Crypto Agility
What is Crypto Agility?
The ability of a system to quickly transition between different cryptographic algorithms and protocols in response to new threats or requirements.
Terms that appear alongside crypto agility
Each of these is named in at least one of the same controls as crypto agility. The number is how many controls name both.
- key management 4 shared controls
- nist 4 shared controls
- owasp 4 shared controls
- fips 3 shared controls
- tls 3 shared controls
- zero trust 3 shared controls
- generative ai 2 shared controls
- sub processor 2 shared controls
Frameworks that govern crypto agility
What the standards actually require on crypto agility
Requirements naming crypto agility across 6 standards, quoted from the control text.
Architect cryptographic agility per NIST SP 1800-38 + ISO/IEC 24759 covering: pluggable cryptographic providers + algorithm abstraction layers + key lifecycle management + protocol negotiation (TLS 1.3 PQC hybrid drafts + IETF LAMPS WG) + KMIP + PKCS#11 + HSM...
PQC-6 · Crypto-Agility Architecture and Hybrid Composite Mode Strategy →HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...
HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination →HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...
HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint →Per OWASP ASVS V6: implement secure stored cryptography. Requirements include (a) classify data + apply appropriate cryptographic protection per classification + (b) use industry-vetted algorithms + key sizes + modes + libraries (AES-GCM + ChaCha20-Poly1305 +...
OWASPASVS-6 · Stored Cryptography (V6) →Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities.
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection · ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography →Kuwait NCF Protect function (Data). Data Protection and Encryption aligned with NIST SP 800-53 SC family + ISO 27001 A.10 cryptography + A.13 communications security + KDPPR CITRA data protection coordination.
KNCF-Protect-Data-Encryption-Classification-Cryptography-Key-Management-DLP-PKI-Quantum-Resistant · Kuwait NCF Protect + Data + Encryption + Classification + Cryptography + Key Management + DLP →Questions people ask about crypto agility
What is Crypto Agility?
Why is Crypto Agility important for compliance?
Which compliance frameworks address Crypto Agility?
Where can I learn more about Crypto Agility?
See how Crypto Agility applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.