Post-Quantum Discovery as a Governance Capability: Evidence-Based Cryptographic Visibility and Exposure Prioritisation in a Critical Service Provider

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Zelenovic, Jelena, Taghizadeh, Leila, Pena-Gonzalez, Edoardo, Garcia, Jaime Gomez, Preneel, Bart
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866911690438737920
author Zelenovic, Jelena
Taghizadeh, Leila
Pena-Gonzalez, Edoardo
Garcia, Jaime Gomez
Preneel, Bart
author_facet Zelenovic, Jelena
Taghizadeh, Leila
Pena-Gonzalez, Edoardo
Garcia, Jaime Gomez
Preneel, Bart
contents Post Quantum Cryptography (PQC) readiness is increasingly constrained not by algorithm availability, but by cryptographic visibility, dependency complexity, and fragmented governance. This paper presents an anonymised case study of a large European critical service provider that initiated PQC readiness through a discovery first strategy, utilizing tool supported cryptographic inventorying to establish an evidence based baseline prior to migration planning. The discovery phase revealed systemic challenges, including distributed cryptographic ownership, uneven evidence quality across legacy and modern environments, and high dependency on third party cryptographic roadmaps. To operationalise these findings, the organisation introduced a structured exposure register that enabled prioritisation based on asset criticality, confidentiality longevity, and migration feasibility. We argue that PQC discovery should be understood as a governance capability that stabilises organisational knowledge and converts cryptographic uncertainty into measurable accountability, supporting risk based decision making and ecosystem coordination. The results contribute actionable lessons for institutions pursuing crypto-agility and resilience under post quantum harvest now, decrypt later threat models.
format Preprint
id arxiv_https___arxiv_org_abs_2605_16549
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Post-Quantum Discovery as a Governance Capability: Evidence-Based Cryptographic Visibility and Exposure Prioritisation in a Critical Service Provider
Zelenovic, Jelena
Taghizadeh, Leila
Pena-Gonzalez, Edoardo
Garcia, Jaime Gomez
Preneel, Bart
Cryptography and Security
Computational Engineering, Finance, and Science
D.4.6, K.6.5
Post Quantum Cryptography (PQC) readiness is increasingly constrained not by algorithm availability, but by cryptographic visibility, dependency complexity, and fragmented governance. This paper presents an anonymised case study of a large European critical service provider that initiated PQC readiness through a discovery first strategy, utilizing tool supported cryptographic inventorying to establish an evidence based baseline prior to migration planning. The discovery phase revealed systemic challenges, including distributed cryptographic ownership, uneven evidence quality across legacy and modern environments, and high dependency on third party cryptographic roadmaps. To operationalise these findings, the organisation introduced a structured exposure register that enabled prioritisation based on asset criticality, confidentiality longevity, and migration feasibility. We argue that PQC discovery should be understood as a governance capability that stabilises organisational knowledge and converts cryptographic uncertainty into measurable accountability, supporting risk based decision making and ecosystem coordination. The results contribute actionable lessons for institutions pursuing crypto-agility and resilience under post quantum harvest now, decrypt later threat models.
title Post-Quantum Discovery as a Governance Capability: Evidence-Based Cryptographic Visibility and Exposure Prioritisation in a Critical Service Provider
topic Cryptography and Security
Computational Engineering, Finance, and Science
D.4.6, K.6.5
url https://arxiv.org/abs/2605.16549