Sagentix Cyber & AI
The deadline is fixed.
The inventory is the hard part.
Post-quantum migration is not principally a cryptography problem. It is an inventory problem, an agility problem, and a sequencing problem — against dates nobody gets to move.
We build the programme that gets an organization from “we should look at this” to a funded, sequenced roadmap anchored to the milestones that bind it.
The dates that bind
The Government of Canada migration roadmap sets three milestones for non-classified federal systems. They are not aspirational.
April 2026
Departmental plans due
An initial migration plan, and the start of annual progress reporting. The plan is the deliverable that makes everything after it fundable.
End of 2031
High-priority systems migrated
Not 2030 — the figure often quoted is NIST’s own algorithm-deprecation timeline, which is a different instrument. Deciding what counts as high-priority is itself a governance decision, and it is one most organizations have not made.
End of 2035
Remaining systems migrated
Full migration. Distant enough to defer, close enough that anything with a long replacement cycle is already inside the window.
Why this is harder than it sounds
The algorithms are the settled part. Everything expensive is somewhere else.
Nobody has the inventory
You cannot migrate cryptography you cannot find. It is embedded in appliances, hardcoded in applications, inherited from vendors, and buried in protocols nobody has looked at in a decade. The inventory is the long pole, and it is the work most programmes discover late.
The data is already exposed
Encrypted traffic captured today can be decrypted once the capability exists. For anything with a confidentiality lifetime measured in decades, the exposure is not a future risk — it has already happened, and the migration date is what bounds it.
Agility matters more than any algorithm
The specific algorithms will change again. An organization that can swap cryptographic primitives without re-architecting is positioned for the next transition too; one that hardcodes the new standards has merely bought time.
What the programme is made of
Six components, built against the recommended standards — ML-KEM, ML-DSA and SLH-DSA, published as NIST FIPS 203, 204 and 205.
Cryptographic inventory
What cryptography you run, where, on what protocols, under whose control, with what replacement cycle — assembled as a maintained asset rather than a one-off spreadsheet.
Crypto-agility assessment
How hard it would be to change primitives in each system, which is the variable that actually sets your sequencing — and which surfaces the systems that need re-architecting rather than upgrading.
Quantum-safe cryptography standard
The technical instrument that states requirements a system can be assessed against, rather than guidance a project can decline.
Amendment packages
Targeted amendments into the encryption, authentication, network, application and cloud standards already in force, so cryptographic obligations land where practitioners already look.
Programme directive and risk integration
Governance structure, roles and mandatory activities — plus quantum risk factors folded into the risk-assessment framework you already run, so a new system inherits the question automatically.
Phased migration roadmap
Sequenced most-exposed-first against the fixed milestones, with the high-priority determination made explicitly and defensibly rather than left implicit.
Delivered
Delivered at a major Canadian federal financial-sector institution as a migration programme directive, a quantum-safe cryptography IT security standard, amendment packages across the existing standards stack, quantum risk factors folded into the assessment framework, and a phased roadmap anchored to the Government of Canada milestones — running in parallel with an AI governance programme, with explicit composition between the two.
No client is named. Engagements are described at method level; named references are available on request, subject to client consent.
Do you know what cryptography you run?
Thirty minutes. We establish how much of your estate is visible today, which systems have a confidentiality lifetime that puts them inside the window, and what a fundable first phase looks like from where you are.
Sources
- Canadian Centre for Cyber Security, 2025 — Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001). cyber.gc.ca. Issued 23 June 2025; source of the April 2026, end-of-2031 and end-of-2035 milestones.
- Canadian Centre for Cyber Security — Guidance on becoming cryptographically agile (ITSAP.40.018) and the ITSP.40.111 approved cryptographic algorithms guidance. cyber.gc.ca.
- National Institute of Standards and Technology, 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). nist.gov.
- National Institute of Standards and Technology — NIST IR 8547 (initial public draft), Transition to post-quantum cryptography standards. The “2030 onward” deprecation timeline sometimes quoted as a Canadian deadline belongs to this NIST instrument, not to ITSM.40.001.