Podcast

Root Causes 636: The Future of Crypto Agility

Hosted by
Tim Callan
Tim Callan
Chief Compliance Officer
Original broadcast date
July 2, 2026

Dustin Moody of NIST joins us to talk about the evolution of standardized cryptography beyond the current PQC efforts. Topics include maintaining visibility on cryptography presently in use, 50 years of RSA, and cryptographic heterogeny.

Podcast Transcript

Tim CallanTim CallanHi, welcome back to Root Causes, and welcome back to Dr. Dustin Moody, our repeat guest from NIST. We've been diving deep on a number of topics around the current state of the PQC effort, and today I'd like to pick up something that you dropped a few episodes ago, Dustin, if I may - where you sort of talked about the on-ramp, which is going on right now, which is trying to bring possibly another one or two DSAs into the mix of approved PQC algorithms, and that's probably a few years more to go. What happens after that? Are we going to continue to have new contests, and are we going to continue to push research on this? Or what goes on next?
Dustin MoodyDustin MoodyNo, I think we're done, and we can all go home and rest easy. That's it.
Tim CallanTim CallanThat's it.
Jason SorokoJason SorokoThat's it. Math is solved. There's no more math. Exactly.
Dustin MoodyDustin MoodyNo, we never know what exactly is going to come next, but we do know research is going to come and things are going to change. There's going to either be new attacks that are discovered, or there's going to be new algorithms that are discovered that lead to better cryptosystems. Or there's going to be new innovations like a quantum computer or AI that are going to change up the field. So, while the specifics of what comes next after the on-ramp - that's as far as we've kind of currently got in the hopper for what's in play at the moment. We do know that we need to be prepared and to respond to that. So we very much encourage people to, as they're making this transition to PQC, they do so with crypto agility - with that idea that there's going to be a future transition at some point, and you want to make that as easy as possible for yourself while you're doing this first transition. If we'd have had that viewpoint over the past thirty years, maybe the PQC transition would have been a little bit easier than it is going to be currently. So I don't know exactly what will come. This is hard. This is really hard.
Tim CallanTim CallanAnd if you start imagining that this isn't the last time - I recall a conversation I had probably a year ago with somebody who is in charge of PKI at a global 1,000 firm, who said, "Oh, I'm going to be glad when this is over." And I said, "I don't think that's the way to think about it," right? Should we assume - for those of us, unless you're near the end of your career, unless you're near retirement - should we assume that this isn't the last time we're going to make a transition like this?
Dustin MoodyDustin MoodyI think it's likely. I don't know when it will be, but I expect that there will be another cryptographic transition. Technology will advance, computers will be faster
Tim CallanTim CallanCould be sooner, could be later. Twenty or thirty years is a long time. I was imagining it could be considerably less than that.
Dustin MoodyDustin MoodyDo you think these things will last for twenty years?
Tim CallanTim CallanI hope they do.
Dustin MoodyDustin MoodyYou're right - it could be less. It's hard to say with any certainty. Hard to say.
Tim CallanTim CallanI know. So what do we do so that the next time - let's assume that there is a next time, or at least, to your point, we have to be ready for there to be a next time. Whether or not it happens, we have to prepare as if there will be a next time. What do we do to do that preparation? How do we - as an industry, as a set of technology platforms - change so that it's not so hard next time?
Dustin MoodyDustin MoodyThis is actually a way more complex topic than I ever thought it was back when I was first hearing the term crypto agility, several years back. My colleague Lily Chen at NIST has written up a very nice white paper giving the NIST perspective on crypto agility and some things you can do. I think we need to do a good job of paying attention to what cryptography we're using, where we're using it, and what information it's protecting. Because, like, right now - that was one of the biggest things, is when we said you need to switch to new algorithms, well, you have to start with finding out where. And then, ideally, you would have already known that. It's not just the algorithms, though. Cryptography gets used in protocols and in products, and it's not just switching the algorithm, but all those other pieces too, as well. How does it fit into TLS, or how does it fit into IKE - and can those be adapted? Can those protocols be changed in a way so that putting in one algorithm in the future will be easier? So there's just a lot of different things you can do at the different levels of the stack to ensure that it's not tied to a specific algorithm, it's not tied to a specific protocol. But just having that viewpoint that there's going to be a transition, so let's make this as generic as possible so that we can plug and play - and that will help, I think.
Jason SorokoJason SorokoI think it's interesting, Dustin, that if we were to sit here and whiteboard the problem sets around everything you just said, I think a lot of it comes down to: we all got spoiled by the longevity of RSA especially - fifty years of RSA. Good old RSA, it'll always be there for me. And ECC has proven itself to be just awesome in every way possible
Tim CallanTim CallanAnd you're touching on an interesting point there, Jason. Traditionally, we've had a very homogenous PKI, in terms of cryptography. We've had just really a couple of signature algorithms - not a lot. Are we imagining a world where it's much more heterogeneous and situational, and there are multiple algorithms in my toolkit, and I'm going to pull the one that I feel is best for a particular use case? Is that the future we should be looking at?
Dustin MoodyDustin MoodyIt's a good question, because there's that balance of wanting the right tool for the right thing - and one tool can certainly be a lot better - balancing that against interoperability, where if you have a number of algorithms that you've got to do, that makes it harder to interoperate. You see that, like, in TLS, where if you have to add five KEMs and four signatures, just kind of the combinatorial possibilities, it makes it really hard. So that is a balance. I do think there will be some algorithms - some PQC algorithms - that are better suited for some use cases, and then there's algorithms designed just for that, and they use those algorithms. But in my view, there will still probably be some kind of general-purpose ones that cover 80%, 90% of use cases, and that's what people will tend to use.
Jason SorokoJason SorokoThat's actually important, in terms of thinking through the future and cryptographic agility - that we might have to think about use cases themselves having specific, very compelling algorithm changes down the road. And I just - towards the end of this podcast, Dustin, I want to thank you for having a sense of humor, because we're dragging you into all kinds of things that are far beyond your remit, which is the hardest thing there is: which is actually choosing the primitives. We thank you for doing that very well.
Dustin MoodyDustin MoodyThank you. You have to have some humor while you're doing this.
Tim CallanTim CallanSo, it's a fast-moving world. I'm sure somewhere along the line we're going to ask you to come back and talk about the things that have happened between now and then. But thank you so much for joining us. I think your perspective is extremely important, and it's good that our listeners have a chance to hear directly from you. Thank you very much.

Stay informed with expert insights

Subscribe to Root Causes for engaging discussions on PKI, digital security, and best practices for protecting your organization's critical assets. Don’t miss an episode!

Listen on Apple PodcastsListen on SpotifyListen on SoundCloud