QRAMM: The Cryptographic Migration to a Post Quantum World

Emily Fane, Abdel Sy Fane

DEF CON 33 · Day 1 · Main Stage

Overview

In this critical DEF CON presentation, Emily Fane and Abdel Sy Fane introduced the Quantum Readiness Assurance Maturity Model (QRAMM), an open-source framework designed to guide organizations through the complex and urgent transition to post-quantum cryptography (PQC). The talk underscored the imminent threat posed by quantum computers to current public-key encryption standards, emphasizing that while large-scale quantum computers are still in development, adversaries are already engaged in a "harvest now, decrypt later" strategy, collecting encrypted data today with the expectation of decrypting it once quantum capabilities mature.

Watch on YouTube

Visual summary for QRAMM: The Cryptographic Migration to a Post Quantum World by Emily Fane, Abdel Sy Fane
Visual summary for QRAMM: The Cryptographic Migration to a Post Quantum World by Emily Fane, Abdel Sy Fane

Key moments

  1. 1:00 Shor's algorithm: the quantum threat to public key crypto
  2. 2:20 Grover's algorithm and quantum impact on symmetric crypto, blockchain
  3. 3:20 NIST Post-Quantum Cryptography standardization and new algorithms
  4. 4:20 Quantum threat timeline and urgent need for transition
  5. 5:30 Cryptographic agility: essential for post-quantum transition
  6. 6:30 Introducing QRAMM: Quantum Readiness Assurance Maturity Model
  7. 7:30 QRAMM Dimension 1: Cryptographic visibility and inventory

QRAMM: The Cryptographic Migration to a Post Quantum World

Speakers: Emily Fane; Abdel Sy Fane

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=SfWOqqDZEWI

Overview

In this critical DEF CON presentation, Emily Fane and Abdel Sy Fane introduced the Quantum Readiness Assurance Maturity Model (QRAMM), an open-source framework designed to guide organizations through the complex and urgent transition to post-quantum cryptography (PQC). The talk underscored the imminent threat posed by quantum computers to current public-key encryption standards, emphasizing that while large-scale quantum computers are still in development, adversaries are already engaged in a "harvest now, decrypt later" strategy, collecting encrypted data today with the expectation of decrypting it once quantum capabilities mature.

The speakers meticulously detailed the foundations of quantum computing, its implications for classical cryptographic algorithms like RSA, Diffie-Hellman, and Elliptic Curve Cryptography (ECC), and the NIST standardization efforts for new, quantum-resistant algorithms. A significant portion of the discussion was dedicated to the practical steps organizations must take, from inventorying cryptographic assets and developing transition plans to implementing crypto-agile architectures and deploying hybrid cryptographic solutions. QRAMM serves as a vital tool in this preparation, offering a structured, evidence-based assessment across key dimensions of cryptographic visibility, governance, data protection, and technical readiness.

This talk is particularly important because it moves beyond theoretical discussions of quantum threats, providing a concrete, actionable framework for preparation. The projected timeline for cryptographic deprecation by 2030 and full PQC transition by 2035 highlights the urgency, especially considering the historical inertia in updating cryptographic systems within organizations. By offering an open-source model and practical guidance, the QRAMM framework aims to demystify the PQC migration process, making it accessible and manageable for a wide range of enterprises facing this unprecedented security challenge.

Background

▶ Watch: Shor's algorithm: the quantum threat to public key crypto (1:00)

The advent of quantum computing introduces a paradigm shift in computational power, leveraging principles of quantum physics such as superposition and entanglement. Unlike classical bits that exist in a definite state of 0 or 1, a quantum bit or qubit can exist in a superposition of both states simultaneously. Entanglement allows multiple qubits to become linked, where the state of one instantaneously affects the others, regardless of distance. These properties enable quantum computers to perform certain computations with vastly greater efficiency than classical machines.

