Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

  • Home
  • Blog
  • PQC
  • Quantum Computing Risk to Cryptography: What Your Organization Needs to Know Now

Quantum Computing Risk to Cryptography: What Your Organization Needs to Know Now

PQC

Quantum computing is advancing faster than most organizations realize, and many of the cryptographic algorithms that protect your business operations today will be breakable within years. This is not a distant science problem. It is a present-day business risk.

The industry calls the tipping point “Q Day,” the moment when quantum computers become powerful enough to crack the cryptographic standards that secure internet communications, financial transactions, and enterprise data. Current estimates vary, but the trajectory is accelerating. According to a McKinsey survey, 72% of experts expect a cryptographically relevant quantum computer (that is, a quantum computer capable of breaking modern cryptography) by 2035, while others point to timelines as early as 2029 to 2030. Organizations that wait too long won’t have enough runway to keep themselves safe while they go through all the planning steps. The transition has to start now.

The window to prepare is shrinking. And the consequences of inaction extend far beyond IT.

What quantum computing means for today’s cryptography

The communication protocols that protect nearly everything your organization does online rely on at least one vulnerable cryptographic algorithm. These are well-known classical schemes such as RSA, ECDH, ECDSA, etc, whose security rely on either the hardness of factoring large numbers, or solving a problem called the discrete logarithm. These algorithms underpin TLS connections, VPNs, payment processing, digital signatures, and secure email. Their security depends on mathematical problems that classical computers cannot solve in any reasonable timeframe.

Quantum computing changes that equation. This transformative computing approach enables speedups to solve certain problems, and some of these improvements are quite substantial and related to modern cryptography. Shor’s algorithm is one of such examples, allowing an adversary to solve certain problems exponentially faster than any of the existing classical solutions. Current quantum computers are not able to run Shor’s algorithm on parameters that are relevant to cryptography, however, this is expected to change in the coming years. A sufficiently powerful quantum computer could use Shor’s algorithm to break RSA and ECC cryptography in days rather than the billions of years a classical computer would require.

NIST has already responded by finalizing several Post-Quantum Cryptographic (PQC) standards. These algorithms are designed to run on normal classical computers, and to resist quantum attacks and represent the target standards organizations should plan to migrate toward. Some examples include ML-KEM for key encapsulation, and ML-DSA and SLH-DSA for digital signatures. More standards are on the way to provide mathematical diversity and robustness to future PQC deployments. The critical point for security teams: the algorithms your organization relies on today have an expiration date. The question is whether you will be ready when it arrives.

Harvest now, decrypt later: why the risk is already here

Quantum computing does not need to reach full maturity to threaten your data. A strategy known as “harvest now, decrypt later” (HNDL) means adversaries are already collecting encrypted data with the intention of decrypting it once quantum capability arrives.

We know data is being stolen now for decryption later. Attackers do not need to breach your systems directly. They can intercept encrypted traffic from the internet and store it until quantum computing makes much of the currently deployed cryptography breakable.

While is hard to provide irrefutable proof in any particular case, this is not a hypothetical thought experiment. Nation-state actors are known to be stockpiling encrypted data at scale. The targets include intellectual property, trade secrets, pharmaceutical research, financial records, healthcare data, and classified government communications. Any information that requires long-term confidentiality is at risk, because the data you transmit today could be readable within five to ten years. Maybe even sooner.

The implication is clear: quantum computing risk to cryptography is not a future concern. It is a present-day data protection issue. Organizations holding long-lived sensitive information, from patient records to proprietary research, face exposure right now.

The business case: why this is a board-level priority, not just an IT problem

The risk that quantum computing imposes on cryptography is not an infrastructure or security issue alone. It is a strategic business risk that belongs in the boardroom alongside AI governance and cyber resilience.

Consider the business exposure. When current cryptography becomes breakable, the consequences cascade across every function:

  • Intellectual property and data leakages: Trade secrets, personal and sensitive data becomes immediately exposed once a large enough quantum computer is developed. Moreover, they are already considered vulnerable due to the HNDL attack.
  • Revenue disruption: Payment systems, partner integrations, and digital commerce platforms that rely on the cryptosystems mentioned priorly, could become incompatible with new standards, forcing emergency upgrades or causing transaction failures.
  • Reputational damage: A quantum-enabled data breach affecting customer information would be devastating, particularly if the organization failed to take widely recommended preparatory steps.
  • Customer trust erosion: Clients and partners increasingly expect their vendors to demonstrate forward-looking security practices. Organizations without a quantum readiness plan risk losing business to competitors who can demonstrate preparedness.
  • Regulatory liability: As regulators begin requiring post-quantum readiness (covered in the next section), organizations without a documented transition plan face compliance gaps and potential penalties.

