{
  "id": 8081043,
  "title": "Daiwa and Deloitte break PQC implementation into manageable steps",
  "url": "https://urgent.news/2026/09/17/daiwa-and-deloitte-break-pqc-implementation-into-manageable-steps",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T19:00:46.000Z",
  "source": {
    "name": "SiliconANGLE",
    "slug": "siliconangle",
    "url": "https://siliconangle.com/2026/09/17/daiwa-deloitte-break-pqc-implementation-manageable-steps-digicertworldquantumreadinessday/"
  },
  "original_language": "en",
  "account": "Daiwa and Deloitte have broken down the process of implementing post-quantum cryptography (PQC) into manageable steps. Colin Soutar, managing director at Deloitte, emphasized the importance of treating PQC as a migration program rather than a physics problem. He suggested focusing on practical tests and staged planning to narrow down the issue and demystify the process. Soutar advised against using the term \"quantum\" as it could create a misconception that an expert background in physics is required to understand the necessary steps.\n\nSadaaki Yamazaki, senior security specialist at Daiwa Institute of Research, spoke about a hybrid approach tested in a development environment for Daiwa Securities' online trading system. The proof of concept involved a post-quantum-enabled load balancer to measure Transport Layer Security (TLS) performance, which showed a negligible impact on high-bandwidth data centers but increased TLS handshake time by approximately 1.2 milliseconds in such environments. This increase could be significant in wireless networks or constrained bandwidth settings.\n\nYamazaki highlighted that PQC implementation varies by cryptographic function, with key establishment and digital signature at different stages of readiness. He noted that while key establishment has been standardized (ML-KEM), hybrid key exchange such as X25519MLKEM768 is becoming available in products and platforms, providing security benefits by addressing the 'harvest now, decrypt later' risk. Enterprises face a prioritization challenge in implementing PQC due to the need for a complete inventory of its use across various systems and ownership, which can delay progress when systems and ownership are widely distributed. Soutar advised starting with iterative discovery around critical assets and systems instead of a full discovery right away.\n\nEnterprise public key infrastructure encompasses certificates, authentication, code signing, application programming interfaces, virtual private networks, and cloud services, all of which use cryptography across infrastructure and applications managed by different organization parts. Yamazaki emphasized that the difficulty lies not in replacing a single algorithm but in identifying where cryptography is used, understanding dependencies, and coordinating migration across the organization. From their perspective, while technology is part of the challenge, governance and cryptographic inventory are likely to be the larger challenges.",
  "summary": "PQC implementation becomes more manageable when organizations treat it as a migration program rather than a physics problem. As the post-quantum cryptography transition moves from discussion to implementation, organizations can test what is ready while planning around unresolved dependencies. Even straightforward technical changes can take years once budgets, products and governance enter the…",
  "key_points": [
    "Daiwa and Deloitte break down PQC implementation into steps",
    "Hybrid approach tested in Daiwa's online trading system",
    "PQC implementation varies by cryptographic function"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}