The cryptographic community became acutely aware of this threat with the invention of Shor's algorithm by Peter Shor in 1994. This algorithm can efficiently factor large numbers, a problem considered intractable for classical computers. The security of widely used public-key cryptographic algorithms like RSA relies precisely on the computational difficulty of factoring large numbers. Consequently, a sufficiently powerful quantum computer running Shor's algorithm could easily break RSA. Furthermore, variants of Shor's algorithm can also compromise Diffie-Hellman and Elliptic Curve Cryptography (ECC), as these are all based on more general problems falling under the Aelion hidden subgroup problem, which quantum computers can solve efficiently. This means virtually all current public-key cryptography will become obsolete.

For symmetric-key algorithms like AES and cryptographic hash functions, the threat is different. While Shor's algorithm does not directly break them, Grover's search algorithm offers a quadratic speedup for brute-force searches. This implies that to maintain the same level of security against a quantum adversary, the key length for symmetric algorithms would need to be doubled. For instance, AES-128 would offer only 64-bit quantum security, whereas AES-256 would provide 128-bit quantum security, making it a more robust choice. Blockchain technologies, while architecturally sound, rely on ECC digital signatures for transaction authorization and ownership proof, meaning they too will require a transition to quantum-resistant signatures.

In response to this looming threat, the National Institute of Standards and Technology (NIST) initiated a global competition in 2016 to standardize post-quantum cryptography (PQC) algorithms. As of 2024, NIST has begun standardizing several PQC algorithms, primarily lattice-based cryptography. The timeline for this transition is aggressive: organizations are advised to deprecate classical public-key cryptography by 2030 and achieve a full transition to PQC by 2035. This seemingly distant future is deceptive, as the complexity of cryptographic transitions, often seen to lag by decades in some organizations, necessitates immediate action, especially given the "harvest now, decrypt later" threat where adversaries are already collecting encrypted data. A core concept underpinning this transition is cryptographic agility, the ability to quickly and seamlessly swap out cryptographic algorithms or parameters without requiring major system redesigns, essential for adapting to evolving standards or newly discovered vulnerabilities in PQC algorithms.

Key Findings

▶ Watch: NIST Post-Quantum Cryptography standardization and new algorithms (3:20)

The central finding presented in the talk is the critical and immediate need for organizations to prepare for the quantum threat, underscored by the introduction of the QRAMM (Quantum Readiness Assurance Maturity Model) framework. This open-source framework serves as a structured, evidence-based tool to assess and guide organizations through their PQC migration journey.

A primary finding is the "harvest now, decrypt later" reality. Even though powerful quantum computers capable of breaking current public-key cryptography do not yet exist, nation-state adversaries are actively collecting vast amounts of encrypted data today. Their strategic intent is to store this data and decrypt it once quantum capabilities mature, potentially years or decades from now. This finding fundamentally shifts the urgency of PQC migration from a future concern to a present-day imperative, particularly for data with long-term confidentiality requirements such as intellectual property, protected health information (PHI), and personally identifiable information (PII).

Another key finding relates to the NIST PQC standardization process. After a rigorous, multi-year competition, NIST has begun standardizing a suite of quantum-resistant algorithms. The talk specifically highlighted CRYSTALS-Dilithium (a digital signature algorithm, also known as MLDDSA) and CRYSTALS-Kyber (a key encapsulation mechanism or KEM, also known as MLKEM), both of which are based on lattice problems. Unlike classical public-key algorithms whose security relies on unproven assumptions about computational hardness, these new lattice-based algorithms come with strong security proofs, demonstrating their hardness against both classical and quantum attacks, often linking their security to well-studied NP-hard problems. This provides a higher degree of confidence in their long-term viability.

The QRAMM framework itself is a significant contribution, comprising 120 questions structured across four dimensions, each with three practice areas. This comprehensive design enables organizations to:

  1. Gain Cryptographic Visibility and Inventory: Understand where and how cryptography is implemented, including algorithms, libraries, keys, and dependencies.
  2. Establish Strategic Governance and Risk Management: Develop executive-level, multi-year plans for transition and integrate PQC risks into overall enterprise risk management.
  3. Optimize Data Protection Engineering: Assess data sensitivity and exposure, prioritizing the protection of long-lived, high-value data against the "harvest now, decrypt later" threat.
  4. Achieve Implementation Technical Readiness: Evaluate existing systems for cryptographic agility and technical capacity to integrate new PQC algorithms without significant system redesigns.

