KEY CUSTODY TRANSITION REVIEW
Key Custody Transition Review
Key custody is a stack, and a transition that moves one layer while the others stay classical has not moved. The envelope around a key, the channel it crosses, the escrow deposit that holds its backup, the ceremony that refreshes it and the trail that records all of it each age on their own schedule — and the recorded layers age retroactively, because a copy sealed years ago is still a copy. This review walks the stack layer by layer on an estate whose transition has begun, and scores what would actually survive.
AutoPQC · custody rings
- 01 root keysscheduled
- 02 wrapping at restmoved
- 03 distribution channelsscheduled
- 04 escrow and backupclassical
- 05 rotation ceremoniesmoved
- 06 short-lived materialscheduled
- 07 recovery pathsscheduled
- 08 the custody trailclassical
eight rings · ceremony 3-of-5 · the weakest ring sets the score — illustrative
- Duration
- [PLACEHOLDER: engagement duration, Key Custody Transition Review]
- Method
- theos-method-v1.0
- Surface
- The custody stack
- Depth
- Wrap · channel · escrow
- Artefact
- Register + attestation
- Standards
- FIPS 203 · 140-3
The starting point
The key you rotated is not the copy they kept.
A custody transition has a past as well as a future. Every envelope sealed classically, every escrow deposit made years ago, every channel a key ever crossed — those copies exist on someone's schedule now, not yours, and re-sealing what you hold does not reach them. The review walks the stack with both clocks running: what to move next, and what the record already says.
Scope
In scope, and not in scope
In scope
- The envelope inventory: every wrapping in force, by version — which keys sit under post-quantum or hybrid envelopes and which still sit under classical ones.
- Channel establishment for key material in motion: what actually negotiates on every channel a key crosses, service by service.
- Escrow and backup deposits: when each was sealed, under what, and the re-seal schedule that keeps future copies ahead of the past ones.
- Refresh ceremonies: the quorum arithmetic, who holds each share, and whether the migration-without-identity-rotation path has ever been rehearsed.
- Short-lived material: session keys, cached derivations and pre-computed values, with their measured — not intended — lifetimes.
- The custody trail: how ceremony records and access events are signed, and whether those records will still prove anything when read years from now.
Not in scope
- Digital-asset custody, wallet infrastructure and multi-party wallet schemes, which are outside our practice entirely.
- The baseline key-management estate — an estate that has not begun its transition starts with the Key Management Review, not here.
- Operating ceremonies or handling key material on your behalf; we read records and policy, and we will decline an offer of the material itself.
- Vendor selection. Where a layer waits on a vendor's post-quantum support, we cite the Compatibility Reference and record the wait as a dated constraint.
Surfaces
What we look at
01
Envelopes, by version
The wrapping around every stored key and share, with version metadata read as the transition's actual ledger: what has moved, what has not, and what claims to have moved.
02
The channel map
Every channel key material crosses, with what genuinely negotiates on it — because a recorded classical channel is a recorded key, whatever the policy says.
03
Escrow and backup deposits
Each deposit dated and its sealing named. A deposit sealed classically in 2019 is a liability with a date on it, and the review says so.
04
Ceremonies and quorums
The recorded ceremonies: quorum thresholds, share holders, rehearsal history, and whether refresh can migrate the wrapping without rotating what the estate trusts.
05
The custody trail
The signatures on ceremony records and access events, read against the retention their regulator expects of them.
Custody, in depth
The custody stack, layer by layer
A key estate is not one thing — it is a stack, and in most estates every layer of it is classical: the roots, the envelopes around each key, the channels keys travel over, the escrow deposits, the ceremonies, the recovery paths and the trail that records all of it. A review that reads only the top layer certifies the paint. This is the stack the review actually walks, with what is typically classical at each layer today and the transition move planned for it.
