Boundary of the claim
CALI is informed by NIST crypto-agility guidance. It is not a NIST publication, reference architecture, standard or endorsed implementation. Alignment means the research addresses related operational concerns; it does not establish conformance.
Guidance-to-contract mapping
| NIST crypto-agility theme | CALI research response |
|---|---|
| Cryptography spans applications and infrastructure | Consumer, broker, policy, provider, key and CA boundaries are separated |
| Transitions require inventory and dependency understanding | Discovery records are scoped and migration examples identify signers, verifiers, protocols and providers |
| Algorithms and implementations change over time | Versioned profiles and explicit TransformKey/MigrateKey operations model change |
| Governance matters | Policy authority is distinct from broker enforcement and provider execution |
| Interoperability and continuity must be preserved | Overlap windows are explicit and silent fallback is forbidden |
What CALI adds as a proposal
NIST guidance is not an API specification. CALI proposes request envelopes, policy pinning, operation contracts, error categories, evidence and provider-adapter behavior. Those are CALI design choices and remain subject to review and implementation evidence.
Primary reference
See NIST, Considerations for Achieving Crypto Agility: Strategies and Practices and verify the current revision before relying on dates or recommendations.