Ultimately, the key findings coalesce into a clear message: the quantum threat is real and present, NIST has provided standardized solutions, and frameworks like QRAMM are essential tools for organizations to navigate this complex and time-sensitive cryptographic migration effectively and evidence-based.

Technical Deep Dive

▶ Watch: Quantum threat timeline and urgent need for transition (4:20)

The technical core of the quantum threat stems from fundamental differences between classical and quantum computing. Classical computers use bits, which are binary (0 or 1). Quantum computers use qubits, which, due to superposition, can be 0, 1, or any combination of both simultaneously. Additionally, entanglement allows qubits to be interconnected such that the state of one instantly influences the others. These properties enable quantum computers to solve certain problems exponentially faster than classical computers.

The most impactful quantum algorithm for cryptography is Shor's algorithm. It efficiently solves the problem of integer factorization and the discrete logarithm problem. Current public-key cryptography, including RSA (based on the difficulty of factoring large numbers) and Diffie-Hellman and Elliptic Curve Cryptography (ECC) (based on the difficulty of the discrete logarithm problem over finite fields or elliptic curves), relies on the computational hardness of these problems for classical computers. Shor's algorithm renders these problems tractable for a sufficiently powerful quantum computer, thus breaking the foundation of virtually all widely deployed public-key infrastructure. The speaker noted that these public-key systems are variants of a more general challenge known as the Aelion hidden subgroup problem, which quantum computers can solve very efficiently.

For symmetric-key algorithms like AES and hash functions, the threat comes from Grover's search algorithm. This algorithm provides a quadratic speedup for brute-force search attacks. While it doesn't "break" these algorithms in the same way Shor's algorithm breaks public-key crypto, it effectively halves their security strength. For example, a 128-bit symmetric key that would classically require 2^128 operations to brute-force would only require roughly 2^64 operations with Grover's algorithm. To maintain an equivalent level of security (e.g., 128 bits of security post-quantum), the key length must be doubled. Therefore, AES-256 is recommended over AES-128, as it would still provide 128-bit security against quantum adversaries.

The NIST Post-Quantum Cryptography (PQC) standardization effort, which began in 2016, is the global response to this threat. After several rigorous rounds of evaluation, NIST has begun standardizing new algorithms designed to be resistant to quantum attacks. The primary algorithms highlighted are:

  • CRYSTALS-Dilithium (MLDSA): A digital signature algorithm.
  • CRYSTALS-Kyber (MLKEM): A key encapsulation mechanism (KEM).

Both are examples of lattice-based cryptography, which derive their security from the perceived difficulty of certain mathematical problems on high-dimensional lattices. Unlike RSA, which lacks formal security proofs beyond empirical observation of its classical hardness, these lattice-based algorithms come with strong security proofs. Their hardness is often provably linked to well-known computationally hard problems, such as the shortest vector problem (SVP) or the closest vector problem (CVP) in a lattice, which are believed to be intractable even for quantum computers. This provides a much higher level of confidence in their long-term security. The rigorous eight-year standardization process, involving global research scrutiny, further solidifies trust in these selections.

The QRAMM framework itself is structured around four technical and organizational dimensions:

  1. Cryptographic Visibility and Inventory: This dimension focuses on the granular understanding of an organization's cryptographic landscape. It involves discovering and documenting every instance of cryptographic usage, including specific algorithms (e.g., AES-128 CBC), key lengths, parameters, cryptographic libraries (e.g., OpenSSL versions), Certificate Authorities (CAs), Hardware Security Modules (HSMs), and all cryptographic dependencies. Without this foundational visibility, a systematic migration is impossible.
  2. Strategic Governance and Risk Management: This covers the executive-level planning required for a multi-year transition. It involves setting policies, allocating resources, and integrating PQC risks into the overall organizational risk posture.
  3. Data Protection Engineering: This dimension assesses the sensitivity and exposure of data assets. It differentiates between data with short-term significance (e.g., credit card numbers that become stale quickly) and data with long-term value (e.g., intellectual property, PHI, PII). The latter is critically vulnerable to "harvest now, decrypt later" attacks and requires immediate prioritization for PQC protection. This also includes best practices for transitioning symmetric cryptography.
  4. Implementation Technical Readiness: This directly evaluates an organization's capacity for cryptographic agility. It assesses whether systems are designed to easily swap out cryptographic primitives without extensive code changes or system redesigns. This includes the ability to support larger key sizes or digital signature sizes, which are characteristic of some PQC algorithms, and to quickly update or replace algorithms if new vulnerabilities emerge. Techniques like abstracting cryptography behind centralized services or APIs are crucial here.

