| name | performing-post-quantum-cryptography-migration |
| description | Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when working with performing post quantum cryptography migration. |
| domain | cybersecurity |
| tags | ["post-quantum","PQC","CRYSTALS-Kyber","ML-KEM","ML-DSA","FIPS-203","FIPS-204","hybrid-TLS","crypto-agility"] |
| subdomain | cryptography |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.DS-01","PR.DS-02","PR.DS-10"] |
Performing Post Quantum Cryptography Migration
Overview
Cybersecurity skill for performing post quantum cryptography migration. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing post quantum cryptography migration"
-
"Assesses organizational readiness for post-quantum cryptography migration per NI"
-
When assessing organizational readiness for the NIST post-quantum cryptography transition
-
When building a cryptographic inventory to identify quantum-vulnerable algorithms across infrastructure
-
When evaluating hybrid TLS 1.3 configurations using X25519MLKEM768 key exchange
-
When testing CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) algorithm support
-
When implementing crypto-agility to support both classical and post-quantum algorithms
-
When preparing migration roadmaps aligned with NIST IR 8547 deprecation timelines
-
When configuring oqs-provider with OpenSSL 3.x for post-quantum algorithm support
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Python 3.8+ with
cryptography, requests, pyOpenSSL libraries
- OpenSSL 3.0+ (3.5+ recommended for native ML-KEM/ML-DSA support)
- oqs-provider for OpenSSL (for hybrid TLS testing with older OpenSSL)
- Network access to target servers for TLS assessment
- Administrative access for infrastructure scanning
- Familiarity with PKI, TLS, and cryptographic protocols
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def () -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}