European Affairs Correspondent
The awkward thing about quantum risk is that it does not wait politely for quantum computers to become useful. Encryption that looks secure today can still be copied, stored and left to mature in an adversary’s archive, which is why governments are now treating post-quantum cryptography as a migration programme rather than a theoretical seminar.[1][2][5][8] The threat is less cinematic than a machine instantly cracking the internet, and rather more bureaucratic: a long, expensive re-engineering of the systems that keep banking, government and private communications intact. That is not thrilling, but it is the sort of problem that tends to outlast the headlines.
NIST’s transition guidance says the goal is to move from quantum-vulnerable algorithms to post-quantum digital signature and key-establishment schemes, and that the work is meant to inform federal agencies, industry and standards organisations.[1][4][7][10] NIST expects ML-KEM, ML-DSA and SLH-DSA to provide the foundation for many deployments.[7][12] In other words, the American approach is already institutional rather than speculative. Cryptographic change is rarely a matter of swapping one acronym for another; it is a matter of testing, interoperability and avoiding the sort of elegant disaster that only a compliance officer could admire.
The UK’s National Cyber Security Centre has said migration to post-quantum cryptography is a multi-year effort.[2][5][8][11] In March 2025 it set milestones of 2028 for an initial migration plan, 2031 for highest-priority services, and 2035 for completion across systems and services.[5][8][11] That timetable is more than a list of dates; it is a quiet admission that the hard work begins long before a quantum attack is possible. The British state, never one to miss an opportunity for orderly alarm, is essentially telling organisations to inventory their cryptography now and hope they still know where the keys are stored by the time the locksmith arrives.
ETSI has published technical work showing that even if no post-quantum standards are yet in place, transition can begin by inventorying cryptographic components and the assets they protect.[3][6][9] It has also launched a quantum-safe hybrid key exchange specification called Covercrypt, designed to preserve security across both pre-quantum and post-quantum conditions through hybridisation.[9] The technical philosophy is sensible enough: do not wait for perfect certainty, because perfection is how migration projects go to die. The political subtext is more interesting, since standards often determine whose products are easy to buy, deploy and certify.
This is where the story stops being a narrow cybersecurity bulletin and becomes a question of industrial power. NIST’s process, the UK’s roadmap and ETSI’s work are defining the grammar by which future systems will be built.[1][2][3][5] For vendors, that means product roadmaps, updated certificates and a great deal of engineering work that will not look glamorous in a quarterly deck. For governments, it means trying to avoid a future in which critical infrastructure depends on cryptography that was known to be vulnerable years earlier.[1][2][5][8] Markets often move faster than regulation, but in security the opposite can be true: the standards tend to decide who gets to keep selling after the panic has passed.
The hardest part is that the evidence can never be complete in the present tense. One arXiv study on internet readiness suggests that the transition is uneven, while another paper on quantum, diplomacy and geopolitics points to a future in which government and military communications become especially exposed if large-scale quantum machines mature.[3][4] That is enough to justify planning, but not enough to justify melodrama. We still do not know when a cryptographically relevant quantum computer will arrive, and that uncertainty should be written into policy rather than airbrushed out of it.[1][2][4][8] The sensible question is not whether every encrypted message is already doomed, but which categories of data have a long enough shelf life to deserve protection now.
In practice, that creates a rather uncomfortable hierarchy of risk. Some traffic is short-lived and will be forgotten before quantum computers matter; some records — legal archives, health data, industrial designs and state communications — have a much longer shelf life and may need confidentiality measured in decades.[1][2][4][8] The phrase “harvest now, decrypt later” sounds like a security consultant’s flourish, but it captures a real asymmetry: attackers can wait, while defenders must migrate under budget, procurement and compatibility constraints. That is why PQC is not merely a technical upgrade but a governance problem, requiring inventories, vendor coordination and a willingness to spend before there is a visible crisis.[1][2][7][8]
There is also the matter of the internet’s habits, which are rarely designed with future-proof elegance in mind. TLS, public-key infrastructure and the embedded systems that depend on them were built for a world in which RSA and elliptic-curve cryptography were assumed to be long-term fixtures.[1][4][7][10] Replacing them will involve hybrid deployments, testing failures and a fair amount of temporary ugliness.[3][6][9] Cisco’s 2026 work on full-stack post-quantum cryptography architecture suggests the industry is already experimenting with end-to-end implementation.[2] Experiments, of course, are not the same as widespread deployment; the gap between a demonstration and a default setting is where most policy hopes go to acquire dust.
So the enduring lesson is not that quantum computing has made encryption obsolete, but that the timetable for trust now depends on migration discipline. The useful watchpoints are the same ones that tend to matter in any infrastructure transition: whether governments stick to their deadlines, whether major vendors ship interoperable support, whether standards bodies converge rather than fragment, and whether organisations can identify what they actually need to protect. Quantum computers may still be absent from the room; the strategic problem is that the locks are already being copied. That is a duller story than a cryptographic apocalypse, but it is also the one most likely to matter when the history is written.
References
References
Small numbered tags in the article body point to the sources below.
- Frequently Asked Questions about Post-Quantum Cryptography — Migration to Post-Quantum Cryptography documentation
- Setting direction for the UK's migration to post-quantum cryptography | National Cyber Security Centre
- TR 104 005 - V1.2.1 - Secure Element Technologies (SET)
- [PDF] MIGRATION TO POST-QUANTUM CRYPTOGRAPHY - NIST | NCCoE
- Timeline for PQC migration revealed
- ETSI releases two Technical Reports to support US NIST standards for post-quantum cryptography - ETSI
- Post-Quantum Cryptography | CSRC
- Migrating to post-quantum cryptography | National Cyber Security Centre
- ETSI launches new standard for Quantum-Safe Hybrid Key Exchanges to secure future post-quantum encryption - ETSI
- IR 8547, Transition to Post-Quantum Cryptography Standards | CSRC
- The UK’s National Cyber Security Centre Presents Timeline and Roadmap for PQC Migration
- NIST Post-Quantum Cryptography Standards: Complete Guide to FIPS 203, 204, 205 | QRAMM
PICKUP ARTICLES
Pickup Articles
-
Technology, Mystery & Disclosure
When the Brain Becomes the Interface: Technology’s Most Radical Promise Takes on a New Face
This article connects the trajectory of brain-computer interfaces to the regulation of neurotechnologies, the rise of non-medical uses, and debates over the privacy of brain data.
-
Technology, Mystery & Disclosure
The Deep Ocean Remains an Incomplete Map, and That’s Also a Political Choice
This article connects deep ocean exploration with the allocation of attention, funding, and scientific infrastructure.
-
Technology, Mystery & Disclosure
Why GPS Is Freely Available Worldwide: The Trade-offs Between Military Systems, National Policy, and Global Standards
This article outlines the policy trajectory of GPS evolving from a military dual-use system to a globally free service. It examines the cessation of Selective Availability in 2000,