The technical deep dive into these areas underscores that PQC migration is not merely an algorithm swap but a comprehensive architectural and operational overhaul, demanding a structured approach like QRAMM.

Demo / Proof of Concept

▶ Watch: Introducing QRAMM: Quantum Readiness Assurance Maturity Model (6:30)

The talk did not feature a live technical demonstration of a quantum attack or a specific proof-of-concept implementation of post-quantum cryptography in action. Instead, the QRAMM (Quantum Readiness Assurance Maturity Model) framework itself serves as a practical, open-source tool for organizations to assess their readiness and plan their migration.

The speakers highlighted that the QRAMM framework is available at qram.org, where users can find the full GitHub repository containing the detailed assessment questions and even an automated quick assessment tool. This online resource allows organizations to immediately engage with the framework, input their current cryptographic practices, and receive results indicating their level of quantum readiness across the four dimensions. While not a code demo in the traditional sense, the QRAMM website and its associated tools provide a tangible and interactive "proof of concept" for how organizations can begin their PQC journey.

Defensive Implications

▶ Watch: QRAMM Dimension 1: Cryptographic visibility and inventory (7:30)

The defensive implications of the quantum threat are profound, demanding a proactive and multi-faceted strategy from organizations. The QRAMM framework and the speakers' recommendations provide a clear roadmap for this complex migration.

  1. Perform a Post-Quantum Assessment: The first step is to understand the current state. Organizations should conduct a thorough assessment of their cryptographic posture using tools like QRAMM or engaging consulting firms. This must extend to assessing vendors, understanding their PQC roadmaps and timelines, as supply chain readiness is critical.
  2. Inventory Cryptographic Assets: A comprehensive inventory is non-negotiable. This involves identifying all cryptographic implementations, including algorithms, key lengths, parameters, libraries, Certificate Authorities (CAs), and Hardware Security Modules (HSMs). Tools for this include:
  • Network scanning: Using TLS scanners like testssl.sh or SSL Labs to identify cryptographic protocols and configurations in network services.
  • Code scanning/Cryptolinting: Employing tools like Bandit, CryptoGuard, or trufflehog (for Git history) to scan application codebases for hard-coded cryptography, insecure implementations, or deprecated algorithms. GitHub's own secret scanning features can also be leveraged.
  • Inspecting cloud configurations and on-premises HSMs.
  1. Develop a Transition Plan and Revise Policies: Based on the inventory, a multi-year transition plan must be developed, outlining phases, responsibilities, and timelines. Existing security policies and standards must be updated to mandate the use of PQC algorithms and crypto-agile practices.
  2. Prioritize Data: The "harvest now, decrypt later" threat necessitates data prioritization. Data with long-term confidentiality requirements, such as intellectual property (IP), protected health information (PHI), and personally identifiable information (PII), should be prioritized for PQC protection. Short-lived data, like credit card numbers that become obsolete quickly, may have a lower immediate priority for PQC migration.
  3. Establish Crypto-Agile Architecture: This is a cornerstone of effective PQC migration. Organizations must design or refactor systems to avoid hard-coding cryptographic primitives. Instead, they should abstract cryptography through centralized services or APIs, allowing for quick and seamless swapping of algorithms, parameters, or updates. This architecture must anticipate potentially larger key sizes or digital signature sizes characteristic of some PQC algorithms.
  4. Test and Benchmark PQC Algorithms: Before widespread deployment, organizations should experiment with the newly standardized PQC algorithms. This involves testing their performance, resource consumption, and compatibility within existing environments. Libraries like OpenSSL 3.2 and liboqs (Open Quantum Safe) offer implementations of these algorithms for testing.
  5. Implement Hybrid Cryptography: As an immediate defensive measure and a bridge to full PQC, hybrid cryptography is strongly recommended. This involves combining a classical algorithm (e.g., elliptic curve) with a post-quantum algorithm (e.g., CRYSTALS-Kyber) in protocols like TLS 1.3 or AWS hybrid key exchange. This ensures classical security today while providing quantum resistance, mitigating risk even if one algorithm is later found to be vulnerable.
  6. Phased Deployment, Prioritizing KEMs: The deployment of PQC should be phased, starting with pilot programs. Crucially, Key Encapsulation Mechanisms (KEMs) should be prioritized over digital signatures. KEMs protect data confidentiality, directly addressing the "harvest now, decrypt later" threat, whereas digital signatures (protecting integrity and authenticity) can be transitioned later if resources are constrained. High-risk systems and those handling long-lived data should be the first targets for full PQC implementation.
  7. Monitor and Stay Updated: The PQC landscape is evolving. Organizations must establish continuous monitoring of their cryptographic inventory to ensure it remains accurate. They must also stay abreast of NIST's evolving PQC standards, any updates to algorithms or parameters, and emerging vulnerabilities.

