There’s a peculiar kind of risk in cybersecurity that most organizations aren’t wired to handle well. It’s the risk that shows up long before its consequences do—the kind where you have to act years ahead of any visible threat, or else lose the window entirely.
Post-quantum cryptography is exactly this kind of risk. And for regulated industries in particular, the window to prepare is narrower than the headlines suggest.
Let’s be clear about what we’re talking about. A sufficiently powerful quantum computer, running Shor’s algorithm, would be able to break the public-key cryptography that protects nearly everything today—TLS connections, VPNs, code signing, digital certificates, secure email, and much more. The RSA and elliptic-curve algorithms that underpin modern trust simply don’t hold up against a large-scale, fault-tolerant quantum machine.
We don’t have one of those yet, and nobody can pin the date with confidence. But the estimates have been moving in one direction. The Global Risk Institute’s annual survey of quantum experts finds a meaningful and growing share who consider a cryptographically relevant quantum computer plausible within about a decade, and in 2025 Google researcher Craig Gidney showed that RSA-2048 could in principle be factored with fewer than a million noisy qubits —roughly a twentyfold reduction from his own 2019 estimate. The hardware isn’t there yet, but the bar keeps getting lower. So how urgent is this, really?
The “Harvest Now, Decrypt Later” Problem
Here’s the part that trips up a lot of leaders. The threat isn’t only in the future—it’s already operating in the present.
Adversaries, including well-resourced nation-state actors, are believed to be collecting encrypted data right now, storing it, and waiting for the day when they can decrypt it. This is what security professionals call “harvest now, decrypt later.” If the data you’re transmitting or storing today will still be sensitive in ten or fifteen years, then it’s already exposed to this strategy—regardless of when quantum computers actually arrive. Notice that uncertainty about the timeline doesn’t rescue you here. If anything, it sharpens the point: the arrival date is beside the point when your data has a long shelf life.
Think about what that means for regulated industries specifically:
- Financial services. Account records, transaction histories, and customer financial data carry decades-long sensitivity. A breach decrypted in 2036 is still a breach.
- Healthcare. Medical records don’t expire. Data harvested today remains personally identifying and regulated under HIPAA and similar frameworks far into the future.
- Government and defense. Classified material and intelligence often carry sensitivity horizons measured in decades. This sector has, unsurprisingly, been the loudest voice pushing quantum readiness forward.
- Energy and critical infrastructure. Design documents, operational data, and control-system details retain strategic value for a very long time.
If any of this describes your organization, the “quantum is a decade away” framing is misleading. Your effective deadline isn’t when quantum computers arrive—it’s that date minus the sensitivity lifespan of your data.

The Standards Have Actually Landed
For years, “post-quantum” felt theoretical because there was nothing concrete to migrate to. That’s no longer true.
In August 2024, NIST finalized its first set of post-quantum cryptographic standards—FIPS 203, 204, and 205 —covering the ML-KEM key-encapsulation mechanism and the ML-DSA and SLH-DSA signature schemes. These are production-ready algorithms, not research proposals. The guessing game about which algorithms would win is largely over.
That matters because it removes the last good excuse for delay. Organizations can now plan real migrations against real standards—and regulators have set the clock. NIST’s transition guidance, IR 8547 , deprecates RSA and elliptic-curve cryptography after 2030 and disallows them after 2035. The NSA’s CNSA 2.0 suite sets quantum-safe milestones for U.S. national security systems beginning in 2027. The Quantum Computing Cybersecurity Preparedness Act of 2022 and OMB Memorandum M-23-02 push U.S. federal agencies toward readiness planning, and in Canada the federal government’s PQC roadmap calls for departmental migration plans by April 2026, high-priority systems migrated by the end of 2031, and everything else by the end of 2035. These obligations tend to cascade down to contractors and vendors across regulated sectors. Whatever the physics does, the compliance deadlines are already on the calendar.
The uncomfortable reality is that cryptographic migrations are slow. The move away from SHA-1 took the better part of a decade. Migrating away from RSA and ECC across an entire enterprise—every certificate, every embedded device, every legacy system, every third-party integration—will be harder and slower than most teams expect.
What Readiness Actually Looks Like
The mistake many organizations make is treating this as a future project to be scoped later. In practice, the early work is the most valuable work, and almost none of it requires waiting for anything.
- Build a cryptographic inventory. You cannot migrate what you can’t see. Most organizations have no comprehensive picture of where and how cryptography is used across their environment—which algorithms, which key lengths, which certificates, which entropy sources and random number generators, embedded in which systems and which vendor products. This discovery work is foundational, tedious, and frequently underestimated. Start here.
