Governance & Policy / Policy Template Generator

What this is for: Generate cryptographic algorithm, key management, vendor, and migration policies.

What a good answer looks like: A policy someone can be non-compliant with. If no realistic action would breach it, it is a statement of values, not a policy.

Worked example: Approve ML-KEM (FIPS 203) and ML-DSA (FIPS 204), list RSA, ECDSA and ECDH as classical algorithms to retire, allow a 2-year exception window and set an annual review: the generated policy names each of them.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Choose the Cryptographic Algorithm Policy, Key Management Policy, Vendor Crypto Requirements or Migration Timeline Policy template, name the policy owner and approver, and export: the policy names the approved and prohibited algorithms and the review cadence.
GRC / Risk & Compliance
Approve ML-KEM and ML-DSA, list the classical algorithms to retire, define the exception process and add KPI drift rules; the Applicable Standards section (NIST, ENISA, ISO/IEC, IETF, FIPS 140-3) ties the policy to its references.

Select a policy type, fill in the template fields, and export a customized PQC policy document. Framework options, jurisdiction, industry, and suggested key rotation are auto-populated from your assessment data when available.

Editing: Cryptographic Algorithm Policy

Approved algorithms · Prohibited algorithms · Exception process

4 unfilled placeholders still in this document and will appear in any export: Organization Name, Effective Date, Policy Owner, Approver.

General Information

Organization, jurisdiction, and policy metadata.

Approved Algorithms

Algorithms approved for use in production systems.

Prohibited Algorithms

Algorithms disallowed for new deployments. Existing uses must be migrated according to the timeline policy.

Exception Process

KPI Drift Rules (CSWP.39 §5.4 → §5.1 feedback loop)

Define which KPI exceptions should trigger updates to this policy template — turning observed drift into policy-as-code feedback. Educational only — these rows export with the policy.

No drift rules defined.

Try it

Approve ML-KEM and ML-DSA, list RSA as an algorithm to retire and set a 2-year exception window. What does the export contain?

Next step

Next in Governance & Policy: KPI Dashboard Builder

KPI Dashboard Builder is the next Governance & Policy tool in the Command Center.