Quantum computing was once exclusively reserved to experts and specialist journals. Today it is widely covered by the mainstream press, and every major regulator has taken up the subject. This media attention has fueled a growing number of warnings, some urgent, even alarmist.
Yet this is no time to panic, nor to procrastinate. The reasons to prepare now are simple and familiar.
In this article, we explain why acting on post-quantum cryptography today is essential: to comply with regulatory standards, to anticipate critical risks to systems and data, and to keep the cost of an inevitable migration under control. We also show how to lay the groundwork now for a successful transition, turning a complex challenge into a structured, well-managed effort.
A transition driven first and foremost by compliance
One of the major shifts in the post-quantum cryptography discussion is that the debate is no longer purely technological. For a long time, the central question was: when will a quantum computer capable of breaking today’s cryptography exist? Uncertainty about that date, known as Q-Day, has often served as a justification for postponing transition efforts.
That position is becoming increasingly untenable. Since 2024, the standards landscape has begun to stabilize. The National Institute of Standards and Technology (NIST) has published the first post-quantum algorithm standards, intended to replace the primitives in widely use today, notably RSA and elliptic-curve-based algorithms.
More importantly, these standards now come with a timeline. NIST has announced its intention to deprecate some current algorithms in 2030, and to disallow their use in most contexts by 2035. The European Union and the United Kingdom are broadly following the same trajectory, driven in particular by the European Commission and the UK’s NCSC. There are nuances, however: certain regulated sectors, such as defense and critical infrastructure, are subject to specific requirements that may partly diverge from this general framework. The deadline is therefore regulatory, to be read in light of each context, and organizations will have to migrate because their cryptographic mechanisms will simply no longer be considered compliant.
This shift brings the post-quantum challenge closer to other major transformations in cybersecurity. Much like patch or vulnerability management, what was once a one-off technical topic is gradually becoming standard operational practice. The cryptographic transition should therefore be viewed not as an exceptional project, but as a normal part of managing the cryptographic security lifecycle.
A critical risk despite uncertain likelihood
Progress in quantum computing, both theoretical and physical, has been significant, including a reduction of more than 95% between 2019 and 2026 in the estimated number of qubits needed to break RSA-2048. Even so, the probability of Q-Day occurring by any given date remains uncertain. What characterizes this risk above all is its considerable impact. A sufficiently powerful quantum computer would not compromise just one algorithm among many: it would undermine the very foundations on which digital trust rests. Authentication, electronic signatures, secure communications, key distribution: these are the mechanisms that silently underpin every digital exchange. It is this systemic reach that sets the quantum threat apart from an ordinary vulnerability.
Once the technological breakthrough has happened, it will be too late. The window for action is now.
Exposure that may already exist today
Tackling the problem now is all the more important because some organizations are already exposed to certain risks stemming from quantum computing.
The first is “harvest now, decrypt later” (HNDL): the idea that malicious actors could collect encrypted communications today to decrypt them later, once a quantum computer becomes available. This risk is real and must be assessed, particularly for data with long confidentiality lifetimes. It does not, however, necessarily warrant an alarmist approach: not all data needs to remain secret for decades, and actual exposure depends heavily on use cases and on the organization’s threat model.
A second scenario, often less discussed but potentially even more far-reaching, concerns digital signatures. The issue lies first and foremost with trust anchors: the certificate authorities that sign smart-card identity documents, those that will underpin European digital identity wallets, enterprise PKIs, and product PKIs used for code and firmware signing. Compromising one of these roots would not amount to an isolated forgery: it would make it possible to issue identities, certificates or software updates recognized as legitimate by every system that trusts that anchor. These are also the hardest assets to migrate due to their lifetimes of ten to twenty years, their massive deployment in equipments that cannot be updated remotely, and their ecosystems standardized at international level.
The same mechanism weakens signed documents downstream. Many legal and financial tools (commercial contracts, loans, regulatory agreements) rely on signatures whose validity must be guaranteed over long periods. They could be forged, and the evidential value of signatures already applied would be called into question if timestamping or countersigning had not been carried out in time.
Above all, such a situation would require a renewal effort of unprecedented scale. For the trust-anchor use case, generating new post-quantum roots would not be enough: they would have to be distributed to every trust store already deployed, the certificate chains that depend on them reissued and, for non-updatable devices, physical replacement awaited. For the document use case, organizations would have to re-sign or re-timestamp a considerable volume of archives to preserve their legal value. In document-intensive sectors such as finance, insurance and law, where retention periods can extend to several decades, the scale of this operation would be far from negligible.
