7 min read
CMMC Is Paused. Your Obligations Aren't.
CMMC Phase II is paused, but DFARS, NIST 800-171, SPRS scores, and prime flow-downs may still apply. Here's what defense suppliers should do.
6 min read
Bill Monreal :
September 3, 2026 (Updated September 3, 2026)
Encryption protects the information your business depends on, but the encryption itself can't be treated as permanent. Algorithms weaken. Certificates expire. Vendors retire protocols. Regulations and customer requirements evolve. Crypto agility is the ability to replace or adapt cryptographic algorithms across software, hardware, protocols, and infrastructure while preserving security and ongoing operations.
For an owner, CFO, or COO, the outcome is straightforward: when cryptography has to change, the business can respond deliberately instead of launching a disruptive emergency project. You don't need to become a cryptographer. You do need visibility, ownership, and a transition plan.
NIST defines crypto agility as a set of capabilities for replacing and adapting cryptographic algorithms while maintaining security and operations. That definition matters because encryption isn't confined to one firewall or application. It's woven through websites, virtual private networks, cloud services, software updates, digital signatures, email, devices, industrial systems, backups, and vendor connections.
If one of those components depends on an algorithm or protocol that becomes unacceptable, the technical change can quickly become a business problem. A production line may rely on an embedded device that can't be updated. A customer portal may depend on a third-party library. A certificate change may break an integration nobody documented. The risk isn't simply that old cryptography exists. It's that the organization doesn't know where it exists or what will happen when it changes.
Quantum computing is increasing attention on this issue, but it isn't the only reason to act. NIST finalized three post-quantum cryptography standards in 2024 and encourages organizations to begin preparing for migration. At the same time, ordinary certificate renewals, software vulnerabilities, vendor changes, and policy updates already test an organization's ability to adapt.
Crypto agility is therefore a resilience discipline. It helps leadership reduce uncertainty around changes that are inevitable, even when their timing isn't predictable.
The first useful step is to build a cryptographic inventory. Joint guidance from CISA, NSA, and NIST recommends discovering where quantum-vulnerable cryptography appears across IT and operational technology, including network protocols, applications, servers, firmware, software-update mechanisms, and development pipelines.
For a small or mid-sized business, the inventory doesn't have to begin as a perfect technical catalog. Start with the systems and information that would create the greatest business impact if confidentiality, integrity, or availability failed. Record what data the system handles, how long that data must remain protected, which certificates or protocols it depends on, who owns the system, which vendor supports it, and whether a replacement path exists.
Data life matters. Some sensitive records lose value quickly. Others must remain confidential for years. Long-lived information deserves earlier attention because an adversary could capture encrypted data now and attempt to decrypt it later if future capabilities make that possible. That doesn't mean every system needs an immediate overhaul. It means priority should reflect the value and lifespan of the information, not the novelty of the technology.
This is also where your cybersecurity obligations connect to the discussion. Regulated manufacturers and other compliance-driven organizations need defensible evidence that risk is being identified, prioritized, and managed. A documented inventory and transition roadmap can support that conversation without pretending a checklist removes the underlying risk.
Buying a product labeled “quantum safe” won't make an organization crypto-agile. The capability comes from repeatable decisions and tested processes across cybersecurity, managed IT, cloud, software, procurement, and business leadership.
A practical roadmap should cover five areas:
The point isn't to change everything at once. It's to make the next necessary change smaller, safer, and more predictable.
Crypto agility fails when it's isolated as a security-team project. Cloud architecture determines where keys and certificates are managed. IT operations determine how changes reach endpoints and servers. Software teams determine whether algorithms are hard-coded. Procurement determines whether vendors are required to disclose dependencies and roadmaps. Leadership decides which risks deserve investment.
That connected view reflects a larger truth: cybersecurity starts with business risk, not products. A cryptographic inventory should feed technology planning, vendor reviews, lifecycle decisions, and the same quarterly priorities used to manage the rest of the environment.
If you're comparing providers after searching for “managed IT services Cleveland,” ask more than how quickly tickets get closed. Ask whether the provider can map dependencies across security, cloud, software, and operations; help you gather proof of your cybersecurity; and turn the findings into a phased plan the business can sustain.
No one can give your business a reliable date when a cryptographically relevant quantum computer will arrive. Waiting for a perfect forecast misses the point. Cryptographic transitions take time because discovery, vendor coordination, testing, procurement, and operational change take time.
Start with one manageable outcome: identify the cryptography supporting your most important system or longest-lived sensitive data. Document the dependencies. Ask the responsible vendors about their migration plans. Then test one change without disrupting operations.
That's crypto agility in practical terms. It's not a bet on a particular algorithm or a promise that risk disappears. It's the confidence that when standards change, your organization can change with them.
Monreal IT helps regulated and compliance-driven organizations connect cybersecurity decisions to practical technology planning through The Monreal Way. If you want to understand where crypto agility fits in your risk roadmap, Start Here with our Compatibility Check.

7 min read
CMMC Phase II is paused, but DFARS, NIST 800-171, SPRS scores, and prime flow-downs may still apply. Here's what defense suppliers should do.

7 min read
Cyber insurance asking for proof? Start with MFA, backups, endpoint protection, response planning, and clear security documentation.

9 min read
When an employee leaves, access can linger in apps, email, files, and vendors. Use this practical offboarding checklist to close the gaps.