Skip to content
ContentLora

    Tip: press / anywhere to search.

    concept

    Crypto-agility

    Also known as cryptographic agility, crypto agility, algorithm agility

    Crypto-agility is the set of capabilities needed to replace and adapt cryptographic algorithms across protocols, software, hardware and infrastructure while keeping systems secure and running, as defined in a NIST white paper published in December 2025.[1][2] The post-quantum migration, expected to take years and to include a second step away from temporary hybrids, has made it a central design goal.[3][4]

    Editor reviewedUpdated Post-quantum cryptography and securityComputingTech policy
    Key facts

    What it is

    Crypto-agility is the capacity to change cryptography without tearing systems apart. NIST’s Cybersecurity White Paper 39, published on 19 December 2025, defines it as “the capabilities needed to replace and adapt cryptographic algorithms” across protocols, applications, software, hardware, firmware and infrastructure, while preserving security and ongoing operations.[1][2]

    Cloudflare puts it more simply: the ability to swap cryptographic algorithms without re-architecting systems. That does not mean supporting every algorithm at once.[5]

    Why post-quantum migration made it urgent

    Cryptographic changes are not new. Key sizes have grown, and weak hash functions and block ciphers have been retired before.[6] Those changes were slow. NIST says it has historically taken 10 to 20 years for a new algorithm to be fully integrated after standardization.[3] The post-quantum move is larger, because it replaces the public-key algorithms used almost everywhere.[7]

    Several features of the transition call for agility:

    • Two-step migration. NIST expects today’s hybrid schemes to be temporary measures leading to a second transition to PQC-only algorithms.[4]
    • Backups. NIST standardized slh-dsa and selected hqc as backups in case the lattice-based primaries prove vulnerable. Switching to them would require agile systems.[8][9]
    • Candidates can fail. SIKE was broken after reaching NIST’s fourth round.[10]
    • Standards keep moving. Even ML-KEM’s final form was incompatible with the earlier Kyber that Chrome had deployed, forcing a switch in Chrome 131.[11]

    Agility in practice

    The web’s TLS protocol is a working example. Clients advertise the key-exchange groups they support and servers pick one. That is how Apple devices offer X25519MLKEM768 while still connecting to servers that only support classical groups.[12] See hybrid-post-quantum-tls.

    Policy

    Governments mostly frame migration around deadlines and inventories. The UK NCSC asks organizations to complete a full discovery exercise by 2028.[13] The June 2026 US executive order sets dates for moving to NIST’s standards.[14] Cloudflare argued that the order says nothing about building systems that can swap algorithms. It also called for a definition of “done” that includes switching off quantum-vulnerable cryptography.[15] For the debate over timing, see migration timeline debate.

    What NIST recommends

    NIST’s white paper uses history to make its case. Block ciphers moved from single DES to Triple DES and then to AES as computing power grew and cryptanalysis improved.[16] For protocols, it says standards bodies should be able to change the algorithms that implementations must support without rewriting the protocol’s base specification.[17]

    For software, it recommends cryptographic APIs that separate applications from the algorithms they call. An application might then switch between AES-CCM and AES-GCM without changing its API calls.[18] For organizations, it starts with an inventory of where cryptography is used, across code, libraries, software, hardware and firmware. It also introduces a crypto-agility maturity model for measuring progress.[19]

    Agility and deadlines

    Deadlines differ between governments, which is another reason to be able to switch. The EU roadmap and an April 2026 EU FAQ put the main target at 2035, in line with the UK, US and Canada. Australia’s signals directorate recommends finishing by the end of 2030.[20][21] NSA’s CNSA 2.0 sets dates by product type, with exclusive use of the new algorithms from 2030 for networking equipment and 2033 for operating systems.[22]

    Questions readers ask

    What does crypto-agility mean?

    In NIST's definition, it is the capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations.[1]

    Why does post-quantum migration need crypto-agility?

    Migrations historically take 10 to 20 years, today's hybrids are expected to give way to PQC-only algorithms in a second transition, and NIST keeps backup algorithms in case a primary one fails.[3][4][9]

    Does the 2026 US executive order require crypto-agility?

