Post-quantum planning is often described as a migration exercise: inventory vulnerable cryptography, prioritise systems, deploy approved alternatives and retire exposed algorithms. That work is urgent and technically demanding. It is also only one layer of the problem.

Institutions do not depend on cryptography in the abstract. They depend on identities, devices, approvals, records, supply chains and physical operations whose legitimacy is represented through cryptographic systems. When the trust mechanism changes, the institution must preserve more than secrecy. It must preserve continuity of authority.

A secure replacement algorithm does not automatically prove that the person, object or instruction attached to it is legitimate.

Migration happens inside a living system

Critical infrastructure cannot be paused while every credential, embedded device and inter-organisational dependency is replaced. Old and new mechanisms will coexist. Long-lived assets will remain in the field. Archived data may need to be trusted years after its original protection has weakened. Attackers can collect encrypted material now and exploit it later.

The transition therefore creates mixed-assurance environments. A mathematically strong component may rely on an inherited enrolment process. A new signature may be attached to an old identity record. A valid software update may reach a physical device whose provenance is uncertain.

Identity continuity is the hidden challenge

Cryptographic agility answers: can the system replace one technical primitive with another? Identity continuity asks: can the organisation still establish who or what is entitled to receive the new primitive?

That question becomes difficult when the digital evidence used for reenrolment was itself created under an older trust regime. If every proof of identity refers only to another digital record, migration can reproduce historic uncertainty inside the new architecture.

A stronger transition process connects digital renewal to an independently observable reference: a verified person, an authentic device, a controlled facility, a physical asset or a governed ceremony. The purpose is not nostalgia for analogue processes. It is to avoid allowing a compromised layer to certify its own replacement.

Systems must fail with boundaries

Post-quantum resilience should also consider how authority behaves during uncertainty. If a credential cannot be validated, does the system fail open, fail closed or move into a constrained mode? Can local operations continue safely when central trust services are unavailable? Which actions require fresh verification, and which can rely on recorded context?

These are policy and architecture questions. They must be answered before an incident, because an emergency is the worst moment to discover that technical validation and operational legitimacy were treated as the same thing.

Physical trust as a continuity layer

A physical trust layer can provide an additional reference across cryptographic generations. It does not replace post-quantum cryptography. It helps bind renewed digital authority to people, objects and events outside the credential being renewed.

Used carefully, that separation can support reenrolment, high-assurance recovery, authentic component verification and controlled operation during migration. It also creates a policy point at which an institution can require stronger evidence for more consequential actions.

The strategic view

Post-quantum programmes should measure success not only by the percentage of algorithms replaced, but by whether the institution can continue to distinguish legitimate authority from technically valid appearance.

The core questions are practical:

What remains trusted during migration? How is that trust established? What happens when validation is uncertain? How does a digital identity reconnect to physical reality?

Quantum computing changes the assumptions beneath cryptography. The durable response is to design systems whose legitimacy does not depend on one assumption alone.

This field note is a strategic systems perspective and does not constitute cryptographic, legal or security advice for a specific deployment.