This session cuts through PQC migration rhetoric to deliver a precise, practitioner-grade roadmap for compliance with NSM-10 and CNSA 2.0. Moses Liskov (MITRE), Nicolas Gama (SandboxAQ), and Basil Hess (IBM Research) dismantle the misconception that migration is primarily about algorithm selection—instead framing it as an inventory and dependency management challenge that most organizations are failing at the discovery phase.
The discussion centers on two concrete frameworks: the Cryptographic Bill of Materials (C-BOM), which extends SBOM methodology to track algorithm specifications, key lengths, and parameters across dependency trees; and ML-enriched network analysis that identifies cryptographic protocols in traffic with significantly lower false positive rates than traditional detection methods. Gama presents data showing that 60-80% of cryptographic calls in enterprise applications originate from transitive dependencies, making library-level inventory non-negotiable.
The panel maps out the compressed timeline created by harvest-now-decrypt-later threats: any data requiring confidentiality beyond 5-7 years demands quantum-resistant protection immediately, regardless of the 2035 full migration deadline. Hess details a three-phase migration framework—discovery, prioritization based on data shelf-life risk scoring, and remediation—while Liskov addresses the policy implications of CNSA 2.0's 2025 software signing deadline as the first hard compliance trigger. Listeners will leave with a clear understanding of why cryptographic inventory must precede algorithm migration, and how emerging tooling makes this feasible at enterprise scale.
Key Insights
- NSM-10 mandates a full PQC migration by 2035, but CNSA 2.0's software signing deadline hits in 2025—creating an immediate, non-negotiable trigger for inventory efforts.
- Cryptographic Bill of Materials (C-BOM) extends the SBOM concept by explicitly tracking algorithm, key length, and parameter sets per dependency, enabling automated compliance mapping against CNSA 2.0.
- ML-enriched traffic analysis can reduce false positives in protocol detection by 40-60% compared to simple port-based or regex methods, accurately identifying hybrid TLS implementations even on non-standard ports.
- The migration follows three distinct phases: discovery (inventory), prioritization (risk scoring based on data shelf-life), and remediation—with most organizations currently failing at phase one due to incomplete asset visibility.
- Harvest-now-decrypt-later attacks compress migration timelines: any data requiring confidentiality beyond 5-7 years must already be protected with quantum-resistant algorithms, regardless of the 2035 deadline.
- Dependency tracking reveals that 60-80% of cryptographic calls in enterprise applications originate from transitive dependencies, not direct code—making library-level inventory essential rather than application-level scanning alone.
Who should listen: Security architects and platform engineers responsible for enterprise cryptographic inventory who need to operationalize NSM-10 compliance before the CNSA 2.0 software signing deadline.
Why This Matters
This session validates our position that PQC migration is fundamentally an inventory and dependency management problem, not a cipher selection problem. The convergence of C-BOM standards and ML-based discovery tools signals that the tooling ecosystem is finally catching up to the mandate urgency.