Thinking

Post-quantum readiness is not a cryptography project

Brand and reputation depend on whether sensitive information, trusted records and critical services remain protected as the technologies and dependencies beneath them change.

Quantum computing is no longer theoretical. Working systems are already being used in research, including materials science, molecular modelling and healthcare. But no publicly known quantum computer is yet large and fault-tolerant enough to break the public-key cryptography protecting much of today’s digital infrastructure. No one knows when that threshold will be crossed.1

That distinction matters. It can also create false comfort.

The date is uncertain. The time to start preparing is not.

Australia recommends that organisations complete their transition by 2030. The UK expects large organisations to spend years discovering dependencies and planning before working towards broad completion by 2035. These are not countdowns to a machine. They reflect how long it takes to understand an estate, coordinate suppliers, make investment decisions, test replacements and migrate safely.2

Some of the exposure is already here

Information encrypted today may still be sensitive when today’s protection can eventually be broken. A malicious actor does not need to read it now. The information can be stolen, copied and retained until the capability to decrypt it becomes available.

Authorities operating in very different political and institutional settings describe almost exactly the same pattern. NIST, Australian and Canadian cyber authorities, and the G7 call it “harvest now, decrypt later.” A Chinese state-linked source uses 先窃取、后解密—“steal now, decrypt later.”3

They may not agree on who is doing the harvesting. They agree on the attack model.

Nor is this only a state-intelligence scenario. Europol has warned that malicious or criminal actors may collect encrypted information now for later exploitation. Criminal networks already steal and retain databases, files and communications for extortion, fraud, identity crime and resale. Quantum computing may create another way to exploit what has been taken; it does not create the incentive or machinery for taking it.4

Public evidence cannot tell us how much encrypted material is being retained specifically for future quantum decryption. It does establish why the risk is current rather than hypothetical.

That makes reducing the chance that encrypted information is stolen now an immediate priority. Information still under the organisation’s control can later be re-protected. A copy already taken by an attacker cannot.

So the useful question is not only when quantum computing will become capable of breaking current cryptography. It is:

What are we protecting today that still needs to be secret when it does?

Start with the information, not the algorithm

Understanding information, assets and controls is not a novel discipline invented for quantum risk. Organisations should already know which information they depend on, why it matters and how it is protected. Post-quantum readiness applies a different threat model and a longer protection horizon—and may reveal where that understanding is incomplete.

Quantum computing does not affect every kind of cryptography in the same way. The principal migration challenge concerns traditional public-key cryptography used to establish secure connections, authenticate systems and create digital signatures. Symmetric encryption is affected differently and, with appropriate key sizes, is not treated as requiring the same wholesale replacement.5

Different cryptographic functions also create different consequences. Harvest-now risk is principally about confidentiality. A future ability to forge a signature, impersonate a system or authorise malicious firmware is a different exposure. The information, systems and timelines may not be the same.

That is necessary technology work. It is still the wrong starting point for a board.

The board needs to begin with the organisation’s continuing obligations. Which information, services and trust functions would still matter if their protection failed years from now? What harm would follow? Where are they stored, processed or transmitted? Which systems and suppliers provide the protection? When were the practices and controls intended to prevent unauthorised copying or loss last tested? Did those tests consider how long that information must remain protected?

The aim is not to classify every encrypted record as a quantum emergency or to build an exhaustive inventory for its own sake. It is to locate material exposure and decide what is proportionate.6

Action now may include reducing unnecessary retention and transmission, strengthening current anti-exfiltration controls, preparing to re-protect information still under the organisation’s control, and avoiding technology or contractual decisions that make eventual migration harder.

Not every implementation decision should be made immediately. Products, protocols and assurance arrangements are still developing, and premature deployment can introduce new security, performance and interoperability risks. The discipline is to distinguish deliberate waiting from delay nobody has examined.

A standard has to survive contact with the organisation

The technical direction is becoming more concrete. NIST published its first three principal post-quantum standards in 2024, and governments, protocol bodies and technology providers are incorporating them into guidance, products and services.7

But standardisation is not the same as deployment maturity.

The public-key cryptography embedded across today’s infrastructure has accumulated decades of study, implementation experience, protocol integration, hardware support and optimisation. Post-quantum deployments begin with far less operating history across the variety of systems that will eventually need to use them. That is not an argument against the standards. It is a reason to test what happens when they meet the real systems that must use them.89

Some products are deliberately designed for crypto agility: the ability to replace or adapt cryptographic algorithms and related components while preserving security and ongoing operations. That can materially reduce migration cost and disruption. But agility at the algorithm layer does not establish that a replacement will fit the operating environment or preserve every property on which the service depends.10

Keys, signatures and certificates may be larger. Processing, memory, storage, bandwidth and latency effects will differ by algorithm and environment. A replacement may preserve the basic cryptographic function while changing interoperability, privacy, reliability, transaction flow or customer experience.

