SecureWorld News

Quantum Security, Part 1: Post-Quantum Cryptography Isn't a 2035 Problem

Written by Neha Srivastava | Mon | Jul 20, 2026 | 6:05 PM Z

For years, quantum computing has been treated as a distant research problem, something that would "eventually" matter to cybersecurity, sometime in the 2030s. That assumption is now the single biggest risk in most organizations' security roadmaps.

Here's the uncomfortable truth: you don't need a working quantum computer to be at risk today. You need an attacker willing to wait.

The threats already taking shape: Harvest Now, Decrypt Later (HNDL) and future signature forgery

This is the reason post-quantum cryptography (PQC) can't wait for "someday."

While Harvest Now, Decrypt Later (HNDL) is already a concern—where attackers collect encrypted data today with the intent of decrypting it once cryptographically relevant quantum computers become available—organizations must also prepare for the future risk of digital signature forgery. Quantum computers capable of breaking widely used public-key algorithms could allow attackers to forge identities, impersonate trusted entities, sign malicious software, and undermine authentication, code signing, financial transactions, and software updates. Together, these threats underscore why organizations need to transition to PQC for both encryption and digital signatures.

Adversaries—nation-states, in particular—are already recording encrypted traffic and storing it. Not because they can decrypt it today, but because they're betting they will be able to eventually. The moment a cryptographically relevant quantum computer exists, the stored data becomes retroactively readable.

If your organization holds data with a long confidentiality shelf life, government records, defense communications, health data, financial records, IP, or critical infrastructure designs, that data may already be sitting in an adversary's archive, waiting for the key to unlock it.

You can't patch this after the fact. The only defense is making sure the data isn't decryptable in the first place, which means migrating before the threat becomes real, not after.

[RELATED: 2030 Clock Is Ticking: The Accelerated Post-Quantum Cryptography Mandate]

Why 'we'll deal with it later' doesn't work

Every executive asks a version of the same question: if quantum computers aren't practical yet, why spend now?

The answer comes down to one fact that consistently surprises leadership teams: cryptographic migration is not a software patch; it's a multi-year transformation.

Most enterprises are carrying:

  • Thousands of applications and millions of digital certificates

  • Legacy systems and industrial equipment with decade-plus lifecycles

  • Medical devices, connected vehicles, and OT environments

  • IoT infrastructure spread across global supply chains

None of this gets swapped out overnight. Real migration requires cryptographic discovery, dependency mapping, vendor coordination, hardware refresh cycles, compliance testing, and operational validation—a process most industries should expect to take years, not months.

Fact: Wait until quantum computers are commercially practical, and you've already run out of runway.

Why governments are treating this as a race

National governments aren't investing billions in quantum-safe cryptography as a hedge; they're treating it as core infrastructure protection. Defense, intelligence, energy grids, financial systems, healthcare, and telecommunications all depend on cryptography that quantum computing threatens to unravel.

This has become a genuine global competition; some call it the next space race. Nations leading the PQC transition will be the ones best positioned to defend their infrastructure and protect digital sovereignty when the threat matures.

And because modern security is a supply chain problem, this isn't contained to any one country or company. One vendor that fails to modernize can create a weak link that ripples through every organization downstream of it.

What organizations should actually do now

Waiting for certainty isn't a strategy; it's a delay tactic. The organizations that come out ahead will be the ones building crypto-agility: the ability to swap cryptographic algorithms without tearing down and rebuilding entire systems.

Here's the roadmap I'd walk any leadership team through:

1. Establish governance and executive sponsorship: Assign clear ownership, define roles, and build an enterprise-wide PQC strategy. This doesn't move without a mandate from the top.

2. Conduct a full cryptographic inventory: You can't migrate what you haven't found. Identify every use of RSA, ECC, and other quantum-vulnerable algorithms, and map how they're interdependent.

3. Assess business risk and prioritize: Classify data by sensitivity, identify business-critical systems, and specifically flag anything exposed to HNDL risk. Not everything migrates at once; prioritize by exposure.

4. Design for crypto-agility: Abstract cryptography out of hard-coded implementations, modernize key and certificate management, and enable hybrid cryptographic approaches so you're never locked into a single algorithm again.

5. Evaluate vendor and supply chain readiness: Push your vendors for their PQC roadmaps now. Build PQC requirements into procurement so readiness becomes a contractual expectation, not a hope.

6. Test and validate: Pilot NIST-standardized PQC algorithms in real environments. Validate performance and interoperability before you rely on them in production.

7. Execute the migration roadmap:  Start with high-risk systems, then move through PKI and identity infrastructure, applications, networks, and cloud services, tracking progress the whole way.

8. Operationalize it: Update security operations, monitoring, and incident response playbooks. Train your teams. Update the policies that assume today's cryptography is permanent.

9. Embed it into enterprise strategy: PQC shouldn't be a side project; it belongs in your enterprise architecture and technology lifecycle planning, not bolted on after the fact.

10. Measure and iterate: Define KPIs, run periodic readiness assessments, and keep refining as NIST guidance and regulatory expectations evolve.

The bottom line

We don't wait for a breach to install firewalls. We don't wait for ransomware to back up our data. We don't wait for an insider threat to build zero trust. Post-quantum cryptography deserves the same posture: prepare before the threat is real, not after.

The question every security leader should be asking isn't if their organization will migrate to PQC. It's whether they'll be ready when the transition becomes non-negotiable or scrambling to catch up while competitors who started early are already secure.

Next in this series (Part 2), I will cover the technical challenges of PQC migration, performance trade-offs, hybrid implementation pitfalls, and where most organizations underestimate the effort.

This article appeared originally on LinkedIn here.

 

To help security teams and leaders transition from panic to a practical roadmap, SecureWorld is bringing together the brightest minds in the industry for the SecureWorld Quantum Cryptography virtual conference on September 23, 2026. See details and register to attend here.