Skip to content

Crypto Agility

What is Crypto Agility?

The ability of a system to quickly transition between different cryptographic algorithms and protocols in response to new threats or requirements.

Information Security

Each of these is named in at least one of the same controls as crypto agility. The number is how many controls name both.

What the standards actually require on crypto agility

Requirements naming crypto agility across 6 standards, quoted from the control text.

Architect cryptographic agility per NIST SP 1800-38 + ISO/IEC 24759 covering: pluggable cryptographic providers + algorithm abstraction layers + key lifecycle management + protocol negotiation (TLS 1.3 PQC hybrid drafts + IETF LAMPS WG) + KMIP + PKCS#11 + HSM...

PQC-6 · Crypto-Agility Architecture and Hybrid Composite Mode Strategy

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...

HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination
HKMA TM-G-12 controls

HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...

HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint
OWASP ASVS2 controls

Per OWASP ASVS V6: implement secure stored cryptography. Requirements include (a) classify data + apply appropriate cryptographic protection per classification + (b) use industry-vetted algorithms + key sizes + modes + libraries (AES-GCM + ChaCha20-Poly1305 +...

OWASPASVS-6 · Stored Cryptography (V6)

Kuwait NCF Protect function (Data). Data Protection and Encryption aligned with NIST SP 800-53 SC family + ISO 27001 A.10 cryptography + A.13 communications security + KDPPR CITRA data protection coordination.

KNCF-Protect-Data-Encryption-Classification-Cryptography-Key-Management-DLP-PKI-Quantum-Resistant · Kuwait NCF Protect + Data + Encryption + Classification + Cryptography + Key Management + DLP

Questions people ask about crypto agility

What is Crypto Agility?
The ability of a system to quickly transition between different cryptographic algorithms and protocols in response to new threats or requirements.
Why is Crypto Agility important for compliance?
Crypto Agility is a key concept in Information Security. Understanding crypto agility helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Crypto Agility?
Crypto Agility appears in the requirement text of NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205), HKMA Cyber Resilience Assessment Framework (C-RAF), HKMA TM-G-1, OWASP ASVS, ITU-T X.805 - Security Architecture for End-to-End Communications. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Crypto Agility?
Explore our compliance framework pages to see how crypto agility applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Crypto Agility applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.