Surface
Crypto-agility is the ability to change cryptographic primitives without rebuilding the system around them—like replacing a lock without rebuilding the house. This series walked from framing and threat modeling through keys, post-quantum planning, compliance, signing, ledger boundaries, incidents, and metrics. This finale is the scorecard: honest levels, not a marketing badge.
Use it in a ninety-minute workshop. Score each dimension 1–5. Average is fine for a headline; the gaps are what you schedule.

Crypto-agility maturity levels
L1 Ad hoc
Keys exist; few people know where
L2 Inventoried
Most prod keys listed with owners
L3 Policy-bound
Age, custody, change control written
L4 Dual-run ready
Overlapping verify + drills
L5 Measured
SLIs + MTTD/MTTR on the wall
Insight: if you have not drilled rotation in a year, you are not level 4 — no matter how good the architecture slide looks.
Maturity levels (1–5)
| Level | Name | You can honestly say | Typical rotation clock |
|---|---|---|---|
| 1 | Ad hoc | Keys exist; a few people know where | Months–unknown |
| 2 | Inventoried | Most production keys are listed with owners | Months with a project |
| 3 | Policy-bound | Age, custody path, and change control are written and mostly followed | Weeks with a program |
| 4 | Dual-run ready | Critical verifiers accept overlapping keys/algorithms; drills happen | Days for Tier-0 paths |
| 5 | Measured & rehearsed | SLIs on coverage, age, failed crypto auth, MTTD/MTTR; cold ceremonies current | Hours to contain, days to cut over |
Scorecard dimensions
Score each row 1–5 using the level definitions above. Weight Tier-0 signing and customer-auth paths higher if you need a single number.
| Dimension | What “5” looks like | Series anchor |
|---|---|---|
| Threat model currency | Assets, actors, and crypto failure modes reviewed on a set cadence | Threat model |
| Algorithm & key inventory | ≥98% tagged; exports feed monthly review | Observability SLIs |
| Key management architecture | HSM/MPC/cold mapped; no unnamed prod PEMs for Tier-0 | HSM & MPC |
| Production signing & custody | Hot/warm/cold paths with limits and quorum | Signing & custody |
| Ledger / trust boundaries | On-chain vs off-chain SoR explicit; indexes not authoritative for settlement | Ledger boundaries |
| Compliance evidence | Policies match production logs and ceremonies | Compliance as architecture |
| Migration readiness (incl. PQC) | Dual-run plan, vendor roadmap, harvest-now risk ranked | PQC migration |
| Incident rotation | Playbook tested; contain/cutover targets met in drill | Incident playbook |
| Crypto health SLIs | Inventory, age, failed auth, MTTD/MTTR on ops cadence | Metrics |
Example scored team (illustrative)
| Dimension | Score | Note |
|---|---|---|
| Threat model currency | 3 | Exists; last full review 14 months ago |
| Algorithm & key inventory | 4 | 97% tagged; legacy batch gap |
| Key management architecture | 4 | MPC for hot payouts; cold roots documented |
| Production signing & custody | 3 | Hot limits good; warm still partly in chat |
| Ledger / trust boundaries | 4 | Clear SoR; one index still treated as gospel in support |
| Compliance evidence | 3 | Policies strong; ceremony video retention uneven |
| Migration readiness (PQC) | 2 | Watching NIST; no dual-run on Tier-0 yet |
| Incident rotation | 2 | Tabletop only; no technical cutover drill |
| Crypto health SLIs | 3 | Inventory dashboard live; MTTR not yet tracked |
| Average | ~3.1 | Priority: dual-run + technical rotation drill |
A 3.1 is a workable mid-maturity product team—not a failure. The point is to fund the next two gaps, not to claim level 5 on a blog post.
How to run the workshop
1. Bring security, platform, product, and compliance—not only cryptography specialists 2. Pick Tier-0 systems first (treasury signing, customer auth, settlement anchors) 3. Score silently, then discuss outliers (large spreads mean shared fiction) 4. Choose two dimensions to raise by one level in the next quarter 5. Attach owners, budget, and a drill date
Reconnect product fit with blockchain business sense and data tiers with AI on-chain boundaries when AI or public-chain surfaces are in scope.
What “good enough for 2026” looks like
For most financial products shipping this year, a credible bar is solid level 3 with a funded path to 4 on signing, inventory, and incident rotation—plus an explicit PQC dual-run plan even if cutover is later. NIST’s post-quantum standards (FIPS 203/204/205) and deprecation guidance toward the 2030s make “we will invent migration under fire” an expensive strategy.
IBM-scale breach economics and MiCA-style operational expectations both punish unmeasured custody. Maturity is how you show you can change locks without demolishing the house.
Closing the series
- Start: Crypto-agility in 2026
- Model risk: Threat model
- Hold keys: HSM & MPC
- Plan change: PQC migration
- Prove control: Compliance as architecture
- Sign safely: Production signing
- Draw lines: Ledger boundaries
- Rehearse failure: Incident rotation
- Measure: Crypto health SLIs
- Score: this checklist
If you want a facilitated scoring session or a build-out against the gaps, SolveMotive’s blockchain, cyber security, and fintech practices run these workshops against working systems—not greenfield slides.





