Skip to content

Add external catalog traceability to cryptographic algorithm approval - #53

Merged
3keyroman merged 1 commit into
pkic:mainfrom
3keyroman:crypto-external-catalog-references
Sep 25, 2026
Merged

3keyroman merged 1 commit into
pkic:mainfrom
3keyroman:crypto-external-catalog-references

Conversation

@3keyroman

@3keyroman 3keyroman commented Aug 26, 2026 •

Copy link
Copy Markdown
Collaborator

Approved cryptographic algorithms are not always freely chosen. Where an organization operates under a regulatory regime or trust scheme, the approval set is bounded by an external cryptographic catalog. The crypto-algorithms requirement did not reflect that, and the catalog entries describing those external catalogs were not cited from the Cryptography category.

Changes

  • Add guidance to crypto-algorithms stating that where a regulatory regime or trust scheme mandates a cryptographic catalog, approved algorithms and parameters should be traceable to that catalog rather than determined independently, and that the applicable catalog should be identified. Add the matching assessment cue.
  • Add etsi-119-312 (ETSI TS 119 312 - Cryptographic Suites) and eccg-acm (ECCG Agreed Cryptographic Mechanisms) to the shared references catalog.
  • Cite etsi-119-312, eccg-acm, eucc-crypto-guidelines and cnsa-2-0 from crypto-algorithms, which previously cited only nist-sp-800-131a.
  • Cite etsi-119-312 from crypto-lifecycle, whose deprecation rules follow the same catalog.
  • Mark sogis-crypto as deprecated with supersededBy: eccg-acm. SOG-IS ceased issuing certificates on 27 February 2026 and the ECCG ACM, maintained under the EUCC scheme, is its successor.
  • Rename eucc-crypto-inventory to eucc-crypto-guidelines and correct its title to EUCC Guidelines on Cryptography. The document covers cryptographic mechanism approval and contains no inventory guidance, so it is cited from crypto-algorithms rather than crypto-visibility.
  • Regenerate categories/cryptography/_index.md and model/references/_index.md from the model YAML.
  • Update the requirement row in the 2.0.0 release notes.
  • Ignore local coverage output.

The guidance names no specific standard, keeping requirement text technology- and framework-neutral. The concrete catalogs are carried by the references, where the regions metadata expresses jurisdictional scope.

Reference URLs for ETSI TS 119 312 and the ECCG ACM point at the publisher landing page rather than a pinned revision, so they remain valid as new versions are published.

Resolves #49

Add ETSI TS 119 312 and the ECCG Agreed Cryptographic Mechanisms to the shared
references catalog and cite them, together with CNSA 2.0, from the algorithm
approval requirement.

Note in guidance that where a regulatory regime or trust scheme mandates a
cryptographic catalog, approved algorithms and parameters should be traceable
to it, and add the matching assessment cue. Cite ETSI TS 119 312 from the
cryptographic lifecycle requirement, whose deprecation rules follow the same
catalog.

Mark the SOG-IS agreed cryptographic mechanisms as deprecated and superseded by
the ECCG ACM, which is maintained under the EUCC scheme.

Rename eucc-crypto-inventory to eucc-crypto-guidelines and correct its title.
The document covers cryptographic mechanism approval rather than inventory, so
cite it from the algorithm approval requirement instead of cryptographic
visibility.

Ignore local coverage output.
@3keyroman
3keyroman force-pushed the crypto-external-catalog-references branch from 8b71085 to a97bdb5 Compare September 25, 2026 05:58
@3keyroman
3keyroman merged commit 7267387 into pkic:main Sep 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Cryptography category: algorithm approval is externally constrained for regulated TSPs — add ETSI TS 119 312 to the references

1 participant