Cryptography 2026+: waiting for the quantum threat to arrive is not a strategy
For several years, the threat quantum computing poses to cryptography was presented as a future problem. Executives could reasonably ask when a quantum computer powerful enough to compromise the cryptographic mechanisms that today protect communications, transactions, digital identities and a large share of the global economy’s sensitive data would appear.
In September 2026, that question still has no precise answer. We still do not know when a cryptographically relevant quantum computer will become operational. Estimates vary considerably, and the scientific and technical obstacles remain significant. Yet something fundamental has changed: organizations no longer need to wait for that machine to begin their transition.
The standards now exist and governments are publishing timelines. The bodies responsible for cybersecurity are asking organizations to inventory their cryptographic assets, map their dependencies and prepare their migrations. NIST now states clearly that the transition to the new post-quantum standards must begin. In Canada, this transformation already has concrete deadlines: the federal roadmap notably calls for migrating high-priority systems by the end of 2031 and all other systems by the end of 2035.
The strategic question has therefore changed. It is now a matter of determining whether organizations understand their current cryptographic environment well enough to be able to change it when standards, knowledge and risks change. This capability could become far more important than the search for the next algorithm we might hope to keep for several decades.
Cryptography is one of the most important and least visible infrastructures of the digital economy. It protects communications, authenticates users, secures connections, signs software and documents, protects financial transactions, secures virtual private networks, takes part in the functioning of cloud infrastructure and allows machines to verify the identity of other machines. It is omnipresent precisely because we rarely see it.
This invisibility is a considerable difficulty when a migration becomes necessary. An executive may know that their organization uses encryption without knowing precisely which algorithms are used, which systems they reside in, which libraries implement them, which vendors control them, which certificates depend on them or which applications would have to be modified if one of these mechanisms became inadequate.
Changing an algorithm in a laboratory environment can be relatively simple. Replacing it across hundreds of applications, devices, cloud services, APIs, industrial systems, certificates, legacy software and vendors can take several years. Cryptographic migration thus becomes as much a problem of architecture, governance and organizational knowledge as a strictly mathematical one.
This is precisely why the authorities now insist on the cryptographic inventory. The G7 Cyber Expert Group has called on public and private organizations to adopt a progressive, risk-based migration, including in particular an inventory of cryptographic assets, the identification of essential systems, the mapping of dependencies and the development of transition plans. Canada relayed this call in September 2026.
This evolution shifts the debate from the laboratory to the organization. The first difficulty is no longer necessarily choosing a post-quantum algorithm. It consists first in knowing where to find the cryptography that will eventually have to be replaced. An organization may discover RSA in certificates, ECDSA in digital signatures, various key exchange mechanisms in its VPNs, cryptographic libraries built into applications developed fifteen years ago, and other mechanisms embedded in equipment whose software it does not even directly control.
Some dependencies are immediately visible, while others are deeply buried in vendors’ products and services. This situation explains why the post-quantum transition also becomes a procurement question. An organization can have an excellent migration strategy and still be unable to execute it because an essential vendor does not yet support the new cryptographic mechanisms.
The Canadian Centre for Cyber Security has begun to build this issue directly into its contractual recommendations. It notably recommends that newly acquired cryptographic modules be able to support the appropriate post-quantum algorithms, and proposes clauses making it possible to build certain post-quantum capabilities into new purchases. This evolution is important, since preparing for the transition then begins well before the algorithms are actually replaced.
Equipment bought today may remain in service for ten or fifteen years, and some industrial systems may operate even longer. A strategic application may also outlive several generations of technology. Every new purchase incapable of evolving cryptographically therefore risks creating a debt that will have to be repaid at migration time.
This reality leads to a notion that is probably more important in the long run than the choice of any particular algorithm: crypto-agility. NIST defines this capability as the ability to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware and infrastructure while preserving security and continuity of operations. Behind this technical definition lies an idea of great strategic importance for executives: cryptography will change again.
History has already demonstrated this. Algorithms once widely used have been abandoned, key sizes have increased, hash functions have been replaced, protocols have evolved and some implementations have revealed vulnerabilities. The authorities’ recommendations have also changed as knowledge advanced. The post-quantum transition is therefore probably not the last cryptographic migration organizations will experience. It represents, rather, an opportunity to stop treating each migration as an exceptional event and to build a permanent capacity for adaptation.
Recent developments around HAWK illustrate this necessity particularly well. HAWK was a candidate for standardization as a post-quantum digital signature. After two years of review by human specialists, an experimental Anthropic model helped, in 2026, to discover in roughly 60 hours a significant improvement on the best known attack against the algorithm. Anthropic shared its results with the authors, and HAWK was then withdrawn from the standardization process.
This story must, however, be interpreted precisely. It in no way demonstrates that post-quantum cryptography is broken. NIST specified that the discovery concerning HAWK did not affect its finalized post-quantum standards, notably ML-KEM and ML-DSA, which rest on other mathematical constructions. It demonstrates, rather, that our ability to test cryptography itself is accelerating.
Artificial intelligence can help explore mathematical spaces, test hypotheses and search for certain weaknesses far more quickly. Cryptographers thus have new tools for stress-testing algorithms before they are deployed, while malicious actors will naturally seek to exploit the same capabilities. We therefore find the acceleration phenomenon that is progressively running through the whole of cybersecurity: when the tools for examining systems become faster, our ability to challenge, validate and possibly replace protection mechanisms must advance as well.
