PREPARING FOR MIGRATION / BEGINNER

Why Post-Quantum Migration Starts Years Before A Quantum Computer Exists

Replacing cryptography takes many years, and some data stolen today will still matter later. Here is why preparation has to begin long before the threat arrives.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

No one has yet shown a quantum computer that can break the public-key cryptography in everyday use. Governments are still telling organisations to start replacing that cryptography now. That can look like a contradiction, but it follows from two simple facts: replacing cryptography across a large organisation takes years, and some of the data protected today will still need protecting when such a machine arrives.

This article explains both facts, uses a past algorithm change to show how long these transitions really take, and sets out what “starting early” means in practice. Later articles in this section cover each step in detail.

What Changes When A Quantum Computer Arrives

Security agencies use the term cryptographically relevant quantum computer, or CRQC, for a quantum computer powerful enough to break today’s public-key algorithms such as RSA and elliptic curve cryptography. These algorithms are used to agree encryption keys and to create digital signatures, so they sit underneath web traffic, VPNs, software updates, payment cards and identity systems.

As of October 2026, the US Office of Management and Budget describes a CRQC as “not yet known to exist” and says one could appear within the coming decade.1 When it does, two kinds of damage become possible. Recorded encrypted traffic can be decrypted, and signatures can be forged, which lets an attacker impersonate people, servers or software publishers.

NIST’s National Cybersecurity Center of Excellence (NCCoE) points to a particular weak spot: software images signed with a vulnerable algorithm on devices whose root of trust cannot be upgraded.2 A root of trust is the small set of keys and code built into a device that it trusts without question, for example to check that a software update is genuine. A device like that may be in service for many years after the algorithm it trusts has stopped being safe.

The Data Problem: Harvest Now, Decrypt Later

An attacker does not need a quantum computer today to cause harm later. They can copy encrypted data now and keep it until it can be decrypted. This is usually called harvest now, decrypt later, or store now, decrypt later.2 The Harvest Now, Decrypt Later article in The Quantum Threat section covers the attack in detail.

Michele Mosca’s well-known rule of thumb turns this into a planning test.3 Take the number of years your data must stay confidential and add the number of years your migration will take. If the total is longer than the time until a CRQC exists, some of your data will be exposed. The test shows that migration time is just as important as data lifetime, and migration time is the part an organisation controls.

  1. Data Is Sent Or Stored Today

    It is protected by a key agreed with RSA or elliptic curve cryptography.

  2. An Attacker Keeps A Copy

    Nothing can be read yet. Storage is cheap, so the copy can be kept for years.

  3. Migration Finishes, Or Does Not

    If your systems move to post-quantum key agreement first, data sent after the switch is protected against this attack. Data sent before it is not.

  4. A Capable Quantum Computer Appears

    Any recorded data that still matters can now be decrypted.

Why the start date matters. The exposure is decided when the data is sent, not when the quantum computer arrives.

Why Migration Takes So Long

Swapping one algorithm for another sounds like a configuration change. In a real organisation it rarely is. The NCCoE notes that an algorithm cannot be replaced until every component that has to process it is ready, and that protocols, schemes and infrastructure often need updating too.2 It also warns that almost all information systems lack crypto-agility, the ability to change algorithms without major rework, and that some components stay in service for a decade or more, giving electricity generation and distribution as an example.2

The NCCoE’s view is that the move to post-quantum cryptography is likely to be harder than past algorithm changes, and that without serious planning it could take decades to replace most vulnerable systems.2

A Lesson From SHA-1

The retirement of the SHA-1 hash function shows how slowly these changes move, even when the problem is well understood and the replacement is ready.

  1. SHA-1 Becomes A Federal Standard

    Published in FIPS 180-1.

  2. Web Certificate Issuance Mostly Stops

    New public web certificates move to stronger algorithms.

  3. First Public SHA-1 Collision

    Researchers at CWI Amsterdam and Google show a practical collision.

  4. Firefox Plans To Warn On SHA-1 Certificates

    Certificates chaining to public roots were to trigger an error that users could override.

  5. NIST Completes The Phase-OutUpcoming

    SHA-1 is removed from the last NIST-specified protocols.

SHA-1 from standard to retirement. Dates are from NIST, Mozilla and the SHAttered researchers.

SHA-1 entered federal standards in 1995.4 Public web certificate issuance using it mostly ended in January 2016, and Firefox planned to start showing an error for such certificates in early 2017.5 The first public collision was announced on 23 February 2017.6 NIST still set the final phase-out for 31 December 2030, which will make 35 years from first standard to scheduled retirement, and told module vendors they had eight years to submit updated products.4 That span covers the whole life of the algorithm, not only the move away from it. Counting only from the end of public web certificate issuance in 2016, the final phase-out still comes 14 years later.

SHA-1 is a single hash function. Post-quantum migration touches key agreement and signatures in almost every protocol an organisation uses, which is why the NCCoE expects it to be harder than past algorithm changes.2

The Replacements Already Exist

Organisations are not waiting for new algorithms. NIST has published three post-quantum standards: FIPS 203 (ML-KEM) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. OMB’s guidance notes that further schemes, such as FALCON and HQC, may follow.1 The open questions are about deployment: which systems can use the new algorithms, in what order, and with what help from suppliers.

That is why every major government roadmap begins in the same place. The CISA, NSA and NIST joint factsheet of 2023 asked organisations to build a quantum-readiness roadmap, prepare a cryptographic inventory, and engage their technology vendors.7 The official timelines article shows how those steps have since turned into dated milestones.

Footnotes

  1. Office of Management and Budget, “Execution of the Migration to Post-Quantum Cryptography” (M-26-15), 24 June 2026. whitehouse.gov ↩ ↩2

  2. NIST National Cybersecurity Center of Excellence, SP 1800-38B (preliminary draft), “Migration to Post-Quantum Cryptography: Quantum Readiness: Cryptographic Discovery”, December 2023. nccoe.nist.gov ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  3. M. Mosca, “Cybersecurity in an era with quantum computers: will we be ready?”, IEEE Security and Privacy, 2018; preprint IACR ePrint 2015/1075. eprint.iacr.org ↩

  4. NIST, “NIST Retires SHA-1 Cryptographic Algorithm”, 15 December 2022. nist.gov ↩ ↩2

  5. Mozilla Security Blog, “Phasing Out SHA-1 on the Public Web”, 18 October 2016. blog.mozilla.org ↩

  6. Google Online Security Blog (authors from CWI Amsterdam and Google), “Announcing the first SHA1 collision”, 23 February 2017. security.googleblog.com ↩

  7. CISA, NSA and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography”, 21 August 2023. cisa.gov ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.