SecureAzCloud Public PQC Artifact

PQC Cloud & Workload Identity Migration Checklist

Checklist covering certificates, workload identities, PKI, TLS/mTLS, signing, key lifecycle, SaaS dependencies, and cloud/IAM migration controls.

Version v1.0 | Updated 2026-06-07 | Vendor-neutral | NIST-aligned | Public/redacted planning aid

← Back to SecureAzCloud PQC Migration Resource Hub

This public version is intentionally redacted and uses examples/placeholders only. It does not include secrets, hostnames, IP addresses, customer data, internal diagrams, proprietary product configurations, or key material.

Downloads

XLSX Checklist

Workbook with cloud/IAM checklist, workload identity inventory, certificate/key map, CISA category mapping, pilot test plan, and sources.

PDF Companion

Printable checklist companion with CISA 2026 product-category alignment and pilot acceptance criteria.

CSV Checklist

Lightweight CSV checklist for importing into ticketing, GRC, or project management tools.

What this artifact covers

AreaCoverageExpected Evidence
Certificates and TLSManaged certs, public/private CAs, mTLS, API gateways, service mesh, chain-size and relying-party constraints.Certificate scan, CA export, TLS test result, gateway/service-mesh config.
Workload identitiesService principals, IAM roles, managed identities, Kubernetes service accounts, SPIFFE/SPIRE IDs, CI/CD identities.IAM export, trust bundle map, workload identity inventory.
Identity signingOIDC, OAuth, SAML, JWT, federation metadata, verifier libraries, and SaaS relying parties.IdP signing-key inventory, relying-party test results.
SaaS/vendor readinessSupplier roadmap, cryptographic disclosure, support windows, procurement language.Vendor response, contract clause, support commitment.

Recommended use

  1. Use the Checklist sheet to assign owners, priorities, due dates, and evidence links.
  2. Populate the Workload_Identity_Inventory for P1 applications and shared platforms.
  3. Populate the Certificate_and_Key_Map for TLS, mTLS, token signing, KMS/HSM, and CA dependencies.
  4. Use the CISA_Category_Map to support vendor/procurement questions.
  5. Run Pilot_Test_Plan in non-production before production change approval.

Standards and source alignment

Aligned to CISA's 2026 PQC product-category release for cloud services, web software, and endpoint security, and to NIST PQC migration guidance.

Core references include NIST FIPS 203, NIST FIPS 204, NIST FIPS 205, NIST NCCoE Migration to PQC, NIST CSWP 39 crypto-agility guidance, CISA quantum-readiness resources, and CISA's 2026 product-category announcement for PQC adoption.

Disclaimer

This artifact is an independent planning aid. It is not a government publication and does not imply endorsement by NIST, CISA, or any public agency. Organizations should adapt it to their own architecture, operating constraints, regulatory obligations, and vendor support status.