Cloud & managed services
KMS, HSM, TLS, identity and certificate capabilities may be provider-controlled.
Outsourcing technology does not outsource cryptographic risk.
Third-party resilience depends on knowing which cryptographic capabilities sit outside direct control, how critical they are, who owns the relationship and whether suppliers can support change when standards evolve.
Last reviewed: August 2026
Cryptography is embedded in SaaS, cloud, managed PKI, identity platforms, libraries, hardware and other supplied technology.
The organisation may not control the algorithm, certificate hierarchy, key-management mechanism, component or migration schedule. Supplier capability and transparency therefore become part of organisational resilience.
KMS, HSM, TLS, identity and certificate capabilities may be provider-controlled.
Customers may have limited visibility into algorithms, keys and migration roadmaps.
Applications inherit capabilities and constraints from software dependencies.
Products constrain supported protocols, algorithms and key types.
External trust services introduce certificate, signing and key-management dependencies.
The real constraint may sit with a supplier's own provider or component.
A supplier dependency becomes material when the organisation lacks sufficient visibility, influence, alternatives or transition capability if cryptography must change.
Post-quantum migration depends on products and external services supporting suitable transition paths.
Early supplier engagement is therefore part of managing the organisation's own readiness.