01 · Root keys
Typically today
RSA and ECC roots living in managed key services and hardware modules
The transition move
Vendor post-quantum key types adopted as firmware lines ship them — with the wait recorded as a dated constraint, not ignored
02 · Wrapping at rest
Typically today
Data keys and exported material sealed under classical envelope encryption
The transition move
Hybrid re-wrap under ML-KEM-768, with envelope-version metadata so old and new wrapping coexist during the changeover
03 · Distribution channels
Typically today
Key material crossing service boundaries over classically-established channels
The transition move
Hybrid establishment on every channel a key crosses, because a recorded channel is a recorded key
04 · Escrow and backup
Typically today
Split-knowledge backups and escrow deposits sealed once and kept for years
The transition move
Re-seal on a schedule — a recorded escrow deposit is harvestable in exactly the way recorded traffic is
05 · Rotation ceremonies
Typically today
Quorum ceremonies that re-establish custody without changing what the estate trusts
The transition move
A rehearsed refresh path that migrates the wrapping without rotating public identity — proven before it is needed
06 · Short-lived material
Typically today
Session keys, cached derivations and pre-computed material outliving their purpose on disk
The transition move
Volatile-memory discipline with measured lifetimes, so nothing short-lived persists long enough to be worth harvesting
07 · Recovery paths
Typically today
Administrator break-glass over hardware tokens and classical attestations
The transition move
Hybrid attestation on recovery, because the emergency door must be as durable as the front one
08 · The custody trail
Typically today
Ceremony records and access events signed classically and retained for the regulator
The transition move
Dual-signing on records that will still be read long after the classical signature stops proving anything
Ceremony quorum · 3-of-5 · illustrative
Ceremony arithmetic — illustrative. The review reads who holds each share, where the threshold sits, and whether the refresh ceremony has ever actually been run.
Where a layer depends on a vendor's post-quantum support, the vendor's published posture lives in the Compatibility Reference — the review cites it rather than restating it.
Scoring
How it is scored
Findings are scored under the published Theos Method across its five dimensions — Primitive Fragility, Confidentiality Horizon, Reachability, Change Cost and Substitution Gap — with weights and tiers stated in full at /methodology. Recorded layers score against their Confidentiality Horizon in particular: an exposed copy that already exists cannot be un-recorded, and the score reflects that honestly.
Read the method specificationDeliverables
What you receive
01
Primary artefact
Custody-stack register
CSV + PDF
Every layer, every envelope version, every channel and every deposit, dated and scored — the transition's ledger in one document.
02
Re-wrap plan
Ordered plan + envelope versioning
The sequence that moves remaining classical envelopes to hybrid wrapping, with version metadata so old and new coexist during the changeover.
03
Channel upgrade map
Findings + per-channel plan
Which channels need hybrid establishment before key material crosses them again, in dependency order.
04
Escrow re-seal schedule
Dated schedule
Every deposit with its re-seal date, and a plain statement of which past copies remain exposed regardless.
05
Ceremony rehearsal findings
Written findings
What the recorded ceremonies show, what the refresh path can and cannot migrate, and what has never been rehearsed.
06
Layer score and Posture Attestation
Signed attestation
The custody layer scored under the method version named on the document, verifiable through the Attestation Lookup.
Evidence
Evidence and reproducibility
Every finding names the layer, the asset, the date and the record it was read from, and the register's scores recompute under the published method from the register's own fields. See /knowledge/reproducing-our-numbers for the standing commitment.
Reproducing our numbersThe standards floor
What the work stands on
Eight standards, runtime and custody lines sit underneath every engagement in the catalogue. Each card names the groundwork the estate needs for it to land, and the failure mode it retires.
FIPS 203
ML-KEM — key establishment
The module-lattice key-encapsulation standard. It replaces classical key exchange in TLS 1.3 handshakes, tunnel establishment and key wrapping — the surfaces where traffic captured today can be stored against a future decryption.
- Groundwork
- A runtime line that can load a post-quantum provider, stated per service rather than assumed estate-wide.
- Risk retired
- Sessions recorded now being opened later, once the classical exchange underneath them falls.
FIPS 204
ML-DSA — digital signatures
The module-lattice signature standard, the replacement path for RSA and ECDSA signing across code, documents and server authentication. During a transition it runs alongside the classical signature rather than instead of it.
- Groundwork
- A signing pipeline that can carry two signatures on one artefact for the length of the transition window.
- Risk retired
- A forged release or a forged server identity signed by an algorithm that no longer resists forgery.
FIPS 205
SLH-DSA — hash-based signatures
The stateless hash-based signature standard: the conservative member of the family, resting on hash-function assumptions alone. Its natural home is firmware and other signatures that must still verify decades from now.
- Groundwork
- Room in the artefact path for a larger signature than the lattice schemes produce.
- Risk retired
- A structural surprise in lattice mathematics taking both primary schemes down at once.