A long-lived device makes the issue tangible. It may use a digital signature to verify its software before starting or accepting a firmware update. But it may have limited memory, processing capacity, storage or battery power, with a root of trust embedded in hardware. What looks like an algorithm substitution may require a redesigned update process, new hardware or earlier asset replacement.11

Transition design can also hedge against uncertainty in the cryptography itself. Some implementations combine a post-quantum and classical signature and require both to be valid, so a weakness in one does not by itself defeat the assurance while the other remains secure. Other migration approaches may run classical and post-quantum methods in parallel for compatibility, but accepting either one alone provides interoperability rather than the same dual-algorithm hedge. Once quantum capability can break the classical component, that part of the hedge no longer provides independent protection; resilience then depends on diversity among post-quantum approaches and the crypto agility to change again.12

Changing the algorithm is not the same as keeping the system working with its current features, performance or experience intact. And choosing an algorithm is not the same as being prepared to change again.

For most organisations, much of the cryptography they rely on is embedded in cloud platforms, managed services, software libraries, network devices, payment and identity services, industrial equipment and supplier products. That can obscure the dependency: it may be unclear which component provides the protection, how it can be changed, or whether a supplier’s post-quantum roadmap actually covers the products, versions and deployment models the organisation relies on.

Australia’s vendor guidance makes the dependency explicit: providers often implement and control cryptographic mechanisms on behalf of customers, and their delays or constraints can undermine an otherwise sound plan.13

The risk may remain with the organisation even when the means of resolution sits elsewhere. That makes procurement, contracts and asset cycles a key part of readiness.

A supplier renewal, platform migration or hardware refresh may be a rare opportunity to reconsider the dependency itself: what transparency is required, what the supplier must be able to change, which migration obligations belong in the contract, how interoperability and exit will be preserved, and whether the existing concentration or lock-in should be carried forward at all.

A migration window may also be a decision window. Once it closes, the organisation may have to live with what it carried forward.

The threat is shared. The transition will not be.

It is tempting to think of post-quantum migration as a modern version of Y2K: a common technical problem that the world will ultimately address together.

The comparison is incomplete. Y2K had a fixed date. That created a common organising logic: assets could be found, tested and addressed against a deadline. Post-quantum transition has no agreed failure date. Information has different protection lives. Products and implementation experience are still developing. Suppliers, devices and jurisdictions will not move together.

There are strong forces for convergence. NIST’s standards have been internationally scrutinised, and global technology providers and protocol bodies have powerful incentives to avoid unnecessary variation.

But a common algorithm does not create common control.

Governments and regions may differ over approved parameters, certification, trusted products, procurement eligibility, migration dates and the treatment of sensitive workloads. The European Union is pursuing a coordinated transition among Member States, while China is running its own process for next-generation commercial cryptographic algorithms. National assurance machinery will continue to shape what is acceptable even where technical standards overlap.14

The likely future is partial technical convergence inside a plural political, assurance and supply-chain environment. The practical consequence is not that every organisation needs a geopolitical strategy for cryptography. It is that a plan built around one assumed timetable, supplier position or assurance regime may not remain sufficient.

Preparedness is the ability to act

Preparedness is not the existence of a programme, risk entry or migration plan. It is the organisation’s continuing ability to see its exposure, make proportionate decisions and act as the technology, standards and threat change.

Security teams may identify the exposure, but decisions about information, architecture, products, suppliers, assets and funding determine whether the organisation can act.

A named owner without access to the relevant information, authority across those decisions and resources that can be directed towards action is not real ownership.

Organisations make promises—through regulation, contracts and their brands—about confidentiality, integrity, reliability and stewardship. A failure involving sensitive information, trusted records, software integrity or critical services would be experienced as a failure of trust, not as an obscure problem in cryptographic engineering.

This governance pattern is not theoretical. Australian telecommunications outages—unrelated to post-quantum transition—show how quickly a technical failure can become a question of trust and accountability.

Optus outages in 2023 and 2025 prompted inquiries, substantial penalties and stronger oversight of Triple Zero. At the Senate hearing, Telstra’s testimony indicated that its July 2026 outage followed maintenance on a 15-year-old network timing server that could have been replaced for $30,000. Required software updates had been flagged but not applied, and an earlier design change had not been properly documented. Telstra acknowledged that either action might have prevented the outage.

That figure does not explain the failure on its own. It sits inside a longer chain of deferred updates, undocumented change and inadequate controls. But the asymmetry is difficult to ignore: a relatively modest asset decision formed part of a failure that damaged the brand, disrupted payments, transport, businesses and emergency calls, and contributed to economic losses an independent telecommunications expert estimated could run into the hundreds of millions.15

The cause of a failure may be complicated. The questions asked afterwards will not be.

