
BSI Crypto Guidelines 2026: New Cryptography Recommendations
New Guidance for PQC Migration and Certificate Management
The German Federal Office for Information Security (BSI) has published version 2026-01 of Technical Guideline BSI TR-02102-1, “„Cryptographic Mechanisms: Recommendations and Key Lengths“. The guideline provides recommendations on cryptographic mechanisms, key lengths and migration paths for new cryptographic systems from 2026 onwards.
Migration Paths for Post-Quantum Cryptography
One focus of the current version is post-quantum cryptography. The BSI defines migration periods for quantum-safe mechanisms and describes the exclusive use of classical asymmetric mechanisms as a model that will be phased out over time. According to the guideline, classical key agreement mechanisms should only be used on their own until the end of 2031. For applications with very high protection requirements, the BSI recommends migrating to quantum-safe mechanisms by the end of 2030.
Classical signature mechanisms will also need to be replaced in the long term. According to the BSI’s current assessment, they remain trustworthy as long as no cryptographically relevant quantum computer is available. At the same time, the guideline follows the European roadmap, which calls for migration to quantum-safe signature mechanisms by 2035 at the latest.
Certificate Management as an Operational Foundation
For organisations, this development is particularly relevant in the context of PKI and certificate management. Digital certificates provide the basis for the authentic distribution of public keys. They secure identities, systems, services and chains of trust. When cryptographic mechanisms change, certificates, certificate chains, root and intermediate CAs, validity periods, policies and technical dependencies are affected as well.
The BSI guideline also refers to specific requirements for public key infrastructures. These include proof of possession of private keys when certificates are issued, options for timely certificate deactivation, limited certificate validity periods, trustworthy issuers, clearly defined certificate usage and limited certificate chain lengths.
This makes crypto-agility an operational task. Organisations need to understand which certificates are in use, which algorithms and key lengths are being used, which systems depend on specific mechanisms and where adjustments will be required. Without transparency across their cryptographic infrastructure, migration paths towards post-quantum cryptography are difficult to plan reliably.
We will revisit this topic soon in a more detailed analysis. In that article, we will look at what the BSI Crypto Guidelines 2026 mean for certificate management, PKI and crypto-agility, and how essendi crypto solutions can help organisations create transparency across cryptographic mechanisms and prepare for the migration to quantum-safe infrastructures.

