top of page

CRYPTOGRAPHIC AGILITY. CAN IT ACTUALLY BE DONE?

  • Writer: Brian Couzens
    Brian Couzens
  • 3 days ago
  • 2 min read


For years we've been told organisations need cryptographic agility.


NIST has repeatedly warned that cryptographic systems must be able to transition as algorithms become vulnerable or obsolete. The post-quantum migration is simply the latest and largest example. The destination has been clear.


The implementation hasn't.


IBM Research has now made a significant contribution to answering that question.


Their 2026 papers introduce an application-level framework that separates cryptographic intent from algorithms, providers and key evolution. Instead of rewriting applications every time cryptography changes, the objective is to make migration an operational activity rather than a software engineering exercise.


That is an important engineering achievement.


At SITG-Consulting, we wanted to determine whether those claims stood up to independent forensic scrutiny.


We therefore conducted a comprehensive technical review of IBM's framework, examining its architecture, API design, technical consistency, implementation practicality and enterprise applicability.


Our conclusion?


Within its stated scope, this is one of the strongest application-level cryptographic agility frameworks published to date.


It is equally important to understand what it doesn't do.


IBM solves application-layer cryptographic agility.


It does not attempt to solve enterprise transformation.


Discovery. Cryptographic inventories. CBOMs. Governance. Board accountability. Programme management. Assurance. Those remain enterprise responsibilities beyond the framework itself.


That distinction matters because too many organisations still believe adopting a technology solves a governance problem.


It doesn't.


Our 25-slide independent forensic review examines:


• The assessment framework

• The API architecture

• The six-system comparative evaluation

• Strengths and limitations

• Enterprise applicability

• Independent scoring

• Where IBM fits alongside NIST, ETSI and broader cryptographic transformation guidance


Credit to IBM Research for publishing work that advances the discussion through engineering rather than marketing.


Constructive technical work deserves constructive technical review.




 
 
 

Comments


bottom of page