Model a representative organization with web, identity, API, messaging, and vendor-controlled cryptographic dependencies.
Post-Quantum Migration Readiness for Internet-Facing Systems
A practical investigation into how organizations can identify cryptographic dependencies, prioritize migration risk, and prepare internet-facing systems for post-quantum transition.
- Lead
- Cross-college research group
- Period
- 2026 — ongoing
- Status
- Ongoing
- Colleges
- College of Quantum Technology · College of Information Security
The question organizing the work.
What does a realistic migration path look like when cryptography is distributed across certificates, applications, vendors, protocols, and legacy infrastructure?
Why this problem is worth examining.
Post-quantum migration is often discussed as an algorithm-selection problem. In practice, organizations first need to discover where cryptographic assumptions are embedded and which dependencies they can actually change.
The project focuses on migration readiness as an engineering and governance problem: inventory, dependency mapping, prioritization, testing, and staged replacement.
How the question becomes testable work.
The methodology is designed to leave behind evidence and reusable artifacts—not only a conclusion.
Develop a cryptographic inventory and dependency map rather than beginning with algorithm replacement.
Create a migration-priority framework based on exposure, data lifetime, system criticality, and replacement difficulty.
Prototype hybrid-transition test cases for selected internet-facing services.
What the project is designed to leave behind.
Where the investigation goes next.
Test the readiness rubric against additional infrastructure profiles.
Develop a small open checklist for technical teams beginning cryptographic discovery.
Connect migration scenarios to future Cryptology and Quantum Technology learning materials.
The problem determines the boundaries—not the org chart.
This project sits across College of Quantum Technology and College of Information Security. That cross-college structure is intentional: emerging technology problems frequently combine technical, organizational, legal, and human dimensions.