top of page

PQC and Zero Trust: Building a Post-Quantum Trust Architecture

  • Writer: Brian Couzens
    Brian Couzens
  • 2 days ago
  • 4 min read
PQC and Zero Trust converging into a cryptographically resilient digital trust architecture

PQC without Zero Trust is like building a vault without knowing who has the keys.

And Zero Trust without post-quantum cryptography?

An excellent access-control system protecting cryptography that may eventually become untrustworthy.

This is the uncomfortable conversation that organisations need to have.

Post-quantum cryptography (PQC) and Zero Trust are often treated as separate cybersecurity transformation programmes. Different teams own them. Different roadmaps define them. Different budgets fund them.

That separation is increasingly difficult to justify.

The reason is simple.

They are solving different parts of the same problem:

Digital trust.

What does PQC actually protect?

Post-quantum cryptography is concerned with protecting cryptographic mechanisms against future quantum-enabled attacks.

NIST has now finalised its first three principal PQC standards: FIPS 203 for ML-KEM, FIPS 204 for ML-DSA and FIPS 205 for SLH-DSA. These standards address key establishment and digital signatures designed to resist attacks from sufficiently capable quantum computers.

That is a major step forward.

But PQC does not decide whether an entity should be trusted.

It does not determine whether a device is compromised.

It does not decide whether an application should access a particular resource.

It does not determine whether a user's privileges remain appropriate.

It does not establish the broader context in which an access decision should be made.

That is where Zero Trust enters the picture.

What does Zero Trust actually protect?

NIST's Zero Trust Architecture moves security away from implicit trust based on network location and towards explicit authentication and authorisation of users, devices, assets and resources.

The fundamental question becomes:

"Should this entity be allowed to access this resource under these circumstances?"

That requires identity, authentication, authorisation, policy enforcement, device and workload context, segmentation and continuous assessment.

Zero Trust therefore controls the decision to trust.

PQC helps protect the cryptographic mechanisms that make that trust possible.

Those are not competing ideas.

They are complementary.

The problem with implementing them separately

Consider a service-to-service connection using mutual TLS.

A Zero Trust architecture may determine that Service A is authorised to communicate with Service B.

It may enforce least privilege.

It may evaluate identity and policy.

It may restrict the connection to a specific workload and resource.

But cryptography still underpins the identity and secure communication.

If the cryptographic mechanisms supporting that trust relationship are eventually vulnerable to quantum attack, the Zero Trust policy has not magically made the underlying cryptography secure.

You have built a sophisticated system for managing trust on top of a potentially compromised cryptographic foundation.

That is not cryptographic resilience.

It is managed exposure.

PQC within Zero Trust

This is why organisations should stop thinking about PQC as a cryptographic replacement exercise sitting beside Zero Trust.

PQC needs to become part of the trust architecture.

That means considering:

  • Cryptographic assurance alongside identity assurance

  • Cryptographic inventories and CBOMs alongside asset visibility

  • Crypto-agility alongside policy enforcement

  • Certificate and key lifecycle management alongside continuous verification

  • Algorithm assurance alongside continuous monitoring

  • Cryptographic dependencies alongside application and workload dependencies

The objective is not simply to replace RSA or ECC.

The objective is to understand where cryptography creates trust across the enterprise and whether that trust can remain reliable as algorithms, standards, vendors and threat capabilities change.

NIST itself notes that organisations should begin applying its PQC standards as part of migration planning.

That migration cannot realistically be reduced to a single technology deployment.

It is an enterprise transformation.

Why crypto-agility matters

The transition to post-quantum cryptography will not happen as a single overnight switch.

Enterprises have decades of cryptographic dependencies embedded across applications, APIs, certificates, identity systems, cloud platforms, devices, software supply chains and third-party services.

Some environments will require hybrid approaches during the transition.

The critical capability is therefore not merely having a PQC algorithm available.

It is being able to change cryptographic mechanisms without breaking the systems that depend upon them.

That is crypto-agility.

And crypto-agility is closely connected to Zero Trust because both require organisations to stop treating trust as a permanent state.

A Zero Trust architecture continuously evaluates access.

A crypto-agile architecture must continuously maintain the ability to evaluate and change the cryptographic mechanisms underpinning that trust.

Together, they create something much more valuable:

A trust architecture capable of adapting.

The missing governance layer

This is where the discussion becomes bigger than technology.

Boards, regulators and auditors increasingly need evidence that organisations understand their cryptographic dependencies rather than simply claiming that they are "quantum ready".

That requires visibility.

What cryptography is being used?

Where is it being used?

Which systems depend upon it?

Which identities depend upon it?

Which certificates and keys support it?

Which suppliers provide it?

Which algorithms are vulnerable?

Which assets are business-critical?

Which dependencies cannot be changed quickly?

A cryptographic bill of materials can contribute to that visibility.

A cryptographic inventory can provide the underlying evidence.

Crypto-agility can provide the ability to respond.

And Zero Trust can provide the architectural framework through which trust decisions are continuously enforced.

This creates a much stronger governance model than treating PQC as a compliance checkbox.

The strategic shift

The question organisations should be asking is no longer:

"Have we started our PQC migration?"

Nor should it simply be:

"Have we implemented Zero Trust?"

Those questions are too narrow.

The bigger question is:

Can we prove that the entire chain of digital trust remains trustworthy?

That chain includes identity.

Authentication.

Authorisation.

Certificates.

Keys.

Algorithms.

Applications.

Devices.

Workloads.

APIs.

Cloud services.

Third parties.

And the policies that connect them.

PQC protects an increasingly important part of that chain.

Zero Trust governs another.

Crypto-agility allows the chain to evolve.

Cryptographic inventory provides visibility.

Governance provides assurance.

That is the convergence.

Not PQC plus Zero Trust.

PQC within Zero Trust.

The organisations that understand this early will stop running two disconnected cybersecurity programmes and start building one cryptographically resilient trust architecture.

Because the post-quantum security challenge is not simply about whether encryption can be broken.

It is about whether digital trust can survive the transition.

And that is a much bigger problem.


 
 
bottom of page