Assets built to run for thirty years. Cryptography with a published expiry date.
Operational technology cannot be patched on an IT schedule. Discovery has to be safe for a live process environment, and migration has to be sequenced around outage windows measured in years.
Everything that makes IT migration hard is worse here
A cryptographic programme designed for a data centre will fail in a process environment. The constraints are structural, not cultural.
Twenty to forty years in service
Equipment commissioned today will outlive the standards that currently permit its cryptography. The replacement cycle, not the migration plan, sets the real timeline.
Availability outranks confidentiality
Safety and continuity come first. A scan that risks a process upset is not an acceptable trade, which rules out most active discovery on a live control network.
Firmware belongs to the OEM
The migration path is a procurement conversation before it is an engineering one, and for many fielded devices no upgrade is offered at all.
Opportunities are measured in years
Some assets can be touched once a year. Some once a decade. Sequencing has to be built around those windows rather than around severity alone.
Passive first, credentialed second, active only where authorized
Active scanning of a live process network is frequently prohibited, and reasonably so. Coverage in this environment comes from method selection, not scan aggression.
Migrate the boundary before the plant floor
Most achievable near-term risk reduction in critical infrastructure sits at the IT and OT boundary, not deep in the process network. Sequence accordingly.
For the lowest layers the honest answer is often not migration but compensating controls until the asset is replaced. An inventory that says so is more useful than one that pretends otherwise.
NERC CIP, NIS2, TSA and IEC 62443 on cryptography
Start at the boundary
Scope one site or one IT and OT boundary, using passive collection where active scanning is not permitted.

