← All Terms

Crypto-Agility

The ability to replace a cryptographic algorithm across systems by changing configuration, without rewriting the applications that use it.

Governance & Risk

Crypto-agility is a design property: algorithms, key sizes and protocols are chosen in configuration or a central library, so a system can move from one algorithm to another without code changes. An agile system can be told to prefer ML-KEM over elliptic-curve key exchange in a setting. A brittle one has the algorithm written into application code, certificates and hardware in dozens of places.

It matters because cryptographic migrations recur. The move from SHA-1 to SHA-2 took most large organisations years, and the post-quantum migration is larger. It will not be the last: NIST selected HQC as a backup to ML-KEM in 2025 in case weaknesses emerge in lattice-based algorithms.

The practical test is simple. Ask how long it would take to switch one algorithm across your estate and who would have to change code to do it. If the answer is months and dozens of teams, the post-quantum budget should include the agility work, so the next migration costs less than this one.