- A first-of-its-kind evaluation of the Crypto Agility Maturity Model (CAMM) reveals ambiguous scope, unoperationalized acceptance criteria, and dependency relation flaws that undermine assessment reliability
- Real-world validation found several higher-level CAMM requirements inapplicable or unclear, meaning organizations relying on CAMM scores may overestimate their post-quantum cryptography readiness
- Security teams should pause CAMM-based assessments and adopt supplementary validation steps until the model’s structural deficiencies are resolved
Your PQC Readiness Score May Be Wrong
Picture this: your organization just completed a crypto-agility assessment using the Crypto Agility Maturity Model. The results look encouraging — you score well on several maturity levels, your board receives a reassuring briefing, and your PQC migration timeline extends comfortably into 2028. There is one problem. The framework that produced that score contains structural deficiencies that make its outputs unreliable.
Researchers published the first independent evaluation of the CAMM in April 2026 (arXiv:2604.12428v1), testing it against established design principles for maturity models and validating it against a real-world scenario. Their findings should concern every CISO who has referenced CAMM outputs in a migration plan.
Cryptographic agility — the capacity of a system to transition between cryptographic algorithms without requiring fundamental architectural changes — is the single most important capability organizations need for the post-quantum transition. A maturity model that measures this capability inaccurately does not just produce bad reports. It produces false confidence at the exact moment when accurate self-assessment matters most.
What the CAMM Is — and What It Claims to Measure
The Crypto Agility Maturity Model, developed by Hohm et al., provides a structured framework for organizations to evaluate how prepared their cryptographic infrastructure is to adopt new algorithms — specifically the NIST post-quantum standards such as ML-KEM, ML-DSA, and SLH-DSA. Like other maturity models (think CMMI or NIST CSF tiers), CAMM defines progressive maturity levels, each with specific requirements that organizations must satisfy to advance.
The promise is straightforward: assess where you are, identify gaps, and build a roadmap to full crypto agility. The model targets organizations navigating the PQC transition, offering acceptance criteria at each level that theoretically allow objective, repeatable measurement.
That theoretical repeatability is exactly what the April 2026 evaluation calls into question.
Inside the Evaluation: Three Structural Failures
The researchers behind arXiv:2604.12428v1 conducted what they describe as the first evaluation of the CAMM against established design principles for maturity models. Their methodology combined principle-based analysis with practical validation using a real-world scenario. The results expose three distinct categories of structural failure.
[IMAGE: A fractured maturity model pyramid with cryptographic symbols falling through the cracks, rendered in dark tones with cyan highlights against a black background]
Ambiguous Scope and Target Groups
The CAMM does not clearly define who it is for or what it measures. The evaluation found that scope boundaries and target group definitions remain ambiguous, which means two assessors evaluating the same organization could reasonably interpret the model’s applicability differently.
For a maturity model, scope ambiguity is not a minor documentation gap — it is a validity defect. If assessors cannot agree on what falls within the model’s boundaries, the resulting scores are not comparable across organizations, across time, or even across assessment teams within the same organization.
“Our analysis reveals that the CAMM only partially satisfies these principles: its scope and target groups remain ambiguous; acceptance criteria are insufficiently operationalized, limiting verifiability and replicability; and dependency relations exhibit redundancies, cycles, and omissions.” — Authors of arXiv:2604.12428v1
Unoperationalized Acceptance Criteria
Each maturity level in CAMM defines acceptance criteria — the conditions an organization must meet to claim that level. The evaluation found these criteria insufficiently operationalized. In plain terms: the criteria lack the specificity needed for different assessors to consistently determine whether a requirement is met.
This directly limits verifiability (can a third party confirm the assessment?) and replicability (would a different team reach the same conclusion?). Both properties are non-negotiable for any assessment framework used in compliance reporting, board-level risk communication, or vendor evaluation.
Dependency Relation Defects
Maturity models build upward — higher levels depend on lower ones. CAMM’s dependency relations between requirements contain three types of defects:
| Defect Type | What It Means | Risk to Assessments |
|---|---|---|
| Redundancies | Multiple requirements overlap, measuring the same capability twice | Inflated scores; wasted assessment effort |
| Cycles | Requirement A depends on B, which depends on A | Logical impossibility; no valid assessment path |
| Omissions | Missing dependency links between related requirements | Organizations can claim higher maturity while skipping foundational capabilities |
Cyclic dependencies are particularly damaging. If requirement A requires B and B requires A, no organization can satisfy either without violating the model’s own logic. This is not an edge case — it is a structural defect that renders portions of the assessment framework unusable.
Real-World Validation Confirms the Theory
The researchers did not stop at theoretical analysis. They applied CAMM to a real-world scenario and found that several requirements at higher maturity levels proved inapplicable or unclear in practice. Requirements that appear coherent in a specification document failed when applied to actual organizational infrastructure.
This gap between specification and application is the most operationally relevant finding. Organizations do not assess their crypto agility in the abstract — they assess it against their specific TLS configurations, key management systems, certificate authorities, hardware security modules, and application architectures. A model that breaks down at the point of application provides theoretical structure without practical value.