Policy
CNSA 2.0 — the dated timeline
The published NSA algorithm suite sets dates, not suggestions: post-quantum operational across national-security systems by 2030, exclusive by 2035. Even estates far from that perimeter inherit its dates through their suppliers.
- Groundwork
- A register the timeline can be laid against, asset by asset, rather than a single estate-wide guess.
- Risk retired
- Discovering a contractual algorithm deadline in a procurement questionnaire instead of in your own plan.
Transition
Hybrid establishment — classical + ML-KEM
The transition posture for key establishment: derive the session from a classical curve and ML-KEM together, so a flaw in either primitive alone leaves the session standing. Mainstream clients already advertise the combined group.
- Groundwork
- TLS 1.3 endpoints, and visibility into which peers negotiate the hybrid group and which quietly do not.
- Risk retired
- Betting the confidentiality of day-one traffic on a single primitive, new or old.
Runtime
The provider-capable runtime line
Post-quantum negotiation arrives through the runtime, and an estate pinned to older lines does not negotiate it. The version actually loaded per service is a finding in its own right, not a build-system detail.
- Groundwork
- Retiring the oldest runtime pins — or naming them in the register as accepted, dated exceptions.
- Risk retired
- One service negotiating hybrid while its neighbour, one pin behind, silently falls back to classical.
Tooling
Open post-quantum tooling, pinned
The open-source implementations the ecosystem tests against. Where they appear in an estate we record the exact build, because a reviewed library and a deployed library are only the same thing if their hashes say so.
- Groundwork
- A pinned build with its hash recorded in the register, not a floating dependency.
- Risk retired
- Drift between the implementation that was reviewed and the one that ships the following quarter.
Custody
KMS and HSM key custody
Where the keys actually live. Managed key services and hardware modules are adding post-quantum key types on their own schedules, and custody boundaries — who can wrap, rotate, restore — decide how a migration lands there.
- Groundwork
- Audit access to key inventories and rotation policy. Key material itself never crosses the boundary.
- Risk retired
- A replica, backup or recovery region migrating out of step with the primary it must mirror.
Inputs
Inputs and duration
- Duration
- [PLACEHOLDER: engagement duration, Key Custody Transition Review]
- Access
- Read access to key inventories, envelope metadata, ceremony records and escrow registers. Key material itself never crosses the boundary, and we will decline it.
- Prerequisite
- A custody transition already underway — at least one layer moved or scheduled. Estates starting cold begin with the Key Management Review.
- Output
- The custody-stack register, the re-seal schedule, ceremony findings, and a Posture Attestation for the layer.
Questions
Questions we are asked
- Do you ever handle our keys
- No, and the review is designed so we never need to. Envelope versions, ceremony records, channel negotiation and deposit dates are all readable as metadata. An offer of key material is declined and noted.
- Our old escrow deposits were sealed classically — can this fix them
- No, and we will not pretend otherwise. Re-sealing protects the copy you hold going forward; any copy recorded by someone else while the old sealing stood remains exposed forever. The review dates that exposure and puts it in the register, because a liability with a date on it can at least be managed.
- Is this the Key Management Review under another name
- No. That review establishes the custody baseline — what exists, where it lives, how it rotates. This one assumes the transition has started and goes to full depth on the transition itself: envelope versions, re-seal schedules, refresh rehearsals and the order the remaining layers should move in.
- What this engagement will not tell you
- It will not tell you whether a key has already been misused — that is forensics. It will not select a custody vendor for you, and it cannot make a recorded past copy safe. Where the honest answer is that a layer's history is unrecoverable, the register says exactly that.
- Our custody vendor says post-quantum support is coming
- Then the wait is a dated constraint, and it goes in the register as one. The vendor's published posture is cited from the Compatibility Reference rather than restated, and the layers that do not depend on the vendor move while the one that does waits visibly.
Signed · Verifiable
Every engagement in the catalogue ends with a Posture Attestation you can verify.
The attestation names the scope, the method version and the date, and anyone holding its code can check it on this site.
Related reading
Three articles that go further
The scope conversation
Take Key Custody Transition Review to a scope conversation
Tell us the estate you have in mind and we will walk through what this engagement would cover, what it would produce, and where its boundary sits — before anything is signed. If you would rather put questions in writing first, write to us instead.