industry · quantum risk
Is Zero trust PQC Quantum Proof? Cyber Program & PQC
Verdict
Combining zero trust with PQC means upgrading the cryptography under continuous verification—not only microsegmentation. Prioritize identity, edge TLS, and service mTLS in the trust fabric.
Overview
Security architects ask how PQC fits zero-trust roadmaps. Answer: treat algorithms as first-class policy objects with owners and metrics.
Pilot hybrid on north-south edges; plan mesh and token signing with platform teams.
Program inventory focus: Control and data planes both may be classical today. Typical classical surfaces: Policy engines over classical or hybrid channels; Workload identity certs. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: Policy engines over classical or hybrid channels, Workload identity certs
- Hash: Control-plane integrity
- Public-key exposure: Control and data planes both may be classical today.
What breaks
- Policy richness with weak crypto
- Ignoring connector certificates
Mitigations
- Crypto requirements in ZT reference architecture
- Vendor roadmap gates for brokers
- Tabletop: forged classical tokens
FAQ
PQC before zero trust?
Parallel tracks; do not block inventory while redesigning access.
Where is network depth?
/security/network and Wave 7b protocol pages.
Key concepts (technical dictionary)
Terms used on this page — open a definition: