spot_imgspot_img

Top 5 This Week

spot_img

Related Posts

The Quantum Threat to Your Company Isn’t the Computer. It’s the Migration You Haven’t Started.

No executive team has ever had to defend a security budget against an attacker that doesn’t exist yet, using a technology that may or may not work, on a timeline nobody can specify with confidence. That is precisely the position boards now find themselves in with post-quantum cryptography, and it is why so many are choosing to do almost nothing.

The instinct is understandable. It is also, on the evidence, the most expensive decision available.

Start with the number that should unsettle any CFO who has priced a technology transition before. DigiCert’s 2026 Quantum Readiness Outlook, a survey of over a thousand IT and security decision-makers across the US, UK and Australia, found that 87 percent of organisations are now planning, testing or implementing post-quantum cryptography. Only 7 percent have actually deployed quantum-safe or hybrid encryption across more than half their digital certificates, up from just 5 percent a year earlier. Eighty-five percent of the same respondents believe today’s encryption will be broken within a decade. The gap between what executives believe and what their organisations have actually done is not a rounding error. It is the entire strategic problem, compressed into two statistics.

A threat with no fixed arrival date, and a fix that takes longer than the threat’s runway

The reason this gap matters more than most compliance shortfalls is timing, not ideology. A cryptographically relevant quantum computer, one capable of using Shor’s algorithm to break the RSA and elliptic-curve cryptography underpinning almost all internet security, banking infrastructure and enterprise systems today, does not yet exist. Google’s Willow chip, unveiled in December 2024, demonstrated an impressive error-correction milestone on a benchmark with no cryptographic relevance. IBM has laid out a credible-looking roadmap toward a fault-tolerant machine it calls Starling by 2029. Microsoft’s claims about a topological qubit, announced with considerable fanfare in February 2025, remain genuinely contested within the physics community, with Amazon’s own quantum hardware leadership publicly stating the underlying paper does not demonstrate what Microsoft says it does.

Close-up of a quantum computing chip and dilution refrigerator wiring in a research laboratory
Hardware progress is real, but a machine capable of breaking today’s encryption standards has not been built. The disagreement among experts is about how much runway remains, not whether the threat is genuine.

Serious people disagree sharply about what any of this means for a timeline. The Global Risk Institute’s 2025 survey of 26 international quantum experts put the probability of a cryptographically relevant machine within ten years at 28 to 49 percent, rising to 51 to 70 percent within fifteen. On the more sanguine end, cryptography researchers such as Justin Thaler at a16z crypto argue a working machine remains “far beyond reach” before the early 2030s at the earliest, and warn that rushing into immature post-quantum schemes carries its own failure risk: two earlier NIST finalist candidates, Rainbow and SIKE, were both broken by conventional mathematics after initially appearing secure. On the more urgent end, cryptography engineer Filippo Valsorda has compared the current moment to the period just before nuclear fission research went classified, arguing the burden of proof now sits with those claiming a breakthrough machine won’t arrive by 2030, not with those preparing for one.

The useful reframe for a CEO is that this disagreement barely matters, because the constraint isn’t when quantum computers arrive. It’s how long migration takes once you start. An academic timeline study published in December 2025 estimated that large enterprises require twelve to fifteen years to complete a full cryptographic migration under normal conditions, once you account for discovering every place RSA and elliptic-curve cryptography is actually used across an organisation (itself a one-to-three-year exercise for a large company), replacing hardware security modules, coordinating with every third-party vendor whose systems touch yours, and dealing with embedded and legacy devices that were never designed to have their cryptography swapped out at all. Layer a twelve-to-fifteen-year migration against even the more conservative quantum timelines, and a company that starts today may finish with little room to spare. A company that starts in 2029, when the threat feels more concrete, will not finish before the 2030s risk window that most credible forecasts now describe.

