Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

  • Home
  • Blog
  • Post-Quantum Resilience Has to Go All the Way to the Silicon

Post-Quantum Resilience Has to Go All the Way to the Silicon

PQC

Written by Keyfactor, with guest author Steve Orrin, Intel

 

For security teams preparing for post-quantum cryptography, one question comes before migration: 

What, exactly, are we migrating?

Cryptography is embedded throughout the enterprise. It protects identities, applications, connections, software updates, firmware, and data. It lives in cloud infrastructure, operating systems, libraries, endpoints, and hardware. 

And on the enterprise PC, some critical cryptographic capabilities exist even deeper in the stack, at the processor level. 

That creates an important blind spot for post-quantum planning. 

Knowing which algorithms and certificates are in use is essential. But organizations also need to know whether the hardware beneath them can support where their cryptographic strategy is headed. 

You can’t migrate what you can’t see

NIST has finalized its first PQC standards, and NSA’s CNSA 2.0 has established a transition path for National Security Systems. The direction is clear. 

But adopting new algorithms isn’t the first step. Discovery is. 

Before security teams can build a credible migration plan, they need to know: 

  • What cryptography are we using and where? 
  • Which algorithms and dependencies need to change? 
  • Which systems can be updated through software? 
  • Which may eventually require new hardware? 

Without those answers, a PQC roadmap rests on assumptions. And even a detailed software inventory can miss part of the picture. 

Look below the operating system

Modern processors support security functions involved in secure boot, firmware integrity, hardware-based roots of trust, protected key storage, storage encryption, memory encryption, attestation, and trusted execution. That changes the question security teams need to ask. 

It’s no longer only: Which applications use cryptography that needs to change? 

It’s now also: Can the underlying platform support the cryptographic capabilities we’ll need next? 

Some changes may require only a software or configuration update. Others may depend on the underlying hardware. 

Finding that out early gives organizations time to incorporate cryptographic requirements into normal hardware lifecycle and procurement decisions, rather than discovering the constraint in the middle of a migration. 

Bringing silicon into the cryptographic inventory

Intel and Keyfactor are collaborating on a Technology Preview designed to provide deeper visibility into endpoint cryptographic readiness. 

Building on Keyfactor AgileSec cryptographic discovery and analytics capabilities, the Technology Preview analyzes certain cryptographic capabilities associated with Intel processor platforms alongside other endpoint cryptographic findings. 

The goal is to connect two views that are often considered separately: the cryptography an endpoint uses and the cryptographic capabilities of the hardware underneath it. 

That context can help organizations: 

  • Build a more complete endpoint cryptographic inventory 
  • Assess hardware readiness against evolving PQC requirements 
  • Distinguish software remediation from potential hardware refresh needs 
  • Prioritize migration work based on evidence 

This isn’t about replacing every endpoint because quantum computing is coming. 

It’s about knowing which systems may need attention, why, and when. 

This matters to CISOs and Security Practitioners concerned with procurement and refresh cycles, risk-based remediation priorities, and the need for audit-ready evidence that boards and regulators require. 

Turn visibility into readiness

Discovery also has to work at enterprise scale. 

Keyfactor’s integrations with ecocystem partners, like CrowdStrike Falcon, help organizations orchestrate cryptographic discovery across endpoints and collect findings at scale. The Intel Technology Preview adds silicon-level context to that picture. 

The result is a better set of questions for security teams: 

  • What’s here? 
  • What’s at risk? 
  • What can the platform support? 
  • What needs to change? 

That’s the difference between having a cryptographic inventory and having a migration plan. 

Organizations don’t need every PQC answer today. But they do need enough visibility to make informed decisions about applications, infrastructure, endpoints, and hardware. 

Because the cryptographic landscape doesn’t stop at the operating system. Post-quantum readiness has to go all the way to the silicon. 

Learn more about post-quantum readiness and explore PQC in the Keyfactor PQC Lab. 

Learn more about Intel’s approach to post-quantum cryptography.