Sweden is treating the security threat from future quantum computers as a near-term cybersecurity problem, calling for organizations to begin moving toward quantum-safe encryption well before machines capable of breaking current systems exist.
The warning is one of the clearest operational priorities in Sweden’s first national quantum technology strategy, which sets policy goals through 2036 across quantum computing, sensing, simulation and communications.
While much of the strategy focuses on building research capacity and a domestic quantum industry, the cybersecurity section takes a different approach. It argues that migration away from vulnerable cryptography must begin early because replacing encryption across government agencies, businesses and critical infrastructure can take years.
The concern centers on public-key cryptography, the mathematical systems used to secure internet traffic, digital identities, software updates, financial transactions and other sensitive communications.
Today’s most widely used public-key methods rely on mathematical problems that are extremely difficult for conventional computers to solve. A sufficiently powerful quantum computer, however, could use quantum algorithms to solve some of those problems much more efficiently, potentially undermining widely deployed encryption and digital-signature systems.
No quantum computer capable of breaking modern cryptography at scale exists today. Sweden’s strategy nevertheless argues that the absence of such a machine does not remove the current risk.
One reason is the security problem known as “harvest now, decrypt later.” An attacker can collect encrypted information today and store it for years, waiting for future computing capabilities that could make the data readable.
That matters most for information that must remain confidential for long periods, including government communications, intellectual property, personal data and some national-security information.
For that reason, Sweden says quantum-safe cryptography needs to be deployed before a cryptographically relevant quantum computer becomes available.
Post-Quantum Cryptography Takes Priority
The strategy identifies post-quantum cryptography, or PQC, as one of the principal defenses against the future threat.
PQC does not require a quantum computer. Instead, it uses new mathematical algorithms designed to resist attacks from both conventional and quantum computers while running on existing computing hardware.
That distinction is important for large organizations because it makes PQC potentially deployable through upgrades to software, security protocols and digital infrastructure rather than requiring a new quantum communications network.
International standards bodies have already begun standardizing post-quantum algorithms for key establishment and digital signatures, giving governments and companies a clearer technical path for migration.
Sweden’s strategy links that international standards work with recommendations already issued by the country’s national cybersecurity authorities.
The government also connects the quantum transition to Sweden’s broader national cybersecurity strategy, suggesting that post-quantum migration will need to become part of routine security planning rather than remain a specialist issue for quantum researchers.
A migration can involve considerably more than replacing one encryption algorithm with another.
Organizations first need to identify where vulnerable cryptography is used across applications, networks, hardware, cloud services and supply chains. They then have to determine which systems can be upgraded, test new algorithms for compatibility and performance, and coordinate changes with outside suppliers and customers.
Legacy systems can make the process more difficult. Some industrial equipment, embedded devices and government systems remain in service for decades and may not have been designed for cryptographic upgrades.
The Swedish strategy therefore frames timing as a central problem. Even if large quantum computers remain years away, the transition process itself could take a similar amount of time.
Quantum Key Distribution Offers a Second Path
Sweden also identifies quantum key distribution, or QKD, as another technology for protecting communications.
QKD uses properties of quantum physics to exchange encryption keys and can allow users to detect certain attempts at interception. Unlike PQC, however, it requires specialized hardware and communications infrastructure.
The technology is commercially available but remains relatively early in its deployment, according to the strategy.
That makes it less practical as a broad replacement for existing encryption across ordinary business and government systems.
Instead, QKD could play a more specialized role in highly sensitive communications where dedicated infrastructure is justified.
The distinction reflects a wider split in quantum cybersecurity. PQC is generally aimed at securing the large installed base of classical networks and devices, while quantum communications technologies may eventually provide additional protection for selected high-value links.
Sweden’s strategy leaves room for both approaches but places immediate emphasis on preparing existing systems for quantum-safe cryptography.
Security Becomes Part of Quantum Policy
The cybersecurity focus also shows how national quantum strategies are expanding beyond research funding and computing hardware.
For governments, quantum technology now sits at the intersection of science policy, industrial competitiveness and national security.
Sweden’s broader strategy calls for protecting strategically important quantum technology while promoting responsible development and stronger international cooperation.
That could affect companies working not only on quantum computers but also on cybersecurity products, photonics, communications equipment, advanced electronics and other technologies needed to build or secure quantum systems.
The strategy does not announce a dedicated new budget for post-quantum migration. Instead, it establishes the transition as a national policy priority tied to existing cybersecurity programs and future implementation work.
That means much of the practical burden is likely to fall on government agencies, infrastructure operators and private companies as they inventory cryptographic systems and plan upgrades.



