NIST CSWP 39 is the definitive framework for achieving cryptographic agility - the capability to replace and adapt cryptographic algorithms for post-quantum readiness.
This guide covers implementation strategies, CAMM maturity tiers, and CNSA 2.0 compliance timelines. First-findings timing set during operator scoping.
~30 min readNew systems must be post-quantum compliant by January 1, 2027
Migration Reality: EnterprisePQC migration takes 5-15 years. Starting in 2026 means completion between 2031-2041. Late starts exponentially raise cost and risk.
CNSA 2.0 requires new systems to be PQC compliant
Source: NSA CNSA 2.0Validated critical findings surfaced through governed enterprise delivery
Source: Qtonic Quantum 2023-2026Rapid visibility without operational disruption
PQC migration is a fraction of this
Source: IBM Security 2024A practical framework that tells organizations exactly what 'quantum-ready' means - and how to prove it.
NIST CSWP 39(Cybersecurity White Paper 39), titled “Considerations for Achieving Cryptographic Agility,” was published by NIST in December 2025. It is the definitive U.S. government framework for organizations to achieve cryptographic agility.
Unlike previous guidance that focused solely on algorithms, CSWP 39 asks:
Algorithms will evolve. Your systems must too.
Executive accountability is now explicit.
Discovery alone is not maturity.
Claims without proof do not count.
Understanding the threat that makes this urgent - even before quantum computers arrive.
Adversaries intercept and collect your encrypted data today
Think of it like someone photocopying your locked safe. They cannot open it yet, but they have an exact copy.
Encrypted data is archived, waiting for future capabilities
That copied safe sits in their warehouse. Storage is cheap. Time is on their side.
When quantum computing matures, stored data is decrypted
Once they have a quantum "master key," every copied safe opens instantly. Your 2024 secrets become 2030 headlines.
Calculate your organization's exposure to harvest-now-decrypt-later attacks based on your data sensitivity, retention requirements, and current encryption.
Key deadlines are closer than they appear. Migration takes time you may not have.
All new deployments must be post-quantum compliant
external CRQC timing uncertainty and 2029 readiness planning
National Security Systems completely migrated
112-bit security public-key schemes disallowed
Assessment + Planning + Migration = 12-18 months minimum. Late starts compress timelines and exponentially raise cost and operational risk. Organizations starting now preserve options and control.
CSWP 39 defines six capabilities organizations must demonstrate. Here is what they mean in practice.
Know where all your encryption lives
You cannot protect what you cannot find. Manual audits miss 40-60% of cryptographic assets.
Fix the most dangerous gaps first
Not all encryption is equal. Customer data in databases matters more than internal wiki encryption.
Track progress, catch drift
Cryptographic posture changes every time you deploy code or update a library.
Prove you can swap algorithms quickly
If a flaw is found in ML-KEM tomorrow, can you switch to an alternative in weeks, not years?
Enterprise-evidence metrics and KPIs
CSWP 39 explicitly requires executive accountability. Your board will ask. Regulators will audit.
Automation-friendly configurations
Manual policy enforcement does not scale. You need programmatic guardrails.
NIST's four-tier framework for assessing organizational readiness. Tier 3 is the minimum for demonstrable compliance.
Organizations with long data retention requirements face the greatest exposure from HNDL attacks.
At-risk data: Transaction records, PII, trading algorithms
OCC/FFIEC inventory required 2025
At-risk data: PHI, clinical trials, research IP
10+ year retention creates maximum HNDL exposure
At-risk data: Classified data, NSS systems
CNSA 2.0 deadline 2027, full migration 2030
At-risk data: Trade secrets, source code, product roadmaps
Competitive value extends 5-10 years
A structured path from uncertainty to compliance, with clear outcomes at every stage.
Governed Readiness Review
Migration Planning
Adversarial Validation
Expert answers to common questions about cryptographic agility and PQC migration.
It is a framework that tells organizations how to prepare for quantum computers breaking current encryption. Think of it as a maturity checklist: Can you find all your encryption? Can you measure your progress? Can you prove readiness to regulators? CSWP 39 defines four levels of readiness, from "we have not started" to "we can adapt to new threats automatically."
The first hard deadline is January 1, 2027 for new system deployments (CNSA 2.0). But here is the catch: assessment, planning, and migration take 12-18 months minimum. If you start in late 2026, you will miss it. Organizations starting now have budget flexibility and avoid the vendor crunch.
Adversaries are recording encrypted data today, betting they can decrypt it when quantum computers mature. If your data needs to stay secret for 5+ years (M&A records, healthcare data, trade secrets), it is already at risk. The theft happened. The breach just has not been disclosed yet.
It is the ability to swap encryption algorithms without rewriting your applications. Think of it like USB: you do not care what brand of flash drive you plug in because the interface is standardized. Crypto-agile systems can switch from one algorithm to another when threats evolve.
CAMM is NIST's four-tier framework: Tier 1 (Reactive) has ad-hoc management, Tier 2 (Managed) has documented processes, Tier 3 (Standardized) has automated discovery and monitoring, Tier 4 (Adaptive) has continuous improvement. Most organizations need to reach Tier 3 minimum for compliance.
ML-KEM (FIPS 203) is the NIST-standardized post-quantum algorithm for key exchange, replacing RSA and ECDH. ML-DSA (FIPS 204) is for digital signatures, replacing RSA and ECDSA signatures. These lattice-based algorithms are the foundation of post-quantum cryptography (PQC).
Research indicates: small enterprises take 5-7 years, medium enterprises 8-12 years, large enterprises 12-15+ years. Starting migration in 2026 means completion between 2031-2041 for most organizations - potentially exceeding regulatory deadlines.
QScout produces scoped findings quickly once authorization and access are complete. A migration roadmap depends on your environment, evidence depth, and stakeholder review.
The QStrike Challenge is Qtonic Quantum's governed adversarial-validation program for buyer-approved environments. Public materials describe the challenge posture and methodology; eligibility and buyer-specific terms remain in controlled procurement. QStrike separates verified evidence, bounded analysis, and unresolved assumptions under scope-controlled review.
NIST CSWP 39 proposes: (1) Strong Governance with executive sponsorship, (2) Asset Inventory with automated discovery, (3) Automation for continuous monitoring and remediation, (4) Risk-Based Prioritization focusing on highest-risk systems.
Late starts compress timelines and exponentially raise cost and operational risk. Start your NIST CSWP 39 implementation journey with a 30-minute scoping call.
Our research team brings public-sector, regulated-industry, and cryptographic migration experience to post-quantum readiness work. Qtonic Quantum evidence-reviews critical cryptographic findings across governed engagements while helping teams plan inventory, remediation, and implementation sequencing.