# The maintenance-path checklist for a re-key

**Worked artifact B · The Operator's Map, GFF 2026 Special · Twin & Machine · 11 September 2026**

Ten numbered items, one per station of the re-key path into a fielded device plus three this manual added: two the path alone would miss, and a date. Each item closes with the source sentence it rests on, quoted as the source prints it. Fill it for one device class, not the fleet. Every unknown is a finding, not a blank.

1. **Ask the vendor for the list.** If the device was procured under a contract that already requires a key-generation document, ask for that document by its contract name first; the Indian model smart-meter contract's "Document detailing security algorithm and security key generation method" is one. Source: CISA, NSA and NIST, "Quantum-Readiness: Migration to Post-Quantum Cryptography," 17 August 2023: "Discovery tools may not be able to identify embedded cryptography used internally within products, hindering discoverability or documentation. Organizations should ask vendors for lists of embedded cryptography within their products." Ministry of Power / REC, model AMISP contract, SBD V4, August 2022, clause 2.7.7 item n: "the AMISP shall provide in the form of a document enough details of such algorithm including the mechanism of security key generation to the Utility."

2. **Read the expiry off the approval listing, and note that an embedded sub-component sets the earliest date.** Source: PCI PTS Program Guide v1.9, June 2020, section 6.5: "For devices that embed other PCI-approved devices and are therefore basing their security on these sub-components (even partially), the expiration date shall be the earliest among all evaluations, including the embedded device itself." Current class dates: PTS POI v5 to 30 April 2027 (bulletin of 11 September 2025); v6 to April 2032 (bulletin of 17 June 2025).

3. **Write the algorithm's status word for 2030 and for 2035, and write DRAFT beside it.** Source: NIST IR 8547, initial public draft, November 2024, tables 3 and 4 ("Deprecated after 2030" / "Disallowed after 2035" at 112 bits; "Disallowed after 2035" at 128 bits and above) and the definitions: "Deprecated means that the algorithm and key length/strength may be used, but there is some security risk." "Disallowed means that the algorithm, key length/strength, parameter set, or scheme is no longer allowed for the stated purpose." The address for a final version returned 404 on 11 September 2026.

4. **Establish whether the change is firmware, hardware, or the unit.** Source: NIST IR 8547 (draft), section 2.2.3: "Hardware modules must be upgraded or redesigned to support PQC algorithms, which often have larger key sizes and different computational requirements. This includes updating firmware or hardware to handle new algorithms and ensuring that the modules can perform quantum-resistant cryptographic operations efficiently while maintaining the high security standards expected of these devices." For the meter class in India the contracted path is over the wire: "It shall be possible to update the firmware of the meters in both Unicast (one to one) and in Multicast fashion (Group of meters)" and "Security patch management of all applications shall be encrypted and signed" (model AMISP contract, SBD V4).

5. **Book the outage weeks ahead.** Source: NIST SP 800-82 Rev. 3, September 2023: "OT outages must often be planned and scheduled days or weeks in advance." And: "Components can be isolated, remote, and require extensive physical effort to gain access to them."

6. **Count the technicians and the units in stock before you count the sites.** Source: PCI Security Standards Council, bulletin of 11 September 2025: "widespread ecosystem challenges, such as limited technician availability, constrained hardware supply, and complex upgrade timelines, particularly in embedded, unattended, and multi-component environments." RBI/2017-18/206, 21 June 2018: "As the implementation of the foregoing control measures would also require field visit(s) to the ATMs, banks should plan and implement these measures in an optimal manner."

7. **Before you migrate the key material, confirm whether the migration can be reversed.** If the vendor says one-way, keep the old files under stricter read access until every dependent is moved. Source: CISA ICSA-26-253-01 (10 September 2026), republishing AVEVA-2026-006 (8 September 2026): "Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys." "For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files." The record is a software product with a local attack vector; it is cited here for the property of the migration, nothing more.

8. **For any instrument or device that acts offline, write the cap the instrument acts under and the moment it reconciles.** The framework's caps sit on the payer's instrument ("on a payment instrument"), and it names the instruments: "Offline payments may be made using any channel or instrument like cards, wallets, mobile devices, etc." Source: RBI, Framework for Facilitating Small Value Digital Payments in Offline Mode, 3 January 2022, updated 4 December 2024: "The upper limit of an offline payment transaction shall be ₹500. The total limit for offline transactions on a payment instrument shall be ₹2,000 at any point in time. For UPI Lite 1, the enhanced limits shall be ₹1,000 per transaction with ₹5,000 being the total limit. Replenishment of used limit shall be allowed only in online mode with AFA."

9. **Do not skip the classes whose algorithm is "only" authentication.** Write beside them the sentence the draft uses. Source: NIST IR 8547 (draft), section 3.1.2: "Authentication systems may continue to use quantum-vulnerable algorithms until quantum computers that are capable of breaking current, quantum-vulnerable algorithms become available, at which point authentication using these algorithms will need to be disabled."

10. **Date the checklist, and re-run it when any of the sources it rests on moves.** First on the list: a final NIST IR 8547; the PCI PTS POI v5 and v6 expiry dates; the RBI offline-framework caps ("Updated as on December 04, 2024" on the run date); the CycloneDX schema version (1.6 on the run date); and any RBI Q-SAFE report, due "within six months from the date of its first meeting" (RBI Press Release 2026-2027/325, 25 May 2026), a date not published.

---

**Provenance.** Derived from NIST IR 8547 (initial public draft, November 2024), NIST SP 800-82r3, PCI SSC bulletins of 17 June and 11 September 2025 and the PTS Program Guide v1.9, CISA/NSA/NIST "Quantum-Readiness" (17 August 2023), CISA ICSA-26-253-01 / AVEVA-2026-006, RBI's offline-payments framework (RBI/2021-22/146), RBI/2017-18/206, RBI Press Release 2026-2027/325, and the Ministry of Power's model AMISP contract (SBD V4, August 2022), all fetched 11 September 2026. Companion to worked artifact A, `twin-machine-gff-artifact-a.csv`, the CBOM table for a fleet of machines that move.
