Migration Planning / MTI Negotiator

What this is for: Protocol-designer + architect decision tool from CSWP.39 §3.1.1 - picks Mandatory-to-Implement signature / KEM / hash plus alternates from audience, deadline, and constraint inputs.

What a good answer looks like: A mandatory-to-implement set both ends can actually negotiate today, checked against the protocol matrix rather than assumed.

Worked example: Keep TLS 1.3, Global commercial and 'Must interop with non-PQC peers': the table names ML-DSA-65 as signature MTI, X25519MLKEM768 as KEM with ML-KEM-768 as alternate and SHA-256 as hash, and a watch-out gives the TLS named-group codepoint.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Security Architect
Choose the protocol and audience, the interoperability profile (non-PQC, hybrid-only or pure-PQC peers), the compliance deadline and hardware constraints: the tool picks the mandatory-to-implement signature, KEM and hash with alternates, checked against the protocol matrix.

Mandatory-to-Implement (MTI) Negotiator

Protocol-designer + architect decision tool from NIST CSWP 39 Section 3.1.1 - Mandatory-to-Implement Algorithms. Picks a balanced MTI per cryptographic role (signature / KEM / hash) and emits an editable recommendation document.

MTI = interop floor

Every implementation must support the MTI - it is the basic-interop guarantee.

Alternates negotiate up

Stronger / more efficient alternates can be selected when both peers support them.

Local policy may override

CSWP-39 Section 3.1.1 confirms local policy may select an algorithm other than the MTI.

Step 1 - Protocol & audience

Which protocol and audience is this MTI recommendation for?

Step 2 - Standards tracking & constraints

What standards posture and hardware limits constrain your MTI pick?

Step 3 - Plan narrative (editable)

Edit the narrative, watch-outs, and adoption notes that will appear in the exported recommendation.

Try it

What must the mandatory-to-implement set be checked against?

Next step

Next in Migration Planning: Crypto API Refactor Audit

Crypto API Refactor Audit is the next Migration Planning tool in the Command Center.