There is no “last algorithm.” This simple statement exposes one of the most persistent and dangerous assumptions in enterprise security today.
For decades, organizations have treated cryptography, Public Key Infrastructure (PKI), and identity systems as something you deploy once and forget for decades. That model is now utterly outdated. The pressure of post-quantum risks, accelerating cryptographic deprecation cycles, and the rise of non-human identities have turned agility from a design goal into an operational necessity. If your identity infrastructure cannot continuously adapt, it will inevitably fail, most likely at the worst possible moment.
Cryptography was never static
Cryptography has always been about time, the temporary advantage of being harder to break than the alternative. The Enigma machine was once considered unbreakable, a pinnacle of cryptographic engineering. It wasn’t broken by a single flaw but by a combination of mathematical insight, operational mistakes, and sheer persistence. What was secure one day became a huge operational risk the next.
Visiting the codebreakers’ museum in Bletchley Park was an eye-opening experience, which I can highly recommend to anyone interested in the history of cryptography. Modern encryption technologies are more sophisticated but not fundamentally different in this respect. Algorithms age, computational capabilities improve, and the speed at which the cycle unfolds is only increasing…
And yet, in enterprise environments, we behave as if cryptography were static. Algorithms are selected during system design and then left untouched for years, sometimes decades. Dependencies accumulate quietly. Certificates, keys, and protocols become deeply embedded into applications and infrastructure, often without full visibility.
We have seen this pattern before. SHA-1 deprecation, TLS 1.0 retirement, and repeated vulnerabilities in widely used libraries all triggered urgent, reactive migrations. Each time, organizations discovered that what looked like a controlled cryptographic environment was in fact a brittle construct held together by outdated assumptions.
Post-quantum cryptography raises the stakes even further. As discussed in Strong Authentication in a Post-Quantum World, the transition does not just mean replacing cryptographic algorithms. It involves rethinking how cryptographic trust is managed across identities, devices, and services. The timeline may still be debated, but the direction is not.
The real issue is not when quantum breaks current algorithms but whether your infrastructure can adapt before it does.
“Set and forget” identity is the real vulnerability
Identity systems have inherited this static mindset. Once an identity is provisioned and bound to credentials, it is often assumed to remain valid until explicitly revoked or expired. That assumption does not hold in a world of dynamic, high-velocity digital interactions.
In an Analyst Chat episode on post-quantum authentication, we discussed the fact that authentication itself is evolving from a point-in-time event into a continuous process. This shift fundamentally undermines the idea that identity can be anchored to long-lived, static credentials.
In such environments, identity is no longer a fixed attribute. It is a continuously evaluated state, influenced by context, behavior, and the strength of underlying cryptographic mechanisms. The idea that you can deploy strong authentication today and rely on it unchanged for the next decade is as outdated as the notion of a permanent firewall perimeter. Identity assurance must evolve alongside cryptographic assurance.
This is where crypto-agility stops being a buzzword and becomes a survival strategy.
Crypto-agility: from concept to operational discipline
Crypto-agility is often described as the ability to swap algorithms without breaking existing systems. That definition is simple, elegant, and almost entirely useless. In practice, crypto-agility is an operational discipline that spans visibility, automation, and governance. It requires organizations to understand where cryptography is used, how it is managed, and how quickly it can be adapted.
This is particularly evident when we look at real-world deployments, like the ones discussed in Alejandro Leal’s Advisory Note Passkeys in Practice, where the complexity of managing certificates and trust relationships at scale becomes apparent. The gap between theoretical agility and operational reality is still significant. Most PKI deployments were designed for stability and compliance, not for continuous change. Retrofitting agility into such environments is complex but unavoidable.
True crypto-agility therefore demands more than algorithm abstraction. It requires continuous discovery of cryptographic assets, automated lifecycle management for keys and certificates, and policy-driven enforcement of cryptographic standards across the environment. It also requires integration with identity and access management systems so that authentication and authorization decisions reflect the current state of cryptographic trust.
Crucially, crypto-agility is not something you implement once and declare complete. It is a capability you operate and improve continuously, much like the proverbial journey to Zero Trust.
The rise of machine identities changes everything
If human identities were the only concern, we might still get away with periodic updates. But the explosion of machine identities makes static approaches unsustainable. Every workload, API, container, and device now carries its own cryptographic identity. These identities are ephemeral, high-volume, and highly automated. They depend on short-lived credentials and require continuous validation.
One recurring theme in discussions of future-proofing authentication is that authentication mechanisms must scale to support not just users, but entire ecosystems of interacting services. These services authenticate to each other, exchange credentials, and make trust decisions autonomously, often without any human in the loop. The result is a dense web of machine-to-machine trust relationships that must be established and maintained in real time.
Thus, PKI stops being a passive provider of certificates and becomes an active control layer for identity. It issues, validates, and revokes trust signals continuously, shaping how identities interact across the environment. In other words, it becomes a real-time identity control plane.
Post-quantum is just a force multiplier
It is tempting to frame crypto-agility purely as a response to post-quantum threats. That would be a mistake. Yes, the transition to quantum-resistant algorithms will be one of the largest cryptographic migrations in history. Its impact extends far beyond encryption into identity, authentication protocols, and trust models.
But even without quantum computing, the current pace of change already demands agility. New vulnerabilities emerge faster than traditional response cycles. Regulatory expectations continue to evolve. Digital ecosystems become more interconnected and interdependent. The quantum risk simply removes any hope that we can postpone the change a bit longer, even for non-technical stakeholders.
And yet, the declared goal should not be to find the perfect cryptographic standard. Instead, we need to build systems that assume change. For organizations, this translates into a set of practical priorities:
- Treat PKI as a dynamic, continuously managed service rather than a static deployment
- Build crypto-agility directly into identity architectures from the start
- Automate certificate and key lifecycle management, especially for machine identities
- Align identity assurance with cryptographic assurance so that trust decisions remain current
- Prepare for continuous migration cycles instead of one-time transformation projects
The end of “set and forget”
There is a certain comfort in believing that security can be solved once and maintained indefinitely. PKI, with its long-lived roots and formal trust hierarchies, reinforced that belief. But the world has changed. Identity is dynamic. Threats are accelerating. And the systems we rely on are more interconnected than ever.
There will never be a last algorithm that fixes all cryptographic issues for identity. The organizations that want to succeed in the future must develop the ability to adapt to whatever comes next.
This, ultimately, is what crypto-agility is really about.