Post-Quantum Cryptography · OpenChainGraph v0.4

Post-Quantum Cryptography: Protocol Migration Suite

Protocol-specific PQC migration across TLS/PKI, SWIFT/ISO 20022, FIDO2/WebAuthn, and blockchain/stablecoin signatures, built on the live inventory/HNDL/roadmap/agility spine (tools 499–502). Agent-native, hash-anchored, zero PII.

EU national crypto inventories required end-2026 CNSA 2.0 NSS procurement deadline: 2027 EU finance PQC-secured: 2030 G7 financial-sector roadmap: Jan 2026 FIPS 203 / 204 / 205 (ML-KEM · ML-DSA · SLH-DSA) NISTIR 8547 · CNSA 2.0 Post-Quantum Cryptography
⚠ MILESTONE NOTICE: EU national cryptographic inventories required by end-2026. CNSA 2.0 NSS procurement deadline: 2027. EU finance PQC-secured: 2030. G7 financial-sector roadmap: Jan 2026. Verify all dates against current official sources before citing.

Existing PQC Spine (live)

The four-tool inventory-to-agility backbone, already live. The protocol chains build on top of it.
pqc-migration: End-to-end PQC migration: crypto asset inventory (NISTIR 8547, tool 499) → HNDL quantum risk scoring (500) → phased migration roadmap (FIPS 203/204/205, tool 501) → crypto-agility readiness score (502). The canonical spine that all protocol chains extend.

New Tools (ART-85–89)

Five new nodes adding protocol-specific coverage. Start with ART-85 to triage and route your crypto estate.
ART-85 · pqc-fit entry point
PQC Timeline & Migration Fit Diagnostic
Maps your crypto estate to CNSA 2.0 / EU-2030 / G7 / DORA milestones. Emits a readiness grade and routes to the correct protocol chain. Start here.
art-85-pqc-timeline-fit-diagnostic
ART-86 · pqc-tls-pki / pqc-hndl-protocol-plan
TLS / X.509 PKI Migration Planner
Sequences TLS + PKI migration. Evaluates hybrid vs composite strategy, certificate-lifecycle windows, and CA replacement ordering against CNSA 2.0 and CA/Browser Forum timelines.
art-86-tls-pki-migration-planner
ART-87 · pqc-swift-iso20022
SWIFT / ISO 20022 PQC Readiness Checker
Checks SWIFT/ISO 20022 BAH signature-bloat sizing per BIS Leap Phase 2. Flags size-breach risk from the ~12.9× payload growth of ML-DSA vs ECDSA against per-message limits.
art-87-iso20022-pqc-readiness-checker
ART-88 · pqc-fido-webauthn
FIDO2 / WebAuthn PQC Conformance Checker
Checks FIDO2/WebAuthn/COSE ML-DSA conformance vs IANA algorithm identifiers and CTAP2.3. Credential crypto-suite migration only; credential FORMAT conformance is EUDI scope.
art-88-fido-pqc-conformance-checker
ART-89 · pqc-blockchain-risk
Blockchain / Stablecoin Quantum-Risk Classifier
Classifies blockchain/stablecoin signature exposure (exposed-pubkey percentage, key-reuse rate, migration-maturity tier) across ECDSA/EdDSA address types. Outputs quantum risk tier.
art-89-blockchain-quantum-risk-classifier

Protocol Chains (7)

