Talk

Not How Fast, But How Well: A Practitioner's PQC Migration

Not How Fast, But How Well: A Practitioner's PQC Migration

conf 2026-11-06 10:40 – 11:10 EN

Not How Fast, But How Well: A Practitioner's PQC Migration

Title: Not How Fast, But How Well: A Practitioner's PQC Migration Quantum computers threaten the public-key cryptography we depend on (RSA, ECDSA, ECDH) and the conversation has hardened into a refrain: migrate now. This session makes a different case: act deliberately. The question isn't how fast you migrate, but how well. What deserves a CISO's budget, and what's just hype? At Black Alps 2023, Jean-Philippe Aumasson mapped the post-quantum landscape. Three years later, we pick up where that left off: a reality check on finalized NIST standards (FIPS 203/204/205: ML-KEM, ML-DSA, SLH-DSA), the challenges they bring (larger keys and signatures, TLS handshake fragmentation, performance, immature tooling) and the solutions the field has or is converging on. We also map the clocks: national and standardization bodies anchor one timeline, while some industries push more aggressive ones. Then we get concrete. Working through one representative organization, we lead its migration end to end: awareness, cryptographic discovery, risk assessment, prioritization, execution, with the do's and don'ts per phase. Much of this rests on classical security work: data classification, business impact analysis, mapping critical processes, key lifecycle management, now extended with the PQC and quantum-computing dimension.