Security leaders are increasingly framing post-quantum preparedness as a top-three strategic risk. The cost of proactive planning is a fraction of the cost of reactive crisis response, and the organizations that start now will have a significant competitive advantage.

Regulatory and compliance pressure is building

Regulators are not waiting for Q Day. The compliance landscape around post-quantum readiness is already taking shape.

In the United States, the federal government has been among the most aggressive movers. National Security Memorandum 10 (May 2022) set the foundational policy, and the Office of Management and Budget’s Memorandum M-23-02, which remains in force, directs agencies to inventory and prioritize their cryptographic systems and develop funding estimates for migration. The timeline then tightened sharply: Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks” (June 22, 2026), directs agencies to move high-value assets and high-impact systems to post-quantum key establishment by December 31, 2030 and to post-quantum digital signatures by December 31, 2031, well ahead of the 2035 horizon that NSM-10 originally implied. The same order pushes the requirement into the supply chain, tasking the FAR Council with a rule requiring covered contractors to comply with PQC-incorporating FIPS by the end of 2030. NIST’s finalized standards (SP 800-208, FIPS 203, 204, and 205, published within the last few years, with HQC and Falcon selected for publication soon) provide the technical foundation for these migrations.

In Europe, the picture has two layers. The EU Cyber Resilience Act (in force since December 2024, with its main obligations applying from December 2027) requires manufacturers of products with digital elements to build in security by design and handle vulnerabilities throughout the product lifecycle, backed by penalties of up to €15 million or 2.5% of worldwide annual turnover and loss of EU market access for non-compliant products. The CRA is horizontal product-security law rather than a quantum-specific mandate, though its state-of-the-art and lifecycle requirements increasingly imply crypto-agility. The EU’s actual post-quantum timeline lives in the Coordinated Implementation Roadmap published by the NIS Cooperation Group in June 2025, which asks member states to begin their transition by the end of 2026, secure high-risk and critical-infrastructure systems by the end of 2030, and complete the migration as far as practicable by 2035. A proposed revision to the NIS2 Directive would go further, making PQC transition planning an explicitly named obligation rather than something inferred from general cryptography requirements.

Existing privacy regulations amplify the risk. Europe’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act both impose strict requirements around the protection of personal data. If encrypted data collected today is decrypted through a future quantum attack, organizations could face retroactive liability for failing to apply adequate safeguards at the time of collection. The regulatory exposure compounds with every month of inaction.

Regulators are already fast-tracking their timelines for post-quantum compliance. What is your cryptographic inventory? What is your prioritization plan? Where are you upgrading first? Organizations that cannot answer these questions face increasing scrutiny.

Industry spotlight: who faces the greatest exposure

While quantum computing represents a risk that affects every organization that uses cryptography, certain industries face outsized exposure.

Financial services sits at the front of the line. Banks, payment processors, and financial institutions rely on cryptography for every transaction. A break in RSA, ECDH, ECDSA, etc. would compromise payment processing systems, interbank communications, and customer financial data. The cost of emergency migration across globally distributed financial infrastructure would be staggering, and the reputational consequences of a quantum-enabled breach would be severe.

Healthcare faces a compounding risk. Patient records have regulatory protection requirements that extend for decades, making them prime targets for HNDL attacks. A scenario where attackers gain access to millions of patient records through decrypted historical data creates a no-win situation: organizations face ransom demands at unprecedented scale plus regulatory fines for the exposure. Healthcare organizations also face the added complexity of legacy systems and medical devices with embedded cryptography that cannot be easily upgraded.

Any sector holding long-lived sensitive data should consider itself at elevated risk. Government agencies, defense contractors, legal firms handling privileged communications, and institutions that own intellectual property. All of them have information that must remain confidential for decades, and therefore, all of them fall into this category.

Why migration takes longer than you think

One of the most dangerous misconceptions about quantum readiness is that organizations can wait and then upgrade quickly once the threat becomes imminent. The reality is far more complex.

Industry estimates suggest that a full cryptographic migration takes approximately 10 years for most organizations. That timeline covers three phases: inventorying every cryptographic asset across the enterprise, prioritizing which systems to upgrade first, and executing (implementing and testing) the migration itself. This is not a simple software update. It requires replacing foundational infrastructure, from certificates and keys to PKI, hardware security modules and embedded device firmware. These algorithms have requirements and properties that are different to the classical schemes.

The G7 Cyber Expert Group and the U.S. Treasury Department have published phased recommendations that underscore the urgency. Organizations should have a planning framework in place by now, complete their cryptographic inventory by 2026, and begin prioritizing upgrades by early 2027.

The math is sobering. If the threat window is four to six years and migration takes ten, organizations that have not started planning are already behind. This is now tomorrow’s problem. The analogy I would use is the best time to plant a tree is 20 years ago;the next best time is today.

