惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
量子位
GbyAI
GbyAI
腾讯CDC
T
Tailwind CSS Blog
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Docker
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
Stack Overflow Blog
Stack Overflow Blog
Hugging Face - Blog
Hugging Face - Blog
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
Netflix TechBlog - Medium
Jina AI
Jina AI
IT之家
IT之家
Y
Y Combinator Blog

News and Events Feed by Topic

Seeking Public Comment! Using Artificial Intelligence for Cybersecurity Framework 2.0 Analysis and Reporting New 5G White Paper Available: Initial Non-Access Stratum Message Security NCCoE Transit CSF Community Profile Webinar ‘Spooky’ Particles Transit DC Suburbs, a Step Toward a Quantum Network Strengthening Transit Resilience: Final CSF Community Profile + Upcoming Webinar NIST NCCoE Mobile Driver’s Licenses Use Case #2 Update NIST Joins National Genesis Mission to Accelerate AI Innovation Back to Basics: Foundational Cybersecurity Practices for Small Businesses Securing AI Data Center: Architecture, Security Posture, and Emerging Standards New NCCoE Project: Asset Management and Visibility for Operational Technology (OT) Environments NIST Guidelines for Secure Remote Access in Water and Wastewater Systems NIST Workshop on Hardware CPE and CVSS Updates NCCoE Two-Pager Now Available: Effective OT Backup Management The Department of Commerce’s CHIPS Program Announces a Letter of Intent with Coherent for up to $50 Million to Expand Indium Phosphide Production Now Available: Practical Guidelines for Preventing and Mitigating Ransomware NIST NCCoE Genomic Data PETs Testbed & Dioptra Webinar NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems NCCoE Cybersecurity Connections Event: Accelerating the Adoption of Mobile Driver's Licenses NIST Expands AI Consortium’s Scope, Calls for New Members Now Available: NIST SP 1800-41, Responding to and Recovering from a Cyber Attack NCCoE Manufacturing Project Update NIST NCCoE Cyber AI Profile Virtual Working Session Series: Usability of the Profile Draft PNT Profile Updated to Align with NIST CSF 2.0 NIST NCCoE Cyber AI Profile Virtual Working Session Series: Extending the Technical Content CAISI Signs Agreements Regarding Frontier AI National Security Testing With Google DeepMind, Microsoft and xAI NIST NCCoE Cyber AI Profile Virtual Working Session Series: Updates to Profile Elements and Contents NICE Releases NICE Framework Components v2.2.0 Adoption of Mobile Driver’s Licenses for Financial Institutions Webinar NIST Updates NVD Operations to Address Record CVE Growth New Publication: Automation of the NIST Cryptographic Module Validation Program
New Draft White Paper | PQC Migration: Mappings to Risk F...
2025-09-18 · via News and Events Feed by Topic

The NIST National Cybersecurity Center of Excellence (NCCoE) has published an initial public draft of NIST Cybersecurity White Paper (CSWP) 48, Mappings of Migration to PQC Project Capabilities to Risk Framework Documents.

Cryptographic algorithms are vital for safeguarding confidential electronic information from unauthorized access. For decades, these algorithms have proved strong enough to defend against attacks using conventional computers that attempt to defeat cryptography. However, future quantum computing may be able to break these algorithms, rendering data and information vulnerable. Countering this future quantum capability requires new cryptographic methods that can protect data from both current conventional computers and the quantum computers of tomorrow. These methods are referred to as post-quantum cryptography (PQC). The NCCoE Migration to PQC project is a collaboration with industry and government to demonstrate capabilities that support an organization’s migration to PQC.

The Need for Action

Organizations should start planning now to migrate to PQC, also known as quantum-resistant cryptography, to protect their high value, long-lived sensitive data.

Historically, it has taken a long time from the moment that a new algorithm is standardized until it is fully integrated into information systems.

No one knows how long it will take to build a cryptographically relevant quantum computer. Predictions vary widely, but some people think it may be possible in less than 10 years.

Even if computer security experts implement post-quantum encryption algorithms before sufficiently powerful quantum computers are built, a lot of encrypted data remains under threat because of a type of attack called “harvest now, decrypt later.” This attack describes an adversary who can’t crack the encryption that protects our secrets at the moment who works to capture encrypted data and hold onto it, in the hopes that a quantum computer will break the encryption down the road.

About CSWP 48: Aligning with Cybersecurity Frameworks and Security Controls

The paper is designed to connect those whose risk management practices reference the NIST cybersecurity framework and controls documents with the capabilities in actions to migration to post-quantum cryptography. Specifically, this paper maps capabilities demonstrated in the NCCoE Migration to PQC project to several security objectives and controls found in two important NIST documents:

  1. NIST Cybersecurity Framework 2.0 (CSF 2.0). A widely adopted framework that helps organizations manage and reduce cybersecurity risk.
  2. Security and Privacy Controls for Information Systems and Organizations (SP 800-53). A comprehensive catalog of security controls that organizations can use to protect their information systems.

This helps organizations align their PQC migration efforts with established security outcomes (and broader cybersecurity risk management practices) and identify specific security controls and objectives needed to successfully implement PQC migration.

Your Feedback Matters

We invite you to review this document and provide comments by October 20, 2025. Comments can be submitted by visiting the NCCoE project page. If you have any questions or need further information, please don’t hesitate to contact the team at applied-crypto-pqc [at] nist.gov (applied-crypto-pqc[at]nist[dot]gov). We encourage you to join the NCCoE PQC Community of Interest (COI) to receive project updates and stay involved!

Comment Now!

View this on the NCCoE website