The quantum threat may still be ahead, but the work to prepare for it has already started. The G7 says uncertainty over when a cryptographically relevant quantum computer will emerge is no reason for organizations to delay preparations.
On Sept. 3, 2026, the G7 Cybersecurity Working Group urged public- and private-sector organizations to begin post-quantum cryptography migration. The group cited “harvest now, decrypt later” risk, in which attackers collect encrypted information for possible decryption once sufficiently capable quantum computers become available.
The G7 call to action urges governments and organizations to begin the transition as soon as possible. Data that must remain confidential for years warrants particular attention because exposure can begin well before quantum decryption becomes practical.
Standards are ready, but migration will take years
Organizations already have standardized algorithms they can begin adopting. NIST finalized its first three PQC standards on Aug. 13, 2024: ML-KEM under FIPS 203 for key establishment, plus ML-DSA and SLH-DSA under FIPS 204 and FIPS 205 for digital signatures.
Recent research into the HAWK signature candidate shows why cryptographic designs continue to face scrutiny. HAWK’s developers withdrew it from NIST consideration on July 29 after Anthropic reported a mathematical vulnerability; NIST said the finding does not affect its finalized PQC standards.
Migration involves more than substituting one algorithm for another. Applications, certificates, hardware, protocols, key-management processes, and vendor products may require changes and interoperability testing.
There is no universal private-sector deadline. A January 2026 G7 financial-sector roadmap noted that guidance from several jurisdictions and standards bodies often points to 2035 as an overall migration target, while stressing that its timeline is non-authoritative. Large environments may need years for discovery, procurement, testing, and replacement work.
Finding vulnerable cryptography comes first
The first operational task is finding where vulnerable public-key cryptography is used. The G7’s June 2026 migration guidance recommends inventorying cryptographic use across systems, devices, network protocols, cloud services, software, hardware, and supply-chain dependencies.
That work should extend beyond public-facing certificates to SSH, VPNs, PKI, identity systems, signing services, HSMs, firmware, internally developed applications, and third-party products. Organizations can then turn the cryptographic inventory into a prioritized migration program:
- Build and maintain a cryptographic inventory. Record algorithms, implementations, cryptographic functions, asset owners, protected data, and available upgrade paths.
- Prioritize systems by risk. Address long-lived sensitive data, critical services, and assets with lengthy hardware or vendor replacement cycles first.
- Design for crypto agility. Reduce hard-coded dependencies so algorithms, keys, and implementations can be changed with less disruption.
- Set post-quantum requirements for vendors. Incorporate PQC readiness into broader third-party risk management by requesting cryptographic disclosures, dependencies, upgrade timelines, and support plans.
- Pilot and test PQC implementations. Validate performance, certificates, protocol behavior, compatibility, and interoperability before production deployment.
- Test incident response and recovery plans. Exercise cryptographic failures, key-management problems, vendor disruptions, and emergency replacement scenarios as part of a broader unified recovery strategy.
- Establish governance and track progress. Assign ownership, document exceptions, monitor vendor readiness, and keep inventories current as systems change.
Automated discovery can accelerate inventory work, but embedded cryptography may still require documentation reviews, configuration checks, code analysis, or vendor input. Early visibility gives organizations time to sequence upgrades and resolve dependencies before post-quantum migration becomes an emergency project.
Read more: As quantum readiness increasingly enters vendor reviews, organizations should also consider how security evidence is reshaping enterprise procurement and what proof they will require from suppliers.





