Policy & principles
Define scope, mandatory outcomes, risk expectations and accountability.
Turn cryptographic risk into accountable decisions, enforceable expectations and managed change.
Governance connects technical standards with risk appetite, ownership, exceptions, lifecycle decisions and evidence so cryptographic risk can be managed consistently across the organisation.
Last reviewed: August 2026
Modern cryptography can still be poorly governed when ownership is unclear, standards are inconsistent, exceptions persist indefinitely or teams cannot respond when requirements change.
Governance establishes what is permitted, who is accountable, how deviations are assessed, how transition is prioritised and what evidence leadership needs to understand material exposure.
Governance does not mean centralising every technical choice. It means knowing which decisions require control, who can make them, what evidence supports them and when they must be revisited.
Define scope, mandatory outcomes, risk expectations and accountability.
Maintain approved and restricted algorithms, protocols, key strengths, certificate and key-management requirements.
Clarify responsibilities across security, architecture, engineering, PKI, IAM, risk, procurement, suppliers and business owners.
Require rationale, compensating controls, accountable acceptance, remediation and expiry for deviations.
Govern cryptography from design and procurement through operation, transition and retirement.
Use evidence and risk reporting to determine whether expectations are operating effectively.
Scope, principles, accountability and mandatory organisational outcomes.
Approved or prohibited algorithms, protocols, strengths and lifecycle requirements.
How teams implement requirements in specific technologies and processes.
How temporary deviations are assessed, approved, monitored and remediated.
Exception principle
An exception is a time-bounded risk decision with an owner and treatment path — not a permanent workaround.
Algorithms and standards will continue to change. Crypto-agility provides the ability to change; governance provides the authority, priorities and evidence that make change consistent.
Together they turn migration from an emergency project into a repeatable organisational capability.
Educational synthesis. Governance should be adapted to legal, regulatory, risk and technology context.