Security Weekly Podcast Network (Audio)

Say Easy, Do Hard - Crypto-Agility - BSW #440

Mar 25, 2026
A deep dive into crypto-agility and why swapping algorithms is only the start. They cover inventorying cryptography across systems, prioritizing migrations with C‑BOMs, and practical roadmaps like the PQCC guides. Conversations focus on tooling, automation, vendor coordination, timelines toward 2030, and strategies for mitigating harvest-now, decrypt-later risks.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

2030 And 2035 Are Key Deadlines

  • Two regulatory timeline milestones matter: NIST-deprecation by 2030 and disallowance by 2035 for current cipher suites.
  • Josh Marpet emphasizes urgency because discovery and remediation multiply time requirements.
ADVICE

Get Stakeholder Buy-In Early And Often

  • Engage stakeholders early and craft strategic messaging to get buy-in from business units, the C-suite, and vendors.
  • Jason Albuquerque stresses relationships and long timelines; vendor readiness may take years and must be negotiated.
INSIGHT

Expect Quantum Adoption To Cascade By Threat Tier

  • Quantum capability will likely appear in waves: nation-state first, then large contractors and enterprises, cascading down over years.
  • Josh Marpet describes a stepped pyramid model to map adversary threat position.
Get the Snipd Podcast app to discover more snips from this episode
Get the app