← Back to news
Archived · Published 7 August 2026
The Post-Quantum Migration Has Started, and Most Organizations Do Not Know What They Would Have to Change
The post-quantum cryptography transition is unusual among security migrations in that the replacement algorithms arrived before most organizations had any idea what they would need to replace. NIST finalized its first post-quantum standards in 2024 — ML-KEM for key encapsulation, ML-DSA and SLH-DSA for digital signatures — and browser and platform vendors moved comparatively fast, with hybrid post-quantum key exchange now widely deployed in mainstream browsers and major TLS libraries. That covers the visible layer. It does not cover the code signing pipeline, the VPN concentrator, the payment terminal firmware, the internal PKI issuing certificates nobody has audited in six years, or the embedded device that will still be in the field in 2035.
The threat model driving the timeline is not that a cryptographically relevant quantum computer exists today. It is "harvest now, decrypt later": an adversary who records encrypted traffic in the present and decrypts it once the capability arrives. That reframes the deadline in a way many risk assessments handle badly, because it means the relevant question is not when quantum computers arrive, but how long the data being transmitted today needs to stay confidential. For ordinary session traffic the answer is minutes. For health records, legal archives, state communications and long-lived intellectual property, the answer is decades — and for that data the migration is already late.
The practical blocker reported repeatedly by organizations that have started is inventory. Cryptography is not centralized in most enterprises; it is embedded in application code, third-party libraries, hardware appliances, and vendor products whose internals the buyer cannot inspect. Producing a cryptographic bill of materials — an actual list of what algorithms are used where, at what key sizes, under whose control, and with what upgrade path — routinely takes longer than the algorithm swap itself. Several national security agencies have converged on the same advice: start the inventory now, because it is the long pole, and it does not depend on any remaining standards work.
The vendor dependency is the part organizations control least. An enterprise can migrate its own code on its own schedule; it cannot migrate a hardware security module, a smart card, or an industrial controller whose manufacturer has not shipped post-quantum firmware. That has begun to show up in procurement language, with post-quantum upgrade commitments appearing as contract requirements rather than nice-to-have roadmap items — which is, in practice, the mechanism by which the migration will actually happen for the long tail of embedded systems that no security team can patch directly.
Defici Editorial · Tech News
This article was generated by Defici's AI editorial system.