From policy to practice: a sector-agnostic operational framework for post-quantum cryptography transition
| dc.authorid | 0009-0008-5058-1081 | |
| dc.authorid | 0000-0003-2865-6370 | |
| dc.contributor.author | Birgin, Berat | en_US |
| dc.contributor.author | Çeliktaş, Barış | en_US |
| dc.date.accessioned | 2026-03-27T08:46:53Z | |
| dc.date.available | 2026-03-27T08:46:53Z | |
| dc.date.issued | 2026-03-02 | |
| dc.department | Işık Üniversitesi, Lisansüstü Eğitim Enstitüsü, Siber Güvenlik Yüksek Lisans Programı | en_US |
| dc.department | Işık University, School of Graduate Studies, Master’s Program in Cybersecurity | en_US |
| dc.department | Işık Üniversitesi, Mühendislik ve Doğa Bilimleri Fakültesi, Bilgisayar Mühendisliği Bölümü | en_US |
| dc.department | Işık University, Faculty of Engineering and Natural Sciences, Department of Computer Engineering | en_US |
| dc.description.abstract | The pace of quantum computing development necessitates not only the adoption of post-quantum cryptographic algorithms, but also the establishment of an executable and auditable institutional transition process. Although guidance documents published by the National Institute of Standards and Technology (NIST) and roadmaps proposed by the Post-Quantum Cryptography Coalition (PQCC) articulate strategic objectives, they largely remain procedural constructs lacking a concrete operational execution model. This paper presents an industry-neutral operational framework that translates policy-level post-quantum cryptography (PQC) guidance into deterministic, proof-producing process flows encompassing cryptographic asset discovery, classification, risk modeling, algorithm selection, deployment, monitoring, and governance enforcement. Central to the framework is a deterministic Quantum Risk Scoring (QRS) function, calibrated using the Analytical Hierarchy Process (AHP), which enables reproducible asset prioritization and policy-driven enforcement decisions. Framework executability is further strengthened through cryptography-aware continuous integration/continuous deployment (CI/CD) validation gates and downgrade protection mechanisms, ensuring the generation of verifiable and immutable audit artifacts. A scenario-based operational validation, implemented using open-source toolchains, demonstrates the framework’s operability, auditability, and governance alignment without relying on empirical cryptographic performance benchmarks, confirming that PQC transition can be operationalized as a verifiable lifecycle process bridging policy guidance with enforceable technical actions. Rather than introducing new cryptographic primitives, this work formalizes PQC transition as an operational systems-engineering problem centered on governance-enforced execution and lifecycle verifiability. | en_US |
| dc.description.version | Publisher's Version | en_US |
| dc.identifier.citation | Birgin, B. & Çeliktaş, B. (2026). From policy to practice: a sector-agnostic operational framework for post-quantum cryptography transition. IEEE Access, 34, 33534-33551. doi:https://doi.org/10.1109/ACCESS.2026.3669437 | en_US |
| dc.identifier.doi | 10.1109/ACCESS.2026.3669437 | |
| dc.identifier.endpage | 33551 | |
| dc.identifier.issn | 2169-3536 | |
| dc.identifier.scopus | 2-s2.0-105032153600 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.startpage | 33534 | |
| dc.identifier.uri | https://hdl.handle.net/11729/7185 | |
| dc.identifier.uri | https://doi.org/10.1109/ACCESS.2026.3669437 | |
| dc.identifier.volume | 14 | |
| dc.identifier.wos | WOS:001708162800019 | |
| dc.identifier.wosquality | Q2 | |
| dc.indekslendigikaynak | Scopus | en_US |
| dc.indekslendigikaynak | Web of Science | en_US |
| dc.indekslendigikaynak | Science Citation Index Expanded (SCI-EXPANDED) | en_US |
| dc.institutionauthor | Birgin, Berat | en_US |
| dc.institutionauthor | Çeliktaş, Barış | en_US |
| dc.institutionauthorid | 0009-0008-5058-1081 | |
| dc.institutionauthorid | 0000-0003-2865-6370 | |
| dc.language.iso | en | en_US |
| dc.peerreviewed | Yes | en_US |
| dc.publicationstatus | Published | en_US |
| dc.publisher | Institute of Electrical and Electronics Engineers Inc. | en_US |
| dc.relation.ispartof | IEEE Access | en_US |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Öğrenci | en_US |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | en_US |
| dc.rights | info:eu-repo/semantics/openAccess | en_US |
| dc.subject | Analytic hierarchy process (AHP) | en_US |
| dc.subject | Cryptographic transition framework | en_US |
| dc.subject | Governance feedback loop | en_US |
| dc.subject | Post-quantum cryptography (PQC) | en_US |
| dc.subject | Quantum risk scoring (QRS) | en_US |
| dc.subject | Scenario-based validation | en_US |
| dc.subject | Analytic hierarchy process | en_US |
| dc.subject | Benchmarking | en_US |
| dc.subject | Life cycle | en_US |
| dc.subject | Public key cryptography | en_US |
| dc.subject | Public policy | en_US |
| dc.subject | Quantum computers | en_US |
| dc.subject | Quantum cryptography | en_US |
| dc.subject | Quantum theory | en_US |
| dc.subject | Analytic hierarchy | en_US |
| dc.subject | CryptoGraphics | en_US |
| dc.subject | Feedback loops | en_US |
| dc.subject | Hierarchy process | en_US |
| dc.subject | Post quantum cryptography | en_US |
| dc.subject | Post-quantum cryptography | en_US |
| dc.subject | Quantum risk scoring | en_US |
| dc.subject | Risk scoring | en_US |
| dc.subject | Scenario-based | en_US |
| dc.subject | Hierarchical systems | en_US |
| dc.title | From policy to practice: a sector-agnostic operational framework for post-quantum cryptography transition | en_US |
| dc.type | Article | en_US |
| dspace.entity.type | Publication | en_US |
Dosyalar
Orijinal paket
1 - 1 / 1
Yükleniyor...
- İsim:
- From_policy_to_practice_a_sector_agnostic_operational_framework_for_post_quantum_cryptography_transition.pdf
- Boyut:
- 2.43 MB
- Biçim:
- Adobe Portable Document Format
Lisans paketi
1 - 1 / 1
Küçük Resim Yok
- İsim:
- license.txt
- Boyut:
- 1.17 KB
- Biçim:
- Item-specific license agreed upon to submission
- Açıklama:












