Quantum-Safe Migration Playbook (Strategic & Operational Guide)

Bilar, Daniyel Yaacov · 2026-04-19 · publication/technicalnote · cc-by-4.0

Version of record (canonical): https://doi.org/10.5281/zenodo.19655682
Download PDF (Zenodo): open

Abstract

Version 1.2.0 is a major restructuring of the Quantum-Safe Migration Playbook with three goals: make the content usable as a retrieval-augmented AI knowledge base, tighten evaluation discipline, and update all dated facts to April 2026. What's new in v1.2.0 Structural changes Fact-ID indexing: every atomic claim now has a stable §N.M identifier for precise cross-reference and citation. Explicit scope block at the top of the corpus, listing what's covered and — critically — what's out of scope. This is what allows a downstream AI advisor to refuse out-of-scope questions instead of improvising. Cross-reference lines at the end of each section pointing to related fact IDs. Provenance block: every dated or numeric claim in the corpus is listed at the bottom with its source and a re-check cadence. Content updates (April 2026) §1.2: NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) finalized August 13, 2024; HQC selected March 2025; FIPS 206 (FN-DSA/FALCON) in development. §1.3: NSA CNSA 2.0 timelines specified by category — software/firmware signing and network equipment by 2030; browsers, servers, cloud, and operating systems by 2033. §1.4 (new): compressed Q-Day estimates. Neutral-atom architectures and improved error correction have cut the qubit count needed to break P-256. Cloudflare now targets 2029 for full internal PQ readiness. §2.1: Cloudflare reports 52% of human-initiated web traffic using post-quantum hybrid key agreement (December 2025 data), up from 29% at the start of the year. §2.3 (new): the authentication gap. Key agreement is largely solved; public PQ certificates are not yet broadly available; CA/Browser Forum has not finalized the hybrid certificate format. §4: replaced unsourced latency percentage with mechanism-based description. §6.4 (new): Cryptographic Bill of Materials (CBOM) concept. §9.3: sharpened vendor validation criteria with FIPS 140-3 and NIST CAVP references. Evaluation suite Expanded from 4 queries to 15 golden queries plus 6 distractor queries. Each query has explicit pass AND fail criteria, testable against paraphrased responses. Distractor queries test scope enforcement: QKD, quantum physics, vendor recommendations, exact Q-Day predictions, legal advice, general crypto tutorials. Integration guide (new) Dedicated INTEGRATION.md with a ready-to-paste system prompt for a retrieval-augmented runtime. Ingestion guidance (corpus fits in system context for models with ≥8K windows; chunking patterns for larger deployments). Refresh cadence tied to the Provenance block. Version history v1.1.0 — initial Zenodo release. v1.2.0 — restructured, fact-indexed, expanded evaluation suite, updated to April 2026 standards and deployment data.

Keywords

ML-KEM · ML-DSA · SLH-DSA · CNSA 2.0 · CBOM · RAG · KB · PQC · FIPS 203 · FIPS 204 · FIPS 205 · harvest now decrypt later · TLS 1.3 · NIST

← All research