By: Adam Everspaugh, PhD, Cryptographic Advisor, Keeper Security
With the clock ticking on federal deadlines for Quantum-Resistant Cryptography (QRC) adoption, U.S. agencies are deep in the planning stages of a monumental cryptographic transition. While the focus is often on selecting the right quantum-resistant algorithms, the unexpected downfall of the HAWK signature scheme reveals a more fundamental requirement for a successful migration. True security in the post-quantum era will not come from a single, perfect algorithm, but from the ability to rapidly swap, update and deploy cryptographic primitives as the landscape evolves. This “crypto agility” is no longer a theoretical nice-to-have; it’s the core principle that will determine the success or failure of the federal QRC mandate.
Algorithm Choice Alone Isn’t Enough
Crypto-agility is as fundamental to a secure QRC strategy as the quantum-resistant algorithm choice itself. In practice, this requires maintaining an inventory of where and how cryptographic algorithms are used across an organization’s environments, and ensuring that update pathways exist before an emergency migration is required. A hybrid cryptographic approach – running a battle-hardened, classic cryptographic algorithm in conjunction with a newer, quantum-resistant algorithm – reflects the same principle.
HAWK, a third-round quantum-resistant signature candidate in the National Institute of Standards and Technology (NIST) standardization process, was recently shown to contain a previously unknown mathematical symmetry that cuts its effective key strength in half. The HAWK team has since confirmed the result and formally withdrawn the candidate from standardization. Systems built to swap or patch cryptographic primitives without a full re-architecture absorb findings like this far more easily than those locked into a single scheme.
NIST standards finalization has never guaranteed permanence nor security. Two of the three standardized quantum-resistant algorithms rely on the same lattice algebra foundation as HAWK, and it’s reasonable to assume that AI-assisted cryptanalysis will be effective on those algorithms as well.
A Credible Migration Plan
Executive Order 14412, signed in June 2026, requires United States federal agencies to transition to quantum-resistant cryptography for key establishment by December 31, 2030, and quantum-resistant digital signatures by the end of 2031. The order required that a migration lead be assigned for each agency by July 2026 and full migration plans are due to the Office of Management and Budget (OMB) this month.
A high-level understanding of the post-quantum migration process is key, moving systematically from initial Inventory and Strategy through Implementation, into a Phased Rollout, and finally establishing continuous Monitoring and Response. As federal agencies navigate this complex trajectory under tight deadlines, several critical pitfalls frequently threaten success.
First, many organizations falter early by attempting to execute an entirely manual inventory phase. Without leveraging modern automation to dynamically scan vendors, active directories and internal codebases for legacy public-key cryptography, agencies risk missing hidden vulnerabilities. Furthermore, a key strategic misstep is selecting a strategy or vendor that doesn’t permit phased roll-out of hybrid QRC and permit rapid response when a QRC algorithm vulnerability is found. The latter is much harder and more consequential than the former.
Crypto-Agility in Practice
EO 14412 sets the deadlines. Meeting them depends on whether the underlying architecture is built for crypto-agility. Here are the criteria for determining if an agency’s transition is crypto-agile:
- Phased rollout: products, servers, data and users can move in phases, not all at once. Individual phases can be rolled-back immediately if they break during rollout.
- Mixed-fleet: individual products, servers, data and users can interoperate during the phased rollout.
- Rapid deployment: implementation and rollout should be measured in weeks or months, not years. If changes take years, then a vulnerability in a QRC algorithm will persist for years, and that isn’t an acceptable security posture in most settings.
- Rapid response: Once rollout is underway, how quickly can a new ciphersuite be rolled out or rolled back? Responses should be possible in weeks.
The nightmare scenario is a complex, fragile and time-intensive rollout. Consider what this looks like in practice: seven months into an 18-month migration, an agency’s systems and data exist in a split state with some still relying on legacy cryptography (State A) and others upgraded to a hybrid quantum-resistant algorithm (State B). The goal is a clean migration from A to B.
Then, disaster strikes. A critical vulnerability is discovered in the new quantum-resistant algorithm, forcing the agency to abandon it for an entirely different, secure ciphersuite (State C). Suddenly, the migration path fractures. Instead of a single, orderly transition, IT teams must simultaneously manage three chaotic, in-flight data conversions: legacy to hybrid (A ? B), hybrid to the new patch (B ? C) and legacy straight to the new patch (A ? C). If the deployment process is rigid and slow, this mid-flight pivot exponentially increases system complexity, dramatically drags out timelines and vastly raises the risk of catastrophic data corruption.
Crypto-agility avoids this. It’s easy to say but hard to do, and the optimal strategy varies by setting. This is a reminder that no algorithm, and no plan, survives contact with reality. Crypto-agility allows an agency to keep moving every time the ground shifts.