Post‑Quantum Crypto Deadlines Collide With OT Legacy Gaps
What Happened — NIST finalized post‑quantum cryptography (PQC) algorithms in August 2024 and set mandatory adoption windows for critical‑infrastructure operators (2028‑2030, with RSA/ECC prohibited by 2035). Practitioners warn that most operational‑technology (OT) environments—SCADA, PLCs, field‑level protocols—lack the cryptographic foundations needed to swap in PQC today.
Why It Matters for Compliance & Audit Readiness
- SOC 2’s Encryption (CC6.1) and System Operations (CC3.1) controls require documented, auditable cryptographic algorithms; legacy OT devices threaten continuous compliance evidence.
- Mapping PQC migration to existing control frameworks creates a defensible audit trail and demonstrates due‑diligence to regulators and customers.
- Continuous evidence collection on algorithm rollout and OT asset inventory helps satisfy both internal governance and external certification bodies.
Who Is Affected
- Energy & utilities (power grids, water treatment, transportation)
- OT‑focused vendors and system integrators
Recommended Actions
- Conduct a PQC gap analysis of OT protocols and hardware.
- Update control documentation to reflect new algorithm requirements and map them to SOC 2 CC6.1.
- Deploy continuous monitoring tools that capture cryptographic configuration changes as audit evidence.
Technical Notes
- No specific CVE; the risk stems from protocol designs that lack built‑in cryptography (e.g., IEC 60870‑5, DNP3).
- Migration will involve both software upgrades and hardware replacements for field devices.
Source: DataBreachToday