    Not explicitly, according to Cloudflare, which said the order mandates specific NIST standards but says nothing about building systems that can swap algorithms.[15]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      NIST defines cryptographic agility as the capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations. confirmedas of 2025-12-19

    2. [2]

      NIST published Cybersecurity White Paper 39, "Considerations for Achieving Cryptographic Agility", on 19 December 2025. confirmedas of 2025-12-19

    3. [3]

      NIST says it has historically taken 10 to 20 years from the standardization of a new algorithm until it is fully integrated into information systems. confirmedas of 2026-10-10

    4. [4]

      NIST notes that hybrid solutions add complexity, which can raise security risks and costs, and expects them to be temporary steps toward a second transition to PQC-only tools. confirmedas of 2024-11-12

    5. [5]

      Cloudflare describes crypto-agility as the ability to swap cryptographic algorithms without re-architecting systems, adding that it does not mean supporting every algorithm at once. confirmedas of 2026-06-23

    6. [6]

      NIST notes that cryptographic technology has been updated many times before, for example by increasing key sizes or phasing out insecure hash functions and block ciphers. confirmedas of 2024-11-12

    7. [7]

      A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10

    8. [8]

      NIST described SLH-DSA as a backup signature method in case ML-DSA proves vulnerable. confirmedas of 2024-08-13

    9. [9]

      On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11

    10. [10]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    11. [11]

      Google announced that Chrome 131 would switch from Kyber to ML-KEM, changing the TLS codepoint for hybrid post-quantum key exchange from 0x6399 (Kyber768+X25519) to 0x11EC (ML-KEM768+X25519), because minor changes in the final ML-KEM standard made it incompatible with the Kyber version deployed earlier. confirmedas of 2024-09-13

    12. [12]

      In iOS 26, iPadOS 26, macOS Tahoe 26 and visionOS 26, TLS connections automatically advertise hybrid quantum-secure key exchange, including X25519MLKEM768 in the ClientHello. confirmedas of 2026-10-10

    13. [13]

      The UK NCSC's March 2025 guidance sets three milestones, define goals and complete discovery by 2028, carry out the highest-priority migration by 2031, and complete migration of all systems by 2035. confirmedas of 2025-03-20

    14. [14]

      The order requires agencies to move all high value assets and high-impact systems to PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031. confirmedas of 2026-06-25

    15. [15]

      Cloudflare called the executive order an important milestone but argued that it needs a clear definition of "done" that includes disabling quantum-vulnerable cryptography, and that it says nothing about crypto-agility. confirmedas of 2026-06-23· interpretation

    16. [16]

      NIST's crypto-agility white paper cites the move of block ciphers from single DES to Triple DES and then AES, driven by growing computing power and better cryptanalysis, as an example of past transitions. confirmedas of 2025-12-19

    17. [17]

      CSWP 39 says it is highly desirable for standards bodies to be able to revise mandatory-to-implement algorithms without modifying a protocol's base specification. confirmedas of 2025-12-19

    18. [18]

      CSWP 39 describes cryptographic APIs that separate applications from algorithm implementations, so that, for example, an application can switch between AES-CCM and AES-GCM with the same API calls. confirmedas of 2025-12-19

    19. [19]

      CSWP 39 recommends that organizations inventory their use of cryptography across code, libraries, software, hardware and firmware, and introduces a crypto-agility maturity model to measure progress. confirmedas of 2025-12-19

    20. [20]

      The EU's coordinated PQC roadmap says the transition should be completed for as many systems as practically feasible by 2035, and that quantum-vulnerable public-key mechanisms should not be used on their own after the end of 2030 for high-risk use cases or after the end of 2035 for medium-risk ones. confirmedas of 2025-06-11

    21. [21]

      An April 2026 EU FAQ on the roadmap says its 2035 target matches the UK, US and Canadian timelines, while Australia's signals directorate recommends finishing migration by the end of 2030. confirmedas of 2026-04-15

    22. [22]

      NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07

    Revision history (2)
    1. Page created.
    2. Added CSWP 39's guidance on protocols, crypto APIs, inventories and maturity, and international deadlines.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "Crypto-agility." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/crypto-agility

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.