COMETQuantum computing is an imminent threat that will enable threat actors who target USG department and agency IT infrastructure to break existing cryptographic systems and gain access to critical information. To address this threat, agencies and organizations will need to migrate their resources to post quantum cryptography (PQC) standards. With the aim of launching this spring, ZRA is working to develop COMET (Cryptographic Object Migration Evaluation Tool) to guide organizations in critical decision-making that will ultimately result in a relevant and nuanced PQC migration effort.COMET includes five compounding stages of critical assessment, each necessitating collective leadership management: business processes assessment, analysis of threat environments, integration, risk analysis, and migration decision-making. ZRA will guide organizations through each stage of assessment to ensure the successful implementation and migration to PQC standards. Thorough assessments of each area will facilitate a comprehensive approach to migration decision-making. Developing and maintaining cryptographic inventories, which catalog all endpoints, devices, services, dependencies, algorithms, protocols, and keys within an organization’s IT infrastructure, poses significant challenges to organizations. Through COMET, ZRA will help organizations navigate these challenges to ensure that inventories remain comprehensive and up to date as new standards emerge. Cryptographic inventories serve as a crucial starting point for any organization aiming to transition to post-quantum cryptography (PQC) as they provide a clear and detailed map of existing cryptographic assets. Using a prioritized cryptographic inventory, ZRA will guide organizations to make critical decisions on encryption and develop a comprehensive migration roadmap. Organizations will integrate risk analysis findings to identify the needed strength to secure systems, determine which layers of communication need encryption, and decide on which encryption algorithms to secure their systems. COMET will provide a roadmap for organizations to understand their systems and assets, identify the threats they face and the weak points that might be exploited, and develop a comprehensive plan for migrating necessary systems to PQC standards. ZRA’s COMET white paper details the specific actions for organizations to take to ensure successful PQC migration. It covers an overview of the quantum computing threat and actions taken by key government agencies to address the threat, including OMB, ONCD, CISA, NIST and the White House. The white paper describes requirements and critical decisions for PQC migration, then moves into discovery and posture management. The challenges of developing a cryptographic inventory are discussed, followed by a detailed description of the components of a cryptographic inventory and the classification of components. After the cryptographic inventory is prioritized, COMET will guide organizations through the development of a comprehensive migration roadmap. ZRA's development of COMET aims to provide organizations with a sophisticated instrument for navigating the complex process of transitioning to post-quantum cryptography, ensuring a tailored and effective migration strategy. | ![]() |