Scrutiny will travel backwards through the decisions, deferrals and assumptions that produced the organisation’s position: what it knew, what it had chosen to protect, which dependencies it understood, which warnings it acted on, what it expected from suppliers and where accountability sat.

Programmes, workstreams, inventories, funding and formal accountability will be needed. But they can also fragment the problem. Data, supplier, architecture, product and implementation decisions may sit in separate workstreams, each able to demonstrate progress while the organisation as a whole remains no better able to act.

Proportionate governance should create coherence across those decisions, not another layer of machinery around them.

A practical test of that coherence is:

Who could explain the organisation’s post-quantum position today—and how long would it take to assemble the answer?

Could they explain:

  • what must remain protected, and for how long;
  • where the material exposures and dependencies sit;
  • what is controlled directly, what can be influenced and what depends on others;
  • which actions, deferrals and assumptions support the current position; and
  • what new evidence would cause the priorities to change?

How long it takes is part of the answer. So are the hand-offs, disagreements and untested supplier assurances the exercise exposes.

A coherent explanation is not enough if new evidence cannot move a budget, backlog, contract or decision.

The continuing governance question is:

Could we explain, under pressure, what we knew, what we did and why?

Conclusion

The purpose of preparedness is not to predict the precise arrival of a cryptographically relevant quantum computer or to lock the organisation into today’s technical answer. It is to keep improving the organisation’s understanding of what must remain protected and why, while maintaining the authority and capacity to act as the evidence, technology and dependencies change.

The transition will expose more than outdated cryptography. It will expose forgotten data, embedded dependencies and choices that have become expensive to change.

A programme can migrate all of them successfully. That does not mean it should.

The opportunity hidden inside the risk is not merely to replace the protection. It is to avoid rebuilding tomorrow around the constraints discovered today.

Related resources

For selected third-party guidance and practical resources, see the Post-quantum readiness collection in QURKI Resources.

Notes

Footnotes

  1. IBM and Cleveland Clinic installed a quantum computer dedicated to healthcare and life-sciences research in 2023. NIST and the UK NCSC state that no cryptographically relevant quantum computer currently exists and that its arrival date is uncertain. See IBM Research, “IBM and Cleveland Clinic unveil first quantum computer dedicated to healthcare research”; NIST, “What Is Post-Quantum Cryptography?”; and UK NCSC, “Timelines for migration to post-quantum cryptography”.

  2. ASD’s current planning guidance calls for a refined plan by the end of 2026, commencement with critical systems and data by the end of 2028, and completion by the end of 2030. The UK NCSC sets milestones for discovery and planning by 2028, priority migration by 2031 and broad completion by 2035. See ASD, “Planning for post-quantum cryptography” and UK NCSC, “Timelines for migration to post-quantum cryptography”.

  3. NIST, ASD, the Canadian Centre for Cyber Security and the G7 describe “harvest now, decrypt later.” A June 2026 article published by Shanghai’s state-owned assets authority uses 先窃取、后解密—“steal now, decrypt later”—when describing threats to securities transactions and core data assets. See NIST, “What Is Post-Quantum Cryptography?”; ASD, “Quantum technology primer: Computing”; Canadian Centre for Cyber Security, “Preparing your organization for the quantum threat to cryptography”; G7 Cybersecurity Working Group statement; and Shanghai State-owned Assets Supervision and Administration Commission, “国泰海通助力全球首个软硬全栈抗量子密码平滑迁移解决方案发布”.

  4. Europol’s Quantum Safe Financial Forum warns of malicious actors collecting encrypted data now for later quantum-enabled decryption; Europol’s earlier quantum report considers criminal exploitation of quantum capability. See Europol, “Call for action: urgent plan needed to transition to post-quantum cryptography together” and Europol, “Exploring the second quantum revolution”.

  5. Traditional public-key or asymmetric cryptography uses a related public and private key pair. Widely used examples include RSA, Diffie–Hellman and elliptic-curve cryptography; sufficiently capable quantum computing threatens the mathematical problems on which these methods rely. Symmetric encryption uses a shared secret key. NIST and the NCSC state that quantum computing affects it differently and that established symmetric algorithms with appropriate key sizes can continue to be used. See UK NCSC, “Preparing for Quantum-Safe Cryptography”; UK NCSC, “Next steps in preparing for post-quantum cryptography”; and NIST, “Post-Quantum Cryptography FAQs”.

  6. NCSC guidance asks organisations to understand data value and lifetime, the systems on which it is stored or processed, the public-key cryptography used and supplier plans. It says early discovery is intended to understand the nature of systems, not create a formal asset register for its own sake. See UK NCSC, “Post-quantum cryptography: what comes next?”, UK NCSC, “Timelines for migration to post-quantum cryptography”, and ASD, “Planning for post-quantum cryptography”.

  7. NIST published FIPS 203, FIPS 204 and FIPS 205 in August 2024. See NIST, “Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography”.

