Skip to main content

Post-quantum data security challenges and how you can brace for it right now

For half a century, the security of digital infrastructure has rested on a handful of well-understood mathematical assumptions, such as RSA and the discrete logarithm problem. That foundation is now running out of time. Quantum computers capable of breaking widely used public-key cryptography are not a threat right now, but the data protected by that cryptography is often meant to stay confidential for decades.

Adversaries are already practicing “harvest now, decrypt later,” and they don’t need a working quantum computer today. All they need is patience and a copy of your traffic.

Regulators have taken note. In France, ANSSI’s guidance in views on the post-quantum cryptography transition states that post-quantum resistance becomes a certification requirement for security products, with broader adoption expected by 2030. Similar timelines are emerging across Europe. Analysts are converging on the same horizon:

According to Postquantum Cryptography: Why You Need to Be Ready by 2030, the likelihood of a cryptographically relevant quantum computer existing by around 2030 is at 75%. Simultaneously, it advises security leaders to target that date for completing PQC planning, remediation, and execution. The result is a shift in perspective: post-quantum migration is no longer a research topic to monitor. It is an operational program that must start now.

In this evolving threat landscape, the challenge is not simply selecting new algorithms, but understanding where cryptography is embedded, how it is used and how to replace it safely.

Decoding the myth: The assumption about algorithm swaps

Instinctively, we assume the best way to treat this is a simple algorithm swap: replace RSA with a NIST-approved post-quantum alternative identified through the NIST Post-Quantum Cryptography Standardization Program, update a configuration file and move on.

That assumption does not survive contact with real infrastructure. Cryptography is not a single control that can be updated centrally: it is embedded in protocols, certificates, hardware modules, firmware, third-party libraries and legacy systems that were never designed to be touched again.


Migration is a multi-year change program, not a patch cycle. If organizations treat it as the latter, they will discover the gap the hard way.

Handled well, though, this migration is also an opportunity. Every organization that is forced to touch its cryptographic estate in this depth should leverage the occasion to build crypto-agility. This is the ability to swap algorithms and parameters without re-architecting the systems around them, so that the next transition – whenever it arrives – is a simple update rather than another multi-year program.

Four shifts leaders need to make right now

Shift #1: Visibility comes before action.

Most organizations cannot produce an accurate inventory of their cryptographic assets: which algorithms are in use, where certificates are deployed, which protocols rely on them and which third-party components introduce cryptographic dependencies.

Building this inventory is not a simple or straightforward task, but it is a prerequisite for migration. Without it, estimating scope, cost and sequencing become largely guesswork.

Shift #2: Symmetric and asymmetric cryptography demand different responses.

Quantum computing does not threaten all cryptography equally.

Symmetric algorithms such as AES face a quadratic speedup from quantum attacks, addressed by increasing key sizes and parameters, not by making a major change. Public-key cryptography is a different problem entirely: the mathematical structures underpinning RSA and elliptic-curve systems are precisely what quantum algorithms are built to break. There is no parameter tweak that fixes this. It requires replacing the mechanism itself: new key exchange protocols, new signature schemes, and every certificate chain and protocol handshake that depends on them.

Treating these two categories as one workstream underestimates the harder half of the problem.

Shift #3: The new candidates are still earning trust.

NIST finalized its first post-quantum standards in 2024 after years of public evaluation and continues to assess additional candidates through its post-quantum cryptography standardization program.

Confidence in a cryptographic scheme takes decades to build, not years. This summer, a significant weakness was identified in HAWK, one of the signature schemes still under evaluation for the additional signature schemes, leading its designers to withdraw it from the process as reported by The Hacker News.

The episode illustrates a broader point: post-quantum cryptography is progressing rapidly, but it is still accumulating the long-term scrutiny that established algorithms such as RSA and elliptic-curve cryptography have already undergone. This is not a reason to delay migration, but rather it becomes the reason to migrate carefully.

Shift #4: Hybrid may be the safer choice, but it is harder than it sounds.

This is precisely why European regulators like ANSSI recommend hybrid constructions during transition, as outlined in its views on the post-quantum cryptography transition. This includes combining a well-studied pre-quantum mechanism with a post-quantum candidate, so that overall security holds even if one component is later weakened.

The principle is sound, but the engineering is not trivial. Combining two cryptographic mechanisms securely, so the result is never weaker than its strongest component and does not silently degrade under edge-case failures, requires careful construction, not simple concatenation. Getting hybridization right is its own specialized discipline – one that many organizations will need to build or acquire.

From challenges to leadership direction

Post-quantum migration is often presented as a cryptography problem. In practice, it is a governance problem first. Decisions about prioritization, procurement, architecture and risk acceptance will determine the pace and success of the migration long before technical deployment begins.


Post-quantum migration should be governed as a standing risk program, not a project with an end date. Sequencing matters more than speed: data with long confidentiality requirements, such as health records, trade secrets, government communications and long-lived contracts, should be prioritized ahead of data with short shelf lives, since “harvest now, decrypt later” attacks are already underway against the former.

Procurement and architecture decisions should favor crypto-agility. Considering an NIST-reviewed candidate was withdrawn within months of new scrutiny, no organization should assume today’s chosen algorithm is the last one it will need to support. Systems built to change gracefully will absorb the next revision at a fraction of the cost of those that are not.

Finally, this is a moment to invest in underlying expertise, not just algorithms. Correct hybrid construction, accurate crypto-asset discovery and sound migration sequencing all depend on cryptographic engineering capability that is currently scarce.

Organizations that build or secure access to that expertise now will be the ones able to move deliberately rather than react under pressure later.

The program also deserves a place in board-level risk reporting, alongside other long-horizon exposures. Progress in this area is not naturally visible through conventional security metrics. There is no incident to point to, nor any breach averted in a dashboard. Leaders who ask for a standing view of crypto-asset coverage, migration sequencing and hybridization status will be better positioned to distinguish genuine progress from mere activity, and to hold the program accountable to the regulatory milestones already on the horizon.

Prepare for the future

Nobody can say when quantum computers will be capable of breaking today’s public-key cryptography at scale. Organizations can only control everything that comes beforehand: understanding their cryptographic assets, identifying what must be replaced and building architectures capable of evolving over time. If they can treat post-quantum migration as a resilience investment rather than a compliance exercise, they will be better prepared not only for the quantum transition, but for whatever cryptographic transition it is that follows.

Share this article

X IconLinked-in Icon

David Pointcheval

Chief Scientific Officer at Cosmian

View detailsof David Pointcheval >
  • Follow David Pointcheval on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Protecting what matters most in the AI economy