Skip to main content

Sagentix Cyber & AI

The deadline is fixed.
The inventory is the hard part.

Post-quantum migration is not principally a cryptography problem. It is an inventory problem, an agility problem, and a sequencing problem — against dates nobody gets to move.

We build the programme that gets an organization from “we should look at this” to a funded, sequenced roadmap anchored to the milestones that bind it.

The dates that bind

The Government of Canada migration roadmap sets three milestones for non-classified federal systems. They are not aspirational.

April 2026

Departmental plans due

An initial migration plan, and the start of annual progress reporting. The plan is the deliverable that makes everything after it fundable.

End of 2031

High-priority systems migrated

Not 2030 — the figure often quoted is NIST’s own algorithm-deprecation timeline, which is a different instrument. Deciding what counts as high-priority is itself a governance decision, and it is one most organizations have not made.

End of 2035

Remaining systems migrated

Full migration. Distant enough to defer, close enough that anything with a long replacement cycle is already inside the window.

Why this is harder than it sounds

The algorithms are the settled part. Everything expensive is somewhere else.

Nobody has the inventory

You cannot migrate cryptography you cannot find. It is embedded in appliances, hardcoded in applications, inherited from vendors, and buried in protocols nobody has looked at in a decade. The inventory is the long pole, and it is the work most programmes discover late.

The data is already exposed

Encrypted traffic captured today can be decrypted once the capability exists. For anything with a confidentiality lifetime measured in decades, the exposure is not a future risk — it has already happened, and the migration date is what bounds it.

Agility matters more than any algorithm

The specific algorithms will change again. An organization that can swap cryptographic primitives without re-architecting is positioned for the next transition too; one that hardcodes the new standards has merely bought time.

What the programme is made of

Six components, built against the recommended standards — ML-KEM, ML-DSA and SLH-DSA, published as NIST FIPS 203, 204 and 205.

Cryptographic inventory

What cryptography you run, where, on what protocols, under whose control, with what replacement cycle — assembled as a maintained asset rather than a one-off spreadsheet.

Crypto-agility assessment

How hard it would be to change primitives in each system, which is the variable that actually sets your sequencing — and which surfaces the systems that need re-architecting rather than upgrading.

Quantum-safe cryptography standard

The technical instrument that states requirements a system can be assessed against, rather than guidance a project can decline.

Amendment packages

Targeted amendments into the encryption, authentication, network, application and cloud standards already in force, so cryptographic obligations land where practitioners already look.

Programme directive and risk integration

Governance structure, roles and mandatory activities — plus quantum risk factors folded into the risk-assessment framework you already run, so a new system inherits the question automatically.

Phased migration roadmap

Sequenced most-exposed-first against the fixed milestones, with the high-priority determination made explicitly and defensibly rather than left implicit.

Delivered

Delivered at a major Canadian federal financial-sector institution as a migration programme directive, a quantum-safe cryptography IT security standard, amendment packages across the existing standards stack, quantum risk factors folded into the assessment framework, and a phased roadmap anchored to the Government of Canada milestones — running in parallel with an AI governance programme, with explicit composition between the two.

No client is named. Engagements are described at method level; named references are available on request, subject to client consent.

Do you know what cryptography you run?

Thirty minutes. We establish how much of your estate is visible today, which systems have a confidentiality lifetime that puts them inside the window, and what a fundable first phase looks like from where you are.

See the full practice

Sources

  • Canadian Centre for Cyber Security, 2025 — Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001). cyber.gc.ca. Issued 23 June 2025; source of the April 2026, end-of-2031 and end-of-2035 milestones.
  • Canadian Centre for Cyber Security — Guidance on becoming cryptographically agile (ITSAP.40.018) and the ITSP.40.111 approved cryptographic algorithms guidance. cyber.gc.ca.
  • National Institute of Standards and Technology, 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). nist.gov.
  • National Institute of Standards and Technology — NIST IR 8547 (initial public draft), Transition to post-quantum cryptography standards. The “2030 onward” deprecation timeline sometimes quoted as a Canadian deadline belongs to this NIST instrument, not to ITSM.40.001.