Governance & Policy / Policy Template Generator
§5.2What this is for: Generate cryptographic algorithm, key management, vendor, and migration policies.
What a good answer looks like: A policy someone can be non-compliant with. If no realistic action would breach it, it is a statement of values, not a policy.
Worked example: Approve ML-KEM (FIPS 203) and ML-DSA (FIPS 204), list RSA, ECDSA and ECDH as classical algorithms to retire, allow a 2-year exception window and set an annual review: the generated policy names each of them.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Choose the Cryptographic Algorithm Policy, Key Management Policy, Vendor Crypto Requirements or Migration Timeline Policy template, name the policy owner and approver, and export: the policy names the approved and prohibited algorithms and the review cadence.
- GRC / Risk & Compliance
- Approve ML-KEM and ML-DSA, list the classical algorithms to retire, define the exception process and add KPI drift rules; the Applicable Standards section (NIST, ENISA, ISO/IEC, IETF, FIPS 140-3) ties the policy to its references.
Select a policy type, fill in the template fields, and export a customized PQC policy document. Framework options, jurisdiction, industry, and suggested key rotation are auto-populated from your assessment data when available.
Editing: Cryptographic Algorithm Policy
Approved algorithms · Prohibited algorithms · Exception process
General Information
Organization, jurisdiction, and policy metadata.
Approved Algorithms
Algorithms approved for use in production systems.
Prohibited Algorithms
Algorithms disallowed for new deployments. Existing uses must be migrated according to the timeline policy.
Exception Process
KPI Drift Rules (CSWP.39 §5.4 → §5.1 feedback loop)
Define which KPI exceptions should trigger updates to this policy template — turning observed drift into policy-as-code feedback. Educational only — these rows export with the policy.
No drift rules defined.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Approve ML-KEM and ML-DSA, list RSA as an algorithm to retire and set a 2-year exception window. What does the export contain?
Next step
Next in Governance & Policy: KPI Dashboard BuilderKPI Dashboard Builder is the next Governance & Policy tool in the Command Center.