads.
- PQ.RG.04
BSI · TR-02102 (Germany)
German BSI cryptographic recommendations include PQC primitives; updated annually.
- PQ.RG.05
ENISA · PQ migration guidance
EU-wide PQ migration recommendations; member-state regulators draw from this baseline.
- PQ.RG.06
ETSI PQC profiles (in flight)
ETSI eIDAS-aligned PQC profile expected 2026; required for qualified-signature migration.
Cryptographic agility is one layer of the trust posture.
Post-quantum migration sits inside the broader security and trust framework. The four pathways below take a programme from this statement to a signed engagement under MNDA.
- CR.00
Security architecture
SOC 2 controls, ISO 27001 scope, the cryptography this PQ plan migrates from.
CR.00 · TS.00 - TC.00
Trust artefacts
SOC 2, ISO 27001, DPA, subprocessors. Full PQ technical brief available under MNDA.
TC.00 · 8 artefacts - RM.00
Public roadmap
PQ migration milestones tracked publicly with quarterly slip explanations.
RM.00 · quarterly - CB.00
Open a PQ scoping
Routed under CT.01 Platform Architecture Session — for buyers wanting tenant-specific timing.
CT.01 · CB.00