Policy & principles
Set organisational expectations for cryptographic protection, risk ownership, compliance, lifecycle management and transition.
Turn cryptographic risk into accountable decisions, enforceable expectations and managed change.
Cryptography governance defines how an organisation directs, controls and oversees the use of cryptography. It connects technical standards with risk appetite, ownership, exceptions, lifecycle decisions and evidence — so cryptographic risk is managed as part of the wider cybersecurity and enterprise risk model.
Last reviewed: August 2026
An organisation can use modern cryptography and still carry significant risk if ownership is unclear, standards are inconsistent, exceptions are unmanaged, keys and certificates lack lifecycle controls, or teams cannot respond when requirements change.
Governance creates the decision framework around cryptography: what is permitted, who is accountable, how deviations are assessed, how change is prioritised and how leadership gains confidence that material exposure is understood.
Cryptographic governance is not about centralising every technical decision. It is about making sure the organisation knows which decisions require control, who can make them, what evidence supports them and when they must be revisited.
The exact operating model will vary, but effective cryptography governance usually needs several connected capabilities.
Set organisational expectations for cryptographic protection, risk ownership, compliance, lifecycle management and transition.
Define approved and restricted algorithms, protocols, key strengths, certificate practices, key-management expectations and implementation baselines.
Clarify responsibilities across security, architecture, PKI, IAM, engineering, infrastructure, risk, procurement, business owners and suppliers.
Provide a controlled route for deviations: documented rationale, exposure, compensating controls, accountable risk acceptance, expiry and remediation.
Govern cryptography from design and procurement through operation, renewal, algorithm transition, decommissioning and secure key destruction.
Translate deprecation, vulnerabilities, standards changes and PQC requirements into prioritised, owned and measurable transformation plans.
Set expectations for vendor cryptography, transparency, supportability, transition capability, contractual obligations and remediation timelines.
Use evidence, metrics, testing and risk reporting to determine whether governance expectations are operating effectively.
A useful governance structure avoids putting every algorithm choice into a high-level policy. Requirements can be layered so they remain maintainable as technology changes.
Why cryptography is governed, scope, principles, accountability, risk expectations and mandatory organisational outcomes.
Approved or prohibited algorithms, protocols, key strengths, certificate requirements, key-management controls and transition rules.
How teams implement requirements in specific platforms, services, development patterns and lifecycle processes.
How temporary deviations are assessed, approved, monitored, time-bounded and ultimately remediated.
Role names and organisational placement differ. The important outcome is explicit accountability and understood decision authority — not a universal RACI template.
“Legacy system cannot support the required cryptographic standard.”
Governance asks: What is exposed? Why can it not comply? What protects it today? Who owns the residual risk? What is the remediation path? When does the decision expire?
Governance becomes credible when policy statements can be connected to evidence. Depending on scope and maturity, useful evidence may include:
Counts can help, but a large inventory or number of completed scans does not itself demonstrate resilience. Metrics should support risk decisions.
Algorithms and standards will continue to change. NIST's crypto-agility work frames agility as the capability to replace and adapt cryptographic algorithms while preserving security and ongoing operations.
Governance provides the policy, accountability, risk decisions and transition mechanisms that allow that technical capability to operate consistently across an organisation.
This page synthesises public guidance through a cryptography risk-governance lens. Organisations should adapt governance to their legal, regulatory, risk and technology context and consult source publications directly for normative or implementation-specific requirements.