  8. NIST’s selection criteria covered security, cost, key, ciphertext and signature sizes, efficiency across software, hardware and constrained platforms, flexibility and fit with existing protocols and applications. See NIST, “Cost” and NIST, “Algorithm and Implementation Characteristics”.

  9. NIST’s PQC standards are recent, while the NCSC notes that robust implementations, protocols, products, validation and hardware acceleration continue to develop. The NCSC expects implementation efficiency to improve as the ecosystem matures. See UK NCSC, “Post-quantum cryptography: what comes next?” and UK NCSC, “Timelines for migration to post-quantum cryptography”.

  10. NIST defines crypto agility as the capabilities needed to replace and adapt cryptographic algorithms across protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations. Its guidance also discusses the challenges and trade-offs involved. See NIST, “Considerations for Achieving Crypto Agility: Strategies and Practices”, updated 29 June 2026.

  11. Current IETF work on PQC in constrained devices addresses strict limits on processing, RAM, storage and power, as well as firmware authentication, secure boot and larger signatures and certificates. It remains an active Internet-Draft rather than a final standard. See IETF PQUIP, “Adapting Constrained Devices for Post-Quantum Cryptography”.

  12. Post-quantum/traditional hybrid schemes combine post-quantum and established classical cryptography. IETF RFC 9794, “Terminology for Post-Quantum Traditional Hybrid Schemes” distinguishes hybrid constructions and also recognises post-quantum/post-quantum schemes based on different mathematical problems. Current IETF LAMPS Composite ML-DSA work combines ML-DSA with traditional signature algorithms including ECDSA, Ed25519, Ed448 and RSA for operators seeking additional protection against breaks or catastrophic bugs in ML-DSA; it remains an Internet-Draft rather than a final RFC. National guidance differs. ANSSI strongly recommends hybridisation in the short and medium term as a non-regression measure. ASD does not recommend but does not prohibit post-quantum/traditional hybrids, noting both the resilience benefit and the additional implementation, maintenance, computation and bandwidth overhead. The UK NCSC treats hybridisation as an interim option that may be justified by interoperability, implementation-security or protocol constraints and recommends retaining a straightforward path to post-quantum-only operation. Implementation evidence includes EJBCA 9.5, which added composite certificates combining ML-DSA with RSA, ECDSA or EdDSA, and Meta’s 2026 migration framework, which says it prioritises a hybrid approach in relevant deployments as a transition safety net. NIST has standardised lattice-based ML-DSA and hash-based SLH-DSA and describes SLH-DSA as a backup method should ML-DSA prove vulnerable; see NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”.

  13. ASD’s July 2026 vendor guidance says vendors often implement and control cryptographic mechanisms for customers, highlights long asset lifecycles and hardware replacement, and recommends incorporating PQC into procurement, contract renewal and vendor assurance. See ASD, “Post-quantum questions to ask your vendors”.

  14. The EU’s coordinated roadmap seeks a synchronised transition among Member States. China’s Institute of Commercial Cryptography Standards is running its Next-generation Commercial Cryptographic Algorithms programme and opened a formal call for next-generation public-key algorithm proposals, with submissions closing on 30 June 2026. See European Commission, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography” and Institute of Commercial Cryptography Standards, “Call for Proposals for the Next-generation Public-Key Cryptographic Algorithms”.

  15. The November 2023 Optus outage prompted a Senate inquiry. ACMA later imposed penalties totalling more than $12 million and said the resulting reforms included better outage communications, greater oversight of the Triple Zero ecosystem and regular systems testing. A second Optus outage in September 2025 affected emergency calls and prompted a further ACMA investigation and subsequent legislative action around the Triple Zero Custodian. Telstra’s 8 July 2026 outage disrupted mobile services, payments, transport, businesses and emergency calls. Telstra Chief Executive Vicki Brady’s opening statement to the Senate inquiry confirms that maintenance on a Network Time Protocol server exposed an undocumented design change and an unapplied software update, and that either issue, if addressed, might have prevented the outage. ABC News reporting of Telstra’s evidence to the 17 July Senate hearing records that the server was 15 years old and could have been replaced for $30,000. ABC News separately reports RMIT telecommunications expert Mark Gregory’s estimate that the broader economic cost could run into the hundreds of millions of dollars. ACMA opened an investigation into Telstra’s compliance with emergency-call and outage obligations. The government had increased the maximum fine for relevant Triple Zero failures to $30 million; see ABC News, “Telstra will face Senate inquiry after nationwide outage”.

QURKI Signal

Receive QURKI updates

QURKI does not publish to a weekly schedule. Signals appear when there is something worth sustained attention. Subscribe to hear when a new Signal or occasional related update is published.

By subscribing, you agree to receive email updates from QURKI. You can unsubscribe at any time.