Crypto-Agility Maturity Models Compared: CARAF, CAMM, and Where ECEM Fits

Two colleagues discussing strategy frameworks on a whiteboard in a modern office

“Crypto-agility” gets used loosely – usually as a general sense that an organisation could change algorithms if it had to. Two named frameworks give the term more precision than that: CARAF, a risk-assessment method, and CAMM, an organisational maturity model. Neither is a competitor to Enterprise Cryptographic Exposure Management (ECEM). Understanding what each one actually measures is what makes it possible to use all three without confusing them.

CARAF: a risk assessment, not a maturity score

The Crypto Agility Risk Assessment Framework (CARAF) was published in 2021 in Oxford University Press’s Journal of Cybersecurity, authored by Chujiao Ma, Luis Colon, Joe Dera, Bahman Rashidi and Vaibhav Garg. It defines crypto-agility precisely: the ability to replace cryptographic primitives, algorithms or protocols quickly, inexpensively, and with no or acceptable risk exposure.

CARAF itself is a five-step process. Determine the specific threat vector driving the assessment. Identify the assets that threat vector actually impacts. Evaluate the expected value of those assets being compromised. Select a mitigation strategy proportionate to that expected value. Build a roadmap sequencing mitigation across asset classes by risk.

Worth noting: CARAF’s second step – identifying the assets a threat vector impacts – assumes those assets are already knowable. The framework doesn’t define how an organisation builds that visibility in the first place; it starts from the assumption that a usable inventory already exists. CARAF remains an active reference point rather than a one-off academic paper – one of its own authors, Bahman Rashidi, presented it again at a NIST crypto-agility workshop in 2025.

CAMM: measuring maturity, not producing a plan

The Crypto-Agility Maturity Model (CAMM), developed by researchers at Hochschule Darmstadt, defines five capability levels, 0 through 4. At Level 0, cryptography is unmanaged – algorithms and keys are hard-coded, with no central inventory. At Level 1, awareness begins: teams start cataloguing algorithms and dependencies, but changes are still manual. At Level 2, management processes emerge, with basic automation supporting key rotation and algorithm updates. At Level 3, governance and tooling are standardised, and cryptographic changes follow formal policy with automated enforcement. At Level 4, agility is continuous – cryptographic assets are fully inventoried, monitored, and automatically transitioned as standards evolve.

CAMM answers a different question than CARAF does. CARAF tells you what to fix first, given a specific threat. CAMM tells you how mature your organisation’s overall capability is to make that fix at all, independent of any single threat. Neither is a substitute for the other, and neither is a substitute for actually having the inventory both frameworks quietly assume exists.

Where ECEM fits

Enterprise Cryptographic Exposure Management runs six continuous stages: Discover, Inventory, Assess, Prioritise, Transition, Monitor. Read against CARAF and CAMM, the overlap is real but partial – not competing.

ECEM’s Discover and Inventory stages produce exactly the asset visibility CARAF’s second step assumes, and that CAMM’s Level 0-to-1 gap describes. Without them, a CARAF-style risk assessment has nothing concrete to run against, and an organisation is structurally capped at CAMM Level 0 or 1 regardless of intent. ECEM’s Assess and Prioritise stages do a version of CARAF’s own threat-vector-to-mitigation-roadmap logic, but as a continuous process running across the whole estate rather than a one-off assessment scoped to a single threat vector. And ECEM’s Transition and Monitor stages, run continuously rather than as a project with an end date, are what CAMM’s Level 4 describes as the highest maturity state: cryptographic assets fully inventoried, monitored, and automatically transitioned as standards evolve.

Put simply: CARAF and CAMM are useful, independently published ways to describe risk and to benchmark maturity. ECEM is the operational discipline that has to be running continuously for either description to actually be true of an organisation, rather than aspirational.

Further reading: what ECEM actually is, cryptographic exposure assessment, and continuous posture monitoring.

Scroll to Top