Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Learn more

    Industries · State & Local Government

    A birth certificate has to stay verifiable for a century.

    Government records do not have retention periods so much as permanence: vital records, property titles, court filings, tax histories. Two different guarantees protect them, and quantum computing breaks both on different schedules. Confidentiality fails quietly through harvest-now-decrypt-later, where traffic captured today is read years from now. Verifiability fails loudly, when the digital signatures on filings, notarizations, and official records can no longer prove the record is authentic and unaltered. A government that cannot prove its own records are genuine has a problem older than cryptography.

    The federal direction is already published. OMB has directed federal agencies to inventory cryptographic systems and prepare migration, NIST has finalized the replacement algorithms and the deprecation trajectory, and CISA's guidance extends the preparation message to the state, local, tribal, and territorial community. Federal expectations have a habit of arriving in state procurement language within a few budget cycles.

    You are already running the identity migration. Once.

    States are shipping mobile driver's licenses and citizen digital identity at production scale right now. Every credential those programs issue rides on signatures with a published deprecation date, which means the question is not whether your state runs an identity migration; it is whether it runs the same one twice. Coordinating the live identity program with PQC planning today, one shared inventory, one re-issuance plan, one named owner, is the cheapest decision available to any state currently issuing digital credentials. QCI-QS1 v2.3 makes that coordination a requirement, not a suggestion.

    The machine identities behind every citizen service.

    Online tax filing, benefits portals, court e-filing, permit systems: all of it authenticates through service accounts, API keys, and certificates that no agency inventory currently counts. The credential population grew with every digitization initiative of the last decade and was inventoried by none of them. The standard's machine identity field group accepts order-of-magnitude estimates with a stated method, because the goal is a defensible answer to "what do we run on," not a census.

    Built for the budget you actually have.

    No new program, no new headcount as a precondition, and a standard with no license fee. The first quarter is a named owner, an inventory of critical systems only, a records-lifetime map, and roadmap requests to the vendors who actually hold your cryptography, which in most jurisdictions is a short list of well-known names. Cryptographic inventory and migration planning are eligible activities under the federal cybersecurity grant programs many jurisdictions already draw on, and the evidence trail the standard requires is the same documentation a grant administrator wants to see. Verify current program terms before committing funds; eligibility language changes by cycle.

    For counties and municipalities.

    Scale the same sequence down: one owner, the five systems that matter, the vendor letters, one briefing to the board or council. If the county's cryptography lives entirely with vendors, then the inventory is mostly a contract review, and that is still an inventory.