The real cost of procrastination
The third reason to act quickly is economic. The transition to post-quantum cryptography is a large-scale undertaking spanning several years, if not more than a decade.
Delaying the start of the program does not eliminate the effort: it simply compresses the timeline, which inevitably drives up costs. A rushed migration typically leads to:
- Greater dependence on vendor solutions,
- Less optimal technology choices,
- Urgent and costly mobilization of teams.
Conversely, an early program makes it possible to spread investment over time and to integrate new mechanisms progressively into the normal evolution cycles of systems. Boston Consulting Group, for instance, estimates that organizations could see migration costs double if the migration is not sufficiently anticipated.
“No-regret” work
Much of the work to be undertaken also falls under so-called “no-regret” measures: actions that improve cyber posture regardless of when a quantum computer actually arrives.
These initiatives in fact converge on a single goal: crypto-agility, meaning the ability to change the algorithms, protocols and keys in use without having to rebuild the systems that depend on them. Inventories, controlled key management, documentation of usage, isolation of cryptographic components within architectures: these are the building blocks of that capability. And that capability has value in its own right, independent of the quantum threat. Cryptographic standards evolve, algorithms once considered secure are sometimes weakened and then retired, and the post-quantum transition itself will happen in stages, with hybrid schemes at first and adjustments as agencies and standard bodies publish new guidance. For an organization that has built this agility, each of these changes becomes routine rather than a migration project to be relaunched.
Building this agility requires first gaining clear visibility: where cryptography is used, which flows and data it protects, and which components it relies on. This visibility quickly extends beyond the cryptographic scope alone. It feeds directly into data protection programs and data-flow mapping exercises, which rest on the same questions. It also surfaces the cryptographic vulnerabilities scattered across the information system (obsolete protocols and algorithms, unmaintained libraries or vulnerable versions) and provides an opportunity to fix them.
The same logic applies to Third-Party Risk Management. By identifying cryptographic dependencies in software, infrastructure and Cloud services, a PQC (Post Quantum Cryptography) program sheds light on technology dependencies that are sometimes poorly documented and enables a more structured dialogue with suppliers about their roadmaps.
In short, risk governance as a whole comes out stronger.
Laying the foundations of a program
Calls to action are not in short supply, from the G7’s recent publication to Google and various government bodies, yet operational implementation often remains unclear.
A PQC program cannot be launched without an executive sponsor: it is a major IT transformation. Beyond the budget and resources to be committed over several years, its success depends above all on the organization’s ability to mobilize stakeholders who do not necessarily work together: bringing teams into alignment, securing commitments from suppliers, and getting PQC requirements built into projects already under way. On top of this, throughout the program, there are recurring trade-offs between the level of risk the organization is willing to accept and the investment needed to reduce it. Given their scope and consequences, these decisions belong to senior management.
Once that mandate is secured, the question remains of where concretely to begin. Large organizations do not all start from the same point. Some already have partial inventories or formalized cryptographic policies; others have not yet established data classification categories. For most, it starts with launching a structured program whose immediate objective is not to migrate, but to create the conditions for migration.
The key to this approach is working top-down. Rather than starting by listing every key and certificate in the information system, an exercise that is often lengthy and not very actionable, the idea is to start from the most critical business processes and work back to the cryptographic mechanisms underpinning them: inventorying the cryptography that will need to be migrated, not all the cryptography that exists. This approach makes it possible to prioritize from the outset, assess the real impact of a compromise, and focus resources where the risk is highest.
On this basis, the structuring actions follow naturally: mapping of usage, integration into configuration management repositories, identification of third-party dependencies, and upskilling of teams.
The question is no longer if or when, but how
The transition to post-quantum cryptography is neither optional nor distant. Regulatory deadlines are becoming clearer, some risks are already present, and the scale of the effort is such that a late start will inevitably come at a price: in cost, in haste, or in exposure.
The good news: much of the work to be undertaken today is useful whatever happens. Knowing your cryptographic assets better, understanding which business processes they protect, and reducing poorly documented dependencies are structural improvements that strengthen overall security, independent of any quantum timeline.
The question, then, is not whether to act, but how to structure this transition so that it fits naturally into existing evolution cycles, rather than one day imposing itself as a poorly prepared emergency.
