{
  "id": 553364,
  "title": "Preparing for post-quantum cryptography: Building a practical roadmap",
  "url": "https://urgent.news/2026/08/11/preparing-for-post-quantum-cryptography-building-a-practical-roadmap",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-11T09:44:15.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/preparing-for-post-quantum-cryptography-building-a-practical-roadmap"
  },
  "original_language": "en",
  "account": "The topic of post-quantum cryptography (PQC) has recently taken center stage, with organizations no longer questioning whether to prepare for quantum computing, but rather how swiftly they can migrate to new, quantum-safe cryptographic methods. As providers hasten their roadmaps, governments are setting new expectations and boards demand stronger assurances about cyber resilience. This urgency is evident across various fronts - Google and Microsoft have outlined roadmaps targeting 2029 as a key point in the shift to quantum-resistant cryptography, while the recent US Executive Order emphasizes the need for organizations to start preparing for the post-quantum era. Collectively, these actions are compressing the planning horizon and intensifying pressure on Chief Information Security Officers (CISOs) to move from strategy to execution.\n\nThis shift is mirrored throughout the industry. According to Gartner's 2026 CISO Role-Based Survey: State of the Union, less than a quarter of organizations have made significant progress toward quantum readiness, and only 8% possess a functional cryptographic inventory. Similarly, DigiCert's Quantum Readiness Outlook research reveals that while most IT and security leaders anticipate quantum computers could potentially crack current encryption methods within three to five years, only 7% report more than half of their digital certificates are already quantum-safe or hybrid. The primary obstacle organizations face is not comprehending the risks posed by quantum computing, but rather achieving readiness before today's encryption becomes obsolete.\n\nQuantum computing holds the potential to revolutionize science, medicine, and artificial intelligence. However, it also poses a significant threat to the asymmetric cryptography that safeguards digital identities, software, financial transactions, and communications. While the arrival of a cryptographically relevant quantum computer is a concern, the threat is more immediate as threat actors are reportedly adopting a harvest now, decrypt later (HNDL) approach. This strategy involves collecting encrypted data today with the expectation that it can be decrypted when quantum capabilities mature. According to our data, 84% of organizations believe at least some of their encrypted data is susceptible to HNDL attacks. Financial transaction records and banking data are identified as the most at-risk assets (58%), followed by cryptocurrency wallets and private keys (53%).\n\nFor CISOs, this underscores the importance of identifying systems that protect long-lived, high-value information and prioritizing migration efforts where the business impact would be most significant. Instead of attempting to replace every cryptographic system at once, the priority should be understanding where vulnerable cryptography exists within the business. The first step in any quantum readiness program should be discovery, which entails comprehending where vulnerable cryptography currently resides. Without a complete inventory of cryptographic systems and their associated business dependencies, organizations cannot prioritize risks, assess interdependencies, or develop a realistic migration strategy. Discovery also aids in identifying the systems protecting the most valuable assets, enabling security teams to allocate resources where they will have the greatest impact. Once this foundation is established, organizations can begin integrating quantum-resistant algorithms into existing infrastructure, testing interoperability, prioritizing critical systems, and cultivating crypto-agility to adapt to evolving standards. Ultimately, those organizations that succeed will be those that commence preparation now, rather than waiting for quantum computing to arrive. By identifying the unknowns within their cryptographic estate and developing a phased migration strategy based on business risks, CISOs can enhance resilience in the present while preparing for the cryptographic challenges of the future.",
  "summary": "Organizations must become quantum-ready before today's cryptography becomes tomorrow's liability.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}