Inventory before migration
Map protocols, certificates, signing systems, libraries, hardware roots and vendor dependencies. Add the sensitivity lifetime of the protected information so “harvest now, decrypt later” exposure is visible.
Prioritize crypto-agility
The first engineering outcome is the ability to change algorithms and key sizes without redesigning the entire service. Separate policy from implementation, remove hard-coded assumptions and test hybrid or updated modes in the least coupled systems first.
- Long-lived sensitive data
- Hard-to-update embedded or appliance systems
- Externally trusted signing workflows
- Vendor roadmaps with unclear migration support
This field note is general technical guidance. The safe remediation sequence depends on the hierarchy, clients and controls in the actual estate.