SDIS 08
Sovereign Cybersecurity
Zero Trust Architectures and Post-Quantum Readiness for National Systems
Sovereign Digital Infrastructure Series
Abstract
Sovereign systems face a security requirement conventional enterprise architectures do not: they must remain defensible even against adversaries who may include, or be sponsored by, the vendors and partner states the system otherwise depends on for cooperation. This paper specifies a zero trust reference architecture for sovereign digital infrastructure aligned to NIST SP 800-207, and traces the history of zero trust as a discipline and why sovereignty requires extending it. It extends the zero trust model with sovereignty-specific controls (independently operated trust anchors, locally verifiable attestation), addresses supply chain security and national CERT coordination, and covers the accelerating requirement to migrate cryptographic infrastructure to post-quantum algorithms, using 2026 NIST migration guidance as the compliance baseline. It examines fourteen detailed case studies and closes with economic and organizational considerations, an implementation roadmap, a glossary, and a self-assessment checklist.
Keywords
- zero trust
- NIST 800-207
- post-quantum cryptography
- national CERT
- supply chain security
Citation
Burnard, B. (2026). Sovereign Cybersecurity (SDIS 08). D-AI Research. https://doi.org/10.5281/zenodo.22085484