Important News:SafeLogic's CryptoComply Achieves FIPS 140-3 Validation for 28 OEs and Receives Certificate #4781! Read the blog post!
The SafeLogic Blog
NIST Publishes Next Volume of PQC Migration Guidance
December 21, 2023 •Evgeny Gervis
In an earlier blog, SafeLogic wrote about the company’s participation in the Post Quantum Cryptography (PQC) migration project led by NIST. This week, the Post-Quantum Cryptography team at the National Cybersecurity Center of Excellence (NCCOE) has published two NIST Special Publications (SP) preliminary draft practice guides titled:
-
“SP 1800-38B, Migration to Post-Quantum Cryptography Quantum Readiness: Cryptographic Discovery”
-
“SP 1800-38C, Migration to Post-Quantum Cryptography Quantum Readiness: Testing Draft Standards”
In the first of these publications, NIST shares insights on and lessons learned from using automated discovery tools to identify instances of quantum-vulnerable cryptography. In the second publication, NIST shares results from interoperability and performance tests using the draft PQC algorithms. SafeLogic would like to encourage all interested parties to submit comments to improve these documents and offer input on what else this collaboration can do to support migration to PQC. Please submit your comments here.
SafeLogic had been contributing to the first work stream covering the discovery of quantum-vulnerable cryptography. Given the ubiquitous use of cryptography across many technology stack layers, automated discovery tools can sometimes find hundreds or thousands of instances of quantum-vulnerable cryptography. Armed with that data, practitioners then face a crucial question about how to prioritize migration efforts. SafeLogic had been focusing on exploring answers to that question. We have been advocating for a risk-based approach rooted in organizational threat modeling. PQC migration prioritization remains an active area of research, and NIST will provide further guidance in future publications.
SafeLogic’s cryptographic modules are used extensively within many of the top technology firms in the world. As such, we are increasingly having more and more conversations with our customers and prospects regarding how they should plan for PQC migration, prioritize PQC migration efforts, etc. In that respect, all the great work that NIST and the PQC migration collaboration community do is very valuable.
To help our customers plan their PQC migrations further, SafeLogic is planning to launch an Early Access Program (EAP) in the first quarter of 2024 to enable its customers to start experimenting with PQC algorithms in their own environments, whether as standalone or in hybrid mode alongside classical cryptography. For the latter, SafeLogic customers subject to FIPS 140 requirements will be able to evaluate PQC implementation jointly with SafeLogic’s upcoming FIPS 140-3 module that is currently going through a validation process by NIST.
Evgeny Gervis
Evgeny is the CEO of SafeLogic.
Popular Posts
Search for posts
Tags
- FIPS 140 (111)
- FIPS validation (85)
- Encryption (70)
- cryptography (68)
- NIST (62)
- CryptoComply (60)
- SafeLogic (58)
- Industry News (54)
- cryptographic module (51)
- Conversations (49)
- CMVP (48)
- RapidCert (46)
- compliance (41)
- Ray Potter (33)
- SafeLogic News (33)
- Event (27)
- federal (27)
- CAVP (23)
- Cybersecurity (23)
- FIPS 140-3 (18)
- OpenSSL (16)
- government (14)
- FedRAMP (13)
- CryptoCompact (12)
- Cryptology (12)
- DoD (12)
- RSA (12)
- healthcare (12)
- partners (12)
- NSA (11)
- post-quantum cryptography (11)
- Cloud (9)
- PQC (9)
- security (9)
- CMMC (8)
- Suite B (8)
- testing (8)
- whitepaper (8)
- Approved Products List (APL) (6)
- HITECH (6)
- ICMC (6)
- lab (6)
- CEO (5)
- NIST 800-171 (5)
- NIST 800-53 (5)
- OpenSSL 3.0 (5)
- iOS (5)
- procurement (5)
- C3PAO (4)
- Common Criteria (4)
- HITECH Act (4)
- deadline (4)
- encrypt (4)
- innovation (4)
- procure (4)
- public sector (4)
- Air Force (3)
- BSAFE (3)
- DFARS (3)
- HIPAA Safe Harbor (3)
- HITECH Safe Harbor (3)
- OpenSSL 1.1.1 (3)
- OpenSSL 3.x (3)
- POA&M (3)
- TLS 1.3 (3)
- magazine (3)
- queue (3)
- transition (3)
- 3PAO (2)
- ACVP (2)
- BAA (2)
- CIO (2)
- CSP (2)
- Cyber Defense Magazine (2)
- Defense Industrial Base (2)
- HIPAA security controls (2)
- Historical Status (2)
- MFA (2)
- OpenSSL 1.0.2 (2)
- SPRS (2)
- StateRAMP (2)
- entropy (2)
- excellence (2)
- finance (2)
- founder (2)
- gold (2)
- leader (2)
- maturity (2)
- overlap (2)
- pilot (2)
- rsa conference (2)
- solution (2)
- sponsors (2)
- sunset (2)
- vendor (2)
- year (2)
- Active Status (1)
- Alliance for Digital Innovation (1)
- Android (1)
- CIO Prime Views (1)
- DHS (1)
- DIU (1)
- DIUx (1)
- DOJ (1)
- DoDIN APL (1)
- Entropy Source Validation (1)
- FCA (1)
- FIPS Compliance (1)
- FISMA (1)
- GSA (1)
- HITRUST (1)
- Matt Cornelius (1)
- Matthew Cornelius (1)
- Maturity Model (1)
- NCCoE (1)
- OMB (1)
- SLED (1)
- SP800-131A (1)
- SP800-90A (1)
- TLS 1.1 (1)
- background (1)
- best (1)
- co-founder (1)
- codies (1)
- congress (1)
- cybertech (1)
- education (1)
- elliptic curve cryptography (1)
- extended (1)
- faq (1)
- fintech (1)
- fiscal (1)
- fiscal year (1)
- fraud (1)
- globee (1)
- hill (1)
- interview (1)
- kratos (1)
- libgcrypt (1)
- national cybersecurity strategy (1)
- opportunities (1)
- parallel (1)
- profile (1)
- public (1)
- representatives (1)
- reseller (1)
- senate (1)
- senators (1)
- simplify (1)
- state (1)
- stealth mode (1)
- story (1)
- terminology (1)
- trophy (1)
- whistleblower (1)
- whistleblowing (1)