By adopting these defensive strategies, guided by frameworks like QRAMM, organizations can systematically navigate the transition to a post-quantum cryptographic world, safeguarding their data against both current and future threats.

Key Takeaways

  • Imminent Quantum Threat: Quantum computers, utilizing Shor's algorithm, pose an existential threat to current public-key cryptography (RSA, Diffie-Hellman, ECC), rendering them obsolete once powerful quantum machines are available.
  • "Harvest Now, Decrypt Later" is Current: Adversaries are already collecting encrypted data, anticipating future decryption with quantum computers, making PQC migration an urgent, present-day security imperative for long-lived sensitive data.
  • NIST Standardization Provides Solutions: NIST has standardized quantum-resistant algorithms, notably CRYSTALS-Dilithium (digital signatures) and CRYSTALS-Kyber (Key Encapsulation Mechanisms), which are primarily lattice-based and offer strong security proofs against quantum attacks.
  • QRAMM Framework for Structured Migration: The Quantum Readiness Assurance Maturity Model (QRAMM) is an open-source, evidence-based framework providing 120 questions across four dimensions (visibility, governance, data protection, technical readiness) to help organizations assess and manage their PQC transition.
  • Cryptographic Agility is Paramount: Organizations must build or refactor systems for cryptographic agility to quickly and seamlessly swap out algorithms, parameters, or updates without major system redesigns, using centralized services and avoiding hard-coding.
  • Hybrid Cryptography and Phased Deployment: Implementing hybrid cryptography (classical + post-quantum) offers immediate risk mitigation. Deployment should be phased, prioritizing Key Encapsulation Mechanisms (KEMs) first to protect data confidentiality against the "harvest now, decrypt later" threat.

About the Speaker(s)

Emily Fane and Abdel Sy Fane are the co-creators of the QRAMM (Quantum Readiness Assurance Maturity Model) framework. Emily Fane delivered the majority of the presentation, detailing the quantum threat, the NIST standardization efforts, and the structure and utility of the QRAMM framework. Abdel Sy Fane joined for the Q&A session, providing additional insights and recommendations regarding practical tools and approaches for cryptographic inventory and migration. Their collaborative work focuses on providing actionable guidance and open-source resources to help organizations prepare for the transition to post-quantum cryptography.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

QRAMM is a well-intentioned maturity model wrapper around PQC migration guidance that's largely available in NIST documentation, CSA whitepapers, and a dozen consulting firm frameworks. The talk synthesizes existing public knowledge competently but doesn't contribute original research, novel tooling, or insider insight that a DEF CON audience couldn't get from reading the NIST IR 8547 and spending an afternoon on the Open Quantum Safe project.

Heather Calloway (CISO) — SOLID

QRAMM is a credible, well-structured framework that addresses a real and urgent cryptographic transition problem. The governance and data prioritization angles are genuinely useful, but the talk stays largely in framework-introduction mode and doesn't push far enough into institutional accountability or the organizational friction that makes these migrations fail.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33