- Assess data sensitivity lifespans. Map your most sensitive data against how long it needs to stay confidential. Data with long sensitivity horizons that traverses public networks or sits in long-term storage is your highest priority for early attention, because it’s most exposed to harvest-now-decrypt-later.
- Establish crypto-agility. The single most useful architectural goal is the ability to swap cryptographic algorithms without rebuilding entire systems. Hard-coded cryptography is a liability. Systems designed so that algorithms can be updated cleanly will handle this transition—and the next one—far more gracefully.
- Don’t overlook keys and randomness. New algorithms don’t help if keys are generated from weak entropy or exposed in memory while in use. Your inventory should cover where keys come from—virtualized, containerized, and embedded environments are often entropy-starved—and how they’re protected at runtime. For long-lived, high-value secrets, high-assurance entropy sources and hardened key handling are worth evaluating as part of the migration.
- Pressure-test your vendors and third parties. Much of your cryptographic exposure lives in products and services you don’t control. Ask vendors about their post-quantum roadmaps now. In regulated industries, third-party risk is your risk, and “we hadn’t thought about it” is an answer you want to hear this year rather than during an audit.
- Prioritize and phase the migration. Nobody migrates everything at once. Sequence the work by risk—long-lived sensitive data first, followed by systems where a compromise would be catastrophic, then the broader estate. A phased plan tied to the sensitivity assessment turns an overwhelming problem into a manageable one.

A Word on Not Overcorrecting
It’s worth being honest about the flip side. This is a genuine risk that deserves genuine planning—but it isn’t a reason to panic, tear everything down tomorrow, or fall for “quantum-proof” claims that can’t be tied to a standard. The test for any quantum-security product is simple: which standard does it implement or conform to—NIST’s PQC standards for algorithms, SP 800-90B and entropy-source validation for randomness, FIPS 140-3 for modules—and where does it fit in your migration plan?
Technology that answers those questions clearly has a place in your architecture; technology that can’t deserves a harder look. And a rushed migration, however well intended, can introduce fresh vulnerabilities of its own.
The right posture is deliberate, not frantic. Understand your exposure, build the inventory, achieve crypto-agility, and migrate in a sequenced, tested way. Regulated industries especially should be moving with intent, because their data lifespans and compliance obligations don’t leave much room to start late.
Where Plurilock Fits
This is precisely the kind of problem we like—one that’s technically deep, easy to underestimate, and best handled by people who’ve done cryptographic migrations before rather than those learning on your dime.
Plurilock’s PKI services include a post-quantum readiness assessment . That makes sense, because public-key infrastructure is where quantum exposure is most concentrated—in certificates, signing keys, and the trust chains that hold everything else together. The assessment gets to the heart of the early, high-value work: discovering where cryptography and keys live in your environment, examining how those keys are generated and protected, mapping them against data sensitivity, identifying where crypto-agility is missing, and building a phased migration plan that fits your regulatory obligations and your timeline. We pair senior practitioners—including people who’ve navigated exactly these transitions in demanding government and enterprise settings—with the automation and integration muscle to actually move the work forward, not just document it.
The organizations that will handle the quantum transition well aren’t the ones that wait for a quantum computer to appear in the news. They’re the ones building their inventory and their plan now, while the runway still allows a deliberate migration rather than a rushed one. If your data will still matter in ten years, that runway is shorter than it looks. ■
Key Takeaways
-
A sufficiently powerful quantum computer running Shor’s algorithm would break the RSA and elliptic-curve cryptography protecting TLS, VPNs, code signing, certificates, and more—and while no one can date its arrival, expert estimates of when and how much hardware it takes keep coming down
-
The “harvest now, decrypt later” threat is already active: adversaries are collecting encrypted data today to decrypt once quantum computers arrive, so your effective deadline is that arrival date minus your data’s sensitivity lifespan
-
Regulated industries—financial services, healthcare, government, and critical infrastructure—hold data with decades-long sensitivity horizons, making them the most exposed and the most urgent
-
NIST finalized production-ready post-quantum standards (FIPS 203, 204, 205) in August 2024, NIST plans to deprecate RSA and ECC after 2030 and disallow them after 2035, and U.S. and Canadian government mandates now cascade readiness obligations to contractors and vendors
-
Real readiness starts now: build a cryptographic inventory, assess data sensitivity lifespans, establish crypto-agility, secure key generation and handling, pressure-test vendors, and phase the migration by risk—while insisting that any quantum-security product be tied to a standard and a validation path
Is your organization ready for the quantum transition before the runway runs out? Plurilock’s PKI services, including our post-quantum readiness assessment , help regulated industries discover where cryptography and keys live in their environment, map them against data sensitivity, identify missing crypto-agility, and build a phased, standards-based migration plan. Contact us to start building your inventory and your plan while the runway still allows a deliberate migration.