This is why “harvest now, decrypt later” deserves to be treated less as a futuristic scenario and more as a present-tense one. Encrypted data with a long confidentiality shelf life, whether that’s a pharmaceutical company’s clinical trial data, a defence contractor’s design files, or a bank’s customer records, is worth stealing today even if it can’t be read for another decade, because someone is betting that decade will come inside the data’s useful life. Western intelligence and cybersecurity agencies have characterised this as a credible, actively relevant risk rather than a hypothetical one; DigiCert’s survey found 84 percent of security leaders believe at least some of their organisation’s data is already exposed on this basis, and more than a third believe a quarter or more of it is.

The regulators are not waiting for certainty either

What has changed materially over the past two years is that governments have stopped treating this as a research question and started treating it as a compliance deadline. NIST finalised its first three post-quantum standards, ML-KEM, ML-DSA and SLH-DSA, in August 2024, and added a fifth backup algorithm, HQC, in March 2025 as a hedge in case the primary lattice-based approach is ever weakened. The NSA’s CNSA 2.0 mandate requires all new national-security-system acquisitions to be quantum-resistant from January 2027, with non-compliant equipment phased out by the end of 2030 and full compliance mandated a year after that. The European Union’s coordinated roadmap, developed through its NIS Cooperation Group, requires member states to publish national transition strategies by the end of 2026 and complete migration of critical infrastructure by 2030, while the EU’s Cyber Resilience Act makes cryptographic agility, the ability to swap algorithms without re-architecting a system, a formal legal requirement from December 2027. In July 2026, the European Central Bank told the roughly 110 significant banks it directly supervises that quantum-safe adoption “must start now and necessitates sustained, strategic investment,” with more specific supervisory requirements to follow.

None of these bodies are claiming to know precisely when a cryptographically relevant quantum computer will exist. They are simply doing the arithmetic on migration timelines and concluding that waiting for certainty is itself the risky choice.

India’s most exposed system sits on the slower track

India offers a particularly sharp illustration of how this plays out when a country has to sequence a transition across very different levels of systemic importance. A Department of Science and Technology task force, reporting in February 2026, laid out a two-track roadmap. Critical information infrastructure, defence, power, telecom, and space and atomic research bodies, is on an accelerated path targeting full post-quantum adoption by 2029. Everything else, including banking, insurance and healthcare, sits on a slower track running to 2033. That second track is where the Unified Payments Interface lives: a system processing hundreds of billions of transactions annually, arguably as systemically significant to India’s economy as any piece of infrastructure on the fast track, yet scheduled for quantum-safe migration four years later.

A customer making a UPI digital payment in India, illustrating the cryptographic security underpinning the payments system
UPI processes hundreds of billions of transactions a year, yet sits on India’s slower, 2033 post-quantum migration track rather than the accelerated critical-infrastructure timeline.

The Reserve Bank of India has convened its own expert committee, with representation from the National Payments Corporation of India, to assess the sector’s readiness, and India’s Centre for Development of Telematics unveiled fourteen indigenous quantum-safe products in August 2026, encouragingly built around NIST’s own algorithms rather than a competing sovereign standard. But the sequencing question, why the country’s most transaction-dense financial rail is not on the accelerated track, is one that Indian financial institutions and their regulators have not yet had to answer publicly.

What this means for how CEOs should be thinking about it

The organisations that will handle this well are not the ones that guess the quantum timeline correctly. They’re the ones that stop treating this as a discrete IT security project with a fixed algorithm to install, and start treating it as a capital allocation and governance decision with a long, uncertain runway, one where the real asset being built is the organisational capacity to change cryptographic standards again, cheaply, when the next one arrives. That capability, crypto-agility, is worth more than any specific algorithm NIST has finalised, because the mathematics underlying today’s post-quantum standards could itself be weakened by an unexpected advance, just as Rainbow and SIKE were. Boards that ask their technology leadership “are we quantum-safe” are asking the wrong question. The right one is whether the organisation could re-key its entire cryptographic infrastructure inside eighteen months if it had to, because that, and not the arrival date of any particular computer, is the real number that determines whether the twelve-year migration finishes in time.

Popular Articles