Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Learn more

    Industries · Critical Infrastructure

    In critical infrastructure, a forged signature is a physical event.

    In most sectors, broken cryptography leaks information. In operational technology it moves switchgear. The commands that open breakers, adjust setpoints, and push firmware to field devices are authenticated by digital signatures and machine credentials. The quantum threat to infrastructure is not primarily that telemetry gets read; it is that a control command, a firmware image, or a device identity gets convincingly forged. Confidentiality failures inconvenience. Authentication failures actuate.

    The clocks here are the worst in any industry. Smart meters, substation controllers, and protection relays are deployed on fifteen-to-twenty-five-year lifecycles, and a device commissioned today with quantum-vulnerable firmware signing will still be in the field deep into the deprecation timeline NIST has already published. CISA has made post-quantum preparation an explicit priority for critical infrastructure, and CNSA 2.0 binds new national-security-adjacent acquisitions to quantum-safe algorithms beginning in 2027. If your organization sells into or operates alongside that supply chain, the procurement clock has already started.

    Your asset inventory is not a cryptographic inventory.

    Utilities are good at asset inventories. Almost nobody's asset inventory says which signature scheme validates firmware on each device class, which field credentials cannot be rotated without a truck roll, or which OT protocols carry no authentication at all and lean entirely on network isolation.

    That last category matters: where cryptography is absent, the compensating control is segmentation, and that is a documented risk decision, not an oversight, only if someone documented it. QCI-QS1's QASI inventory covers cryptographic functions, machine identities, rotation capability, and the evidence behind each row, and the Q-Risk Score cannot pass 65 without the identity and trust-chain portion complete.

    Vendors control your migration. Contracts control your vendors.

    In OT, the institution rarely controls its own cryptography; the vendor does. Without contractual PQC roadmaps and officer-signed attestations, your migration happens on the vendor's schedule, which is to say after their next hardware generation ships.

    The standard's vendor pack exists for exactly this: a standardized question set, an attestation format, and an exception register with exit strategies for suppliers who will not answer. Procurement language drafted now is cheaper than forklift replacement argued later.

    Crypto agility is a field operation here.

    Swapping an algorithm in a data center is a change window. Swapping one across fifty thousand field devices is a multi-year campaign with truck rolls. That is why the standard requires demonstrated agility evidence for at least one critical trust pathway before any score passes 80, and why the highest-leverage engineering requirement for new OT procurement is the ability to change algorithms without changing hardware.

    Where to start.

    A named owner. A cryptographic inventory of the device classes and control pathways that can cause a physical consequence, not the whole estate. A list of which protections are cryptographic and which are segmentation-by-default. Vendor roadmap requests to your top OT suppliers. One board briefing. A quarter of work, sequenced in a free standard.