A diagnostic framework that helps organizations understand where they stand and what capabilities they need to develop next — not a deployment checklist.
Maturity is measured by capability, not by remaining backlog.
By what the organization can do today in response to a vulnerability, a standard change or an algorithm deprecation — not by how much legacy migration remains pending. A legacy estate in active migration does not reduce the maturity level; it represents work in progress, not a deficit of capability.
Post-quantum cryptography is not a level to be reached at the end.
It is a dimension that improves at every level, and that can begin to be adopted from the moment the organization deploys a Cryptographic Control Plane. A model that places PQC at the summit misrepresents both the risk and the remedy.
Maturity should therefore be understood as the organization's ability to exercise the capabilities defined by CAPA across an increasing portion of its cryptographic environment. Progress is not determined by the adoption of a particular technology, provider or key infrastructure model, but by the organization's increasing ability to govern cryptographic change, retain cryptographic sovereignty, modernize existing protection, enforce policy and compliance requirements, and operate across heterogeneous enterprise environments.
Cryptographic logic is embedded directly within application code. Algorithm selection, library invocation and cryptographic parameters are decided at development time and become tightly coupled with the application. Implementations are inconsistent across systems, visibility is limited, and upgrades are manual. A critical characteristic is that the problem perpetuates itself: new applications are built with the same embedded patterns, because no architectural discipline requires otherwise. The cryptographic debt grows with every new deployment.
PQC at this level: absent or isolated — an adopted PQC algorithm is hardcoded exactly as a classical one would be, solving nothing structurallyCentralized components improve the management of cryptographic assets — HSMs, KMS platforms, certificate management, centralized key lifecycle. Key protection and governance improve materially. The limitation is not where keys reside: these infrastructures may themselves be distributed across providers, environments or organizational domains, and their consolidation is not a prerequisite for maturity. The limitation is that cryptographic behaviour and lifecycle decisions remain substantially coupled to individual applications. This is the earliest point at which an organization should establish a greenfield policy: a formal commitment that new applications will not embed cryptographic logic. That policy does not resolve existing debt — it stops its accumulation.
PQC at this level: PQC keys can be stored and rotated in the HSM or KMS, but algorithm governance remains per-application — enterprise-wide adoption stays uncoordinatedThe structural inflection point. The organization deploys a Cryptographic Control Plane — a dedicated infrastructure layer that decouples cryptographic behaviour from application code and centralizes its governance. This is not an incremental improvement over Level 2; it is an architectural change. The defining capability is not the existence of a cryptographic inventory — it is the ability to act on cryptographic policy without modifying or redeploying governed applications. For the existing landscape, a parallel process begins: the brownfield estate is inventoried and prioritized by exposure and data sensitivity. Discovery is applied to the past; the Control Plane governs the future.
PQC at this level: post-quantum and hybrid mechanisms can be introduced where risk, policy, interoperability or regulation require, without creating new application-level algorithm dependenciesThe Control Plane has been operational for a significant period and its coverage has expanded substantially. The focus has shifted from deployment to depth of migration: the most critical and most exposed systems now operate under centralized cryptographic governance, and algorithm transitions in those systems are executed through governed policy changes rather than code changes. The defining characteristic is the dual-track state: the greenfield is fully governed, while the brownfield is in advanced migration. The gap between the two tracks is the remaining technical debt, and systematically closing it is the primary operational objective of this level.
PQC at this level: classical–PQC hybrid coexistence is managed centrally across the governed landscapeEnterprise-scale adoption of governed cryptographic infrastructure. The organization's relevant cryptographic landscape operates predominantly under the Control Plane, including the critical brownfield environments identified for migration. Policy and lifecycle decisions are governed coherently across the enterprise, while cryptographic execution, keys and Roots of Trust may remain distributed across heterogeneous HSMs, KMS platforms, providers, jurisdictions and organizational trust domains. Vulnerability response across the governed landscape is coordinated through established policy and lifecycle mechanisms, and cryptographic posture is continuously evaluated against applicable standards and regulatory requirements.
PQC at this level: supported post-quantum strategies are introduced across governed systems through policy rather than repeated application-level implementationThe long-term state in which cryptographic evolution has become an embedded organizational capability. The distinction from Level 5 is not the deployment of additional technology, but the organization's ability to continuously absorb changes in algorithms, threats, standards, regulations, trust requirements, enterprise environments and external ecosystems through established governance and operational processes. At Level 5 that capability exists; at Level 6 it is the normal mode of operation — absorbed the way operating system patches, certificate renewals or infrastructure scaling events are absorbed today. New providers, trust domains, jurisdictions and external ecosystems can be incorporated without redesigning the cryptographic architecture.
PQC at this level: classical, hybrid, post-quantum and future mechanisms coexist and evolve according to policy and contextThe model is not a rigid progression in which one stage must be completed before the next begins. Many enterprises operate across multiple maturity levels simultaneously — some systems still at Level 1 while others have reached Level 3 or 4. This is not a failure of implementation; it is the expected reality of any enterprise transformation.
An organization may simultaneously operate a greenfield at Level 5 and a brownfield at Level 2.
The greenfield — all new systems being developed today — can and should adopt decoupled cryptographic architecture immediately, regardless of where the organization sits overall. The brownfield — the existing landscape with embedded cryptographic logic — requires a structured, phased migration prioritized by risk and operational feasibility. The organization's maturity reflects the weighted state of both tracks, and the strategic objective is to progressively close the gap between them.