This acceleration further reinforces the value of crypto-agility. The most durable strategy consists less in betting that the algorithm chosen today will be perfect for thirty years than in building an architecture that makes it possible to replace it if knowledge advances. NIST itself applies a logic of diversification by developing several options resting on different mathematical families. ML-KEM is its primary mechanism for post-quantum key establishment, while HQC was selected as a complementary solution based on a different construction. This diversity aims precisely to preserve a fallback should a significant weakness one day be discovered.
Cryptographic resilience is thus beginning to resemble other forms of resilience: it seeks to avoid having all security rest on a single assumption. This consideration takes on added importance when we look at the risk known as Harvest Now, Decrypt Later. Data encrypted today can be intercepted and retained in the hope that a future technology will make it possible to decrypt it. The real risk factor then becomes the length of time the information must remain confidential.
Data whose value disappears in six months has a very different profile from a trade secret, a medical record, government intelligence or intellectual property that must remain confidential for twenty years. For certain information, the future quantum risk therefore already has a present-day dimension: the data can be collected today while its eventual decryption can wait.
This reality profoundly changes how a migration is prioritized. Not all organizations need to transform all their systems at the same time. They must, however, be able to identify the data whose confidentiality period could exceed the security lifetime of current cryptographic mechanisms. That requires knowing the information to be protected, where it is located, how it moves, which cryptographic mechanisms protect it and which vendors take part in that protection. Without this knowledge, establishing a rational priority becomes extremely difficult.
Cryptography is therefore progressively becoming a matter of risk governance. In Canada, this shift is already under way. The Canadian Centre for Cyber Security’s cryptographic recommendations now incorporate NIST’s new post-quantum standards and provide for the progressive withdrawal of several mechanisms vulnerable to quantum computing. We are no longer facing only an academic discussion about what might eventually replace current cryptography. The standards transition has begun, and organizations must now turn this evolution into operational capability.
It is precisely here that several difficulties will appear. A complete cryptographic inventory is far harder to carry out than an inventory of servers or computers. Cryptography can be present in applications, libraries, certificates, protocols, APIs, databases, mobile devices, industrial equipment, embedded systems and services provided by third parties. Once these assets are identified, the relationships among them must be understood.
Changing a certificate can affect an application, modifying a protocol can make a device incompatible, and replacing a signature mechanism can require changes at several business partners. An infrastructure migration can also require various vendors to move at the same pace. The real problem then progressively becomes one of Crypto Dependency Mapping. Knowing that an organization uses RSA is useful information; knowing precisely which business processes, applications, devices, partners and vendors would be affected by replacing it makes it possible to build a genuine transition plan.
This knowledge turns an abstract worry into operational decisions. Some organizations will have to prioritize the systems protecting data with a long confidentiality period, while others will start with their identity and signing infrastructure. Some will discover that their main constraints lie with their vendors, while others will have to modernize legacy applications before they can even consider a cryptographic migration. There is therefore no universal migration. Each organization must develop the capacity to prepare, prioritize and govern its own transition.
This distinction also makes it possible to avoid two reactions that would be equally problematic. The first would be to panic and seek to replace all existing cryptographic mechanisms immediately. The second would be to wait for the announcement of a sufficiently powerful quantum computer before starting to act. Between these two extremes lies a far more rational approach: inventory the assets, map the dependencies, assess the risks, prioritize the systems, build post-quantum requirements into new purchases, test migrations progressively and develop the crypto-agility needed to absorb future changes.
For IT and cybersecurity teams, this transition nonetheless represents an additional responsibility in environments that are already extremely complex. They must maintain current systems, manage vulnerabilities, support operations, integrate artificial intelligence, manage vendors and, at the same time, prepare a cryptographic transformation that may span a decade. Bringing in specialized expertise can then increase their capacity without replacing the deep knowledge they already have of their own environment.
It is from this perspective that Quantum Beyond can work alongside internal teams to turn post-quantum into an operational program rather than an abstract concern. A post-quantum readiness assessment makes it possible to establish the starting point, while the cryptographic inventory and Crypto Asset Discovery make it possible to identify the mechanisms actually in use. Crypto Dependency Mapping then reveals the relationships among these mechanisms, the systems, the processes and the vendors, while Crypto Risk Assessment and the analysis of Harvest Now, Decrypt Later exposure make it possible to set priorities.
Crypto-agility becomes the structuring capability of this approach, since it makes it possible to examine whether current architectures will really be able to change algorithms, protocols, components or vendors when that becomes necessary. Migration prioritization, the transition master plan and post-quantum governance then turn this knowledge into a roadmap that may span several years.
Above all, this approach makes it possible to avoid treating post-quantum as a purely cryptographic project handed over to a few specialists. The transition will affect procurement, contracts, vendors, architectures, applications, infrastructure, data, budgets and continuity of operations. It therefore progressively becomes a matter of corporate governance and, more broadly, of Hypersecurity, since it requires connecting cryptographic protection to resilience, dependencies, technological sovereignty and the organization’s permanent capacity for adaptation.
In September 2026, the conversation about post-quantum cryptography has changed in nature. NIST’s first standards are finalized and available for deployment. The Canadian government has a roadmap with concrete deadlines. The Canadian Centre for Cyber Security is incorporating the new standards into its recommendations, and post-quantum readiness is beginning to influence procurement decisions made today. The G7 is also calling on public and private organizations to inventory their cryptographic assets, map their dependencies and plan their transition.
At the same time, artificial intelligence is beginning to accelerate cryptanalysis itself. The withdrawal of HAWK after the AI-assisted discovery of a significant improvement on an attack is a particularly useful reminder: cryptographic knowledge will continue to evolve, and the algorithms we consider promising today will continue to be attacked, tested, improved and sometimes abandoned. This reality calls for preparation rather than panic.
The most durable strategy is now to know