The disconnect between CAMM’s specification-level coherence and its real-world applicability means organizations may complete assessments that feel rigorous but produce unreliable maturity scores — the worst possible outcome for PQC migration planning.
How This Compares to What CISOs Need
The PQC transition is not a distant concern. NIST finalized its first post-quantum standards in 2024, and federal agencies face mandated migration timelines. Private-sector organizations handling sensitive data face the harvest-now-decrypt-later threat today, meaning adversaries are already collecting encrypted traffic to decrypt once quantum computers reach sufficient capability.
In this environment, CISOs need crypto-agility assessment frameworks that deliver three things:
| Requirement | What CISOs Need | What CAMM Currently Delivers |
|---|---|---|
| Clear scope | Unambiguous boundaries — what systems, what algorithms, what organizational functions | Ambiguous scope and target group definitions |
| Measurable criteria | Binary or scaled criteria that different assessors score consistently | Insufficiently operationalized acceptance criteria |
| Sound dependency logic | Clear prerequisite chains showing what must be done before what | Relations containing redundancies, cycles, and omissions |
| Real-world applicability | Requirements that map to actual infrastructure components | Several higher-level requirements inapplicable in practice |
The gap between what is needed and what CAMM provides is not a matter of minor refinement. The structural deficiencies identified — scope ambiguity, unoperationalized criteria, and dependency defects — require substantive model revision.
Industry Timeline Pressure Makes This Urgent
The stakes of inaccurate crypto-agility assessment compound over time:
Near-term (1-2 years): Organizations using CAMM outputs to justify migration timelines or allocate budgets may make decisions based on unreliable data. A maturity score that overstates readiness could delay critical algorithm transitions or misallocate engineering resources.
Medium-term (3-5 years): As the PQC transition accelerates, regulators and auditors will demand standardized assessment evidence. If CAMM deficiencies are not addressed, the industry risks inconsistent crypto-agility assessments across organizations, creating uneven migration readiness. Supply chain partners with incompatible maturity measurements cannot coordinate transitions effectively.
Long-term (5+ years): Post-quantum cryptography is not the last cryptographic transition. Standardized, validated maturity models become permanent infrastructure for continuous cryptographic modernization. Building that infrastructure on a flawed foundation guarantees repeated migration failures as new algorithms and threats emerge.
The BeQuantum Perspective: Assessment Without the Ambiguity
BeQuantum’s approach to cryptographic transition sidesteps CAMM’s structural weaknesses by design. Rather than relying on abstract maturity scoring, BeQuantum’s PQC Layer and Digital Notary operate on verifiable cryptographic state — the actual algorithms, key lengths, and protocol versions running in production, not self-reported maturity levels.
Where CAMM asks “does your organization have a process for algorithm transition?” — a question whose answer depends on how “process” and “transition” are interpreted — BeQuantum’s verification infrastructure asks “what algorithm is this certificate chain using right now, and can it be validated against a quantum-resistant signature?” The answer is binary and machine-verifiable.
This is not about replacing maturity models entirely. Organizations still benefit from strategic roadmapping tools. But the assessment layer that informs migration decisions must produce deterministic, auditable outputs. BeQuantum’s IceCase hardware provides tamper-evident cryptographic anchoring that gives migration teams ground truth about their current state — the prerequisite for any meaningful readiness measurement.
What You Should Do Next
Within 30 days: Audit any existing crypto-agility assessments your organization has completed using CAMM. Identify which findings informed active migration plans or budget decisions. Flag any maturity scores at higher levels (where the evaluation found requirements inapplicable) for re-evaluation.
Within 90 days: Supplement CAMM-based assessments with direct infrastructure inventory. Map every cryptographic algorithm in use across TLS configurations, code-signing certificates, VPN tunnels, API authentication, and data-at-rest encryption. This inventory provides the ground truth that abstract maturity scoring cannot.
Within 180 days: Establish a crypto-agility validation process that does not depend on a single maturity model. Combine automated cryptographic inventory tools with structured assessment frameworks, and require that any readiness claims trace back to verifiable infrastructure evidence.
Frequently Asked Questions
Q: Should we stop using CAMM entirely? A: Not necessarily. CAMM provides useful conceptual structure for thinking about crypto-agility dimensions. However, the April 2026 evaluation (arXiv:2604.12428v1) demonstrates that its outputs should not be treated as reliable measurements without supplementary validation. Use CAMM as a discussion framework, not as an audit tool, until its structural deficiencies are resolved.
Q: Are there alternative crypto-agility assessment frameworks? A: The evaluation authors note this is the first formal evaluation of CAMM against maturity model design principles, which suggests the broader crypto-agility assessment space lacks rigorously validated alternatives. Organizations should combine multiple approaches: direct cryptographic inventory, NIST PQC migration guidance, and structured risk assessment rather than relying on any single model.
Q: How does this affect our PQC migration timeline? A: If your timeline was informed by CAMM maturity scores, particularly at higher levels, the evaluation’s finding that several higher-level requirements proved inapplicable in practice means your actual readiness may differ from your assessed readiness. Re-validate timeline assumptions against direct infrastructure evidence before your next planning cycle.
Last updated: April 2026. Based on the evaluation published as arXiv:2604.12428v1.