Start with pqc-fit to classify and route. Each chain follows the hash-anchored provenance pattern: run stages in-browser or over MCP, pass execution_hash forward, export the terminal artifact. Aggregate everything in pqc-audit-pack.
pqc-fit · 1 node · entry point
PQC Timeline & Migration Fit Diagnostic
Single-node entry point. Maps crypto estate to regulatory milestones, emits readiness grade, routes to the correct protocol chain or existing pqc-migration spine.
→ ART-85
pqc-tls-pki · 3 nodes · PKI workhorse
TLS / X.509 PKI PQC Migration Plan
CBOM inventory (499) → TLS/PKI migration sequencing, hybrid vs composite strategy (ART-86) → Merkle integrity (cry-04). The PKI protocol-migration workhorse.
→ 499 · ART-86 · cry-04
pqc-swift-iso20022 · 3 nodes · payments
SWIFT / ISO 20022 PQC Readiness
HNDL risk prioritisation (500) → SWIFT/ISO 20022 readiness + BAH signature-bloat sizing (ART-87) → Merkle integrity (cry-04).
→ 500 · ART-87 · cry-04
pqc-fido-webauthn · 2 nodes · authentication
FIDO2 / WebAuthn PQC Conformance
FIDO2/WebAuthn/COSE ML-DSA conformance vs IANA identifiers + CTAP2.3 (ART-88) → audit receipt (cry-05).
→ ART-88 · cry-05
pqc-blockchain-risk · 3 nodes · blockchain
Blockchain / Stablecoin Quantum-Risk
CBOM inventory (499) → blockchain/stablecoin signature-exposure classification (ART-89) → Merkle integrity (cry-04).
→ 499 · ART-89 · cry-04
pqc-hndl-protocol-plan · 4 nodes · prioritised plan
HNDL-Prioritised Protocol Migration Plan
CBOM inventory (499) → HNDL scoring (500) → TLS/PKI sequencing (ART-86) → audit receipt (cry-05). Exposure-prioritised protocol plan.
→ 499 · 500 · ART-86 · cry-05
pqc-audit-pack · 3 nodes · convergence terminal
PQC Migration Audit Pack
Convergence terminal. Merkle integrity over the full PQC protocol decision set (cry-04) → Merkle-root receipt (cry-05) → regulator/board cover memo (ptg-01).
→ cry-04 · cry-05 · ptg-01
pqc-migration-evidence · 2 nodes · CBOM evidence
PQC Migration Evidence Workflow
CBOM structural lint and CNSA-2.0 classification (ART-386) → per-row CNSA-2.0 deadline ladder calculation (ART-387). Structural checks over a declared inventory, not a security scan.
→ ART-386 · ART-387

Chain topology

pqc-fit (ART-85) · entry point ├──→ pqc-migration (existing spine · inventory → HNDL → roadmap → agility) ├──→ pqc-tls-pki (TLS/PKI protocol migration · 499 → ART-86 → cry-04) ├──→ pqc-swift-iso20022 (SWIFT/ISO 20022 · 500 → ART-87 → cry-04) ├──→ pqc-fido-webauthn (FIDO2/WebAuthn · ART-88 → cry-05) ├──→ pqc-blockchain-risk (blockchain/stablecoin · 499 → ART-89 → cry-04) ├──→ pqc-hndl-protocol-plan (HNDL-prioritised · 499 → 500 → ART-86 → cry-05) ├──→ pqc-migration-evidence (CBOM evidence · ART-386 → ART-387) └──→ (all) → pqc-audit-pack (convergence terminal)
NIST PQC standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA), finalized Aug 2024. NISTIR 8547 (transition guide). Verify current status at csrc.nist.gov.
CNSA 2.0: NSA Commercial National Security Algorithm Suite 2.0, NSS procurement deadline 2027. Verify at media.defense.gov.
EU cryptographic inventory: National cryptographic inventories required by end-2026 per EU Cyber Resilience Act / NIS2 implementing measures. Verify current obligations at eur-lex.europa.eu.
G7 financial-sector PQC roadmap: Published Jan 2026. Verify at g7.utrechtfinance.org or relevant national regulators.
DORA: Fully enforced 17 Jan 2025. ICT risk obligations apply to cryptographic controls. Verify at eur-lex.europa.eu/eli/reg/2022/2554/oj.
OpenChainGraph v0.4 · Post-Quantum Cryptography · © 2026 Post Oak Labs · Suite · Spec v0.4 · Zero PII · CC BY 4.0