Where to start: building your quantum readiness plan

The first step is the same one that security experts and regulators agree on: know what you have.

Step 1: Cryptographic inventory and discovery.
You cannot protect what you cannot see. A comprehensive cryptographic inventory identifies every algorithm, certificate, key, and cryptographic library across your environment, including PKI infrastructure, machine certificates, APIs, code signing certificates, and embedded cryptography in IoT devices and open source code.

This is harder than it sounds. As Keyfactor’s CSO Chris Hickman has noted, “The problem we’ve seen most is that organizations still lack visibility. [Cryptography] is in everything, and now you’ve got to go find it.” Certificates and certificate authorities are distributed throughout systems, from individual IoT devices in the field to libraries embedded in compiled software.

Step 2: Prioritize high-risk systems.
Once you have visibility, rank your cryptographic assets by risk exposure. Systems protecting long-lived sensitive data, customer-facing transaction processing, and regulatory-critical infrastructure should move to the top of the migration queue.

Step 3: Execute the migration.
This includes updating implementations and devices, testing new deployments and updating procurement policies. Every new hardware and software purchase should include quantum-safe compatibility requirements. Organizations that continue purchasing systems with embedded vulnerable cryptography are extending their migration timeline and increasing costs.

Budget for a multi-year program.
Reactive migration after Q Day, when quantum computers will break these cryptographic algorithms, will cost significantly more than a planned, phased approach. Build quantum readiness into your annual security budget now, and frame it as risk reduction rather than discretionary spending.

How Keyfactor can help

The challenges outlined above, cryptographic discovery, certificate management, and algorithm migration, are exactly where Keyfactor’s platform delivers value.

Cryptographic discovery and inventory.
Keyfactor’s AgileSec has the ability to inventory certificate authorities from multiple points across the enterprise, connecting to appliances and applications on the back end to identify what certificates are present in those systems. This visibility is the essential foundation for any quantum readiness program.

Certificate lifecycle management.
Keyfactor’s Command includes a lifecycle manager for digital certificates that detects, finds, and brings them all in, managing them on an ongoing basis. This continuous management capability ensures that organizations maintain visibility as their environments evolve, rather than treating inventory as a one-time exercise.

Crypto-agility.
Federal mandates and industry best practices call for agility in dealing with cryptography, because the cryptographic landscape will continue to evolve even after migrating to PQC. Keyfactor also offers an open-source cryptography stack that allows organizations to implement post-quantum algorithms into their own custom software development, building flexibility into the migration process.

PQC Lab.
Organizations can explore post-quantum readiness through Keyfactor’s PQC Lab, which provides open-source toolkits, free trials, and resources to begin testing quantum-safe implementations.

Starting now with the right tooling is the difference between a managed transition and a crisis response. Keyfactor helps organizations turn an overwhelming challenge into a structured, executable program.

Got quantum computing risk questions? We’ve got answers.

What is Q Day and when is it expected to happen?
Q Day is the point at which quantum computers become powerful enough to break many of the cryptographic algorithms most businesses rely on today. Current estimates suggest this could occur as early as 2029 to 2030, based on the accelerating pace of quantum hardware development.

Which cryptographic algorithms are most at risk from quantum computing?
RSA, ECDH, ECDSA, etc., are the two public-key algorithm families most vulnerable to quantum attacks. These algorithms underpin much of internet security, payment processing, and enterprise communication.

What is a “harvest now, decrypt later” attack?
Adversaries collect encrypted data today and store it, planning to decrypt it in the future once quantum computing makes much of the current cryptography breakable. This means sensitive data transmitted now could be exposed years from now.

Is quantum cryptography risk only a concern for large enterprises?
No. Any organization that stores or transmits sensitive data, processes payments, or must comply with data privacy regulations faces quantum cryptography risk. Third-party and supply chain relationships also create exposure.

How long does it take to migrate to post-quantum cryptography?
Industry estimates suggest a full migration takes approximately 10 years, covering inventory, prioritization, and phased upgrades. Given that quantum threats may materialize within four to six years, organizations that have not started planning face significant time pressure.

What should my organization do first to prepare?
Start with a comprehensive cryptographic inventory: identify every algorithm, certificate, key, and cryptographic library across your environment. This foundational step informs prioritization and budgeting for the migration ahead.

What are NIST’s post-quantum cryptography standards?
NIST has finalized several post-quantum cryptographic algorithms, including ML-KEM and ML-DSA, designed to resist quantum attacks. These standards provide the target algorithms organizations should plan to migrate toward.

How does Keyfactor help with post-quantum readiness?
Keyfactor provides automated cryptographic discovery (identifying all certificates and algorithms across your infrastructure), certificate lifecycle management through PKI, and crypto-agility capabilities that enable organizations to transition to quantum-safe algorithms without disrupting operations.