Businesses are being urged to prepare a quantum readiness roadmap well before a machine capable of breaking today’s encryption arrives, because replacing encryption across a large organization could take years. Security researchers and government agencies increasingly argue that companies waiting for a cryptographically relevant quantum computer to emerge may already have waited too long.
Chris Harris, EMEA technical director for data and application security at Thales, said that realization is changing how security teams approach the issue. He discussed the threat and how companies should respond in an interview with UC Today.
“It’s really the fact that we’ve moved from something that people saw as an if to something that people now understand is a when,” Harris said.
The Clock Is Already Running
Much of the groundwork for a transition is already in place. The National Institute of Standards and Technology finalized its first three post-quantum cryptography standards in August 2024. Known as ML-KEM, ML-DSA and SLH-DSA, the standards are designed to withstand attacks from sufficiently powerful quantum computers. That matters because many of the encryption methods used today, including RSA and elliptic curve cryptography, could eventually prove vulnerable to quantum algorithms.
Governments are also putting dates on the transition that can be integrated into the roadmap. The U.K.’s National Cyber Security Centre has laid out a phased migration plan that calls for organizations to identify where cryptography is used by 2028, complete high-priority migrations by 2031 and finish the shift to post-quantum cryptography by 2035. Those dates may seem distant, yet replacing cryptography is nothing like installing a routine software update. Encryption is woven through applications, networks, devices, certificates, cloud services and third-party products. In a large organization, simply figuring out where it is being used can become a substantial project on its own.
Harvest Now, Decrypt Later
One reason to start early is that attackers do not necessarily need a quantum computer today to take advantage of one tomorrow. They can collect encrypted information now, store it and attempt to decrypt it later if quantum computers become powerful enough to defeat the protection. The practice is commonly called “harvest now, decrypt later.”
Not all information carries the same risk because, for instance, a piece of encrypted data that loses its value within a few days or months may have little exposure to a quantum computer that arrives years from now. Information that needs to remain confidential for decades is a different matter. That could include intellectual property, government and defense information, medical records and pharmaceutical research. For organizations holding those kinds of records, the relevant question is not only whether their encryption is secure today, but how long the underlying information needs to stay secure.

Where to Begin, and What to Protect First on Your Quantum Readiness Roadmap
Harris said the first step in creating a quantum readiness roadmap is understanding where cryptography is actually being used. That may sound easy, but it can be (and most likely is) complicated. Encryption may be built into applications, devices, databases, APIs, cloud services, certificates and identity systems. It may also be buried inside software supplied by outside vendors.
A cryptographic inventory gives companies a map of those dependencies. That means identifying which algorithms are in use, where certificates and keys are stored, which systems contain sensitive or long-lived information and where the organization depends on third-party products. The work is likely to involve more than the security department. IT teams, application developers, procurement staff and business units may all control systems that rely on cryptography.
“You need to begin understanding where your cryptography lives because everything else depends on that,” Harris said, according to UC Today
Once companies know where their cryptography is located, they can decide which systems need attention first. The goal is not necessarily to replace every cryptographic system at once. Organizations can instead rank systems according to the sensitivity of the information they hold and how long that information must remain protected. Systems containing trade secrets, patient records, sensitive government information or other long-lived data would generally move higher on that list. Systems protecting information with a short useful life may be less urgent. That turns the transition into a risk-management exercise rather than an organization-wide technology replacement carried out on a single deadline.
Outside vendors will also play a large role, according to Harris. Most companies rely on software, hardware and cloud platforms they do not control, so organizations will need to understand when their suppliers plan to support post-quantum standards. Harris said businesses should begin asking vendors about those plans while testing post-quantum approaches in their own environments. Procurement and vendor reviews can include questions about support for NIST-standardized algorithms, migration schedules and hybrid systems that use existing and post-quantum cryptography together during the transition.
The transition is also an opportunity to address a broader problem that changing cryptography is difficult. Harris said organizations should work toward “crypto-agility,” or the ability to replace cryptographic algorithms without rebuilding entire systems. Rather than hardcoding a particular algorithm into an application, for example, companies can use modular cryptographic libraries and centralized management systems that make algorithms easier to replace.
Embedding that agility in your quantum readiness roadmap could prove useful well beyond the current quantum threat. Cryptographic standards change as weaknesses are discovered, computing power increases and new algorithms become available. A system designed to accommodate those changes could make the next migration considerably less disruptive.
For businesses beginning the process, the immediate job is relatively straightforward. Find the cryptography already in use, identify the information that needs protection the longest, ask vendors about their migration plans and begin testing the new standards. None of those steps requires a fault-tolerant quantum computer to exist today. In fact, that is the point. The work is intended to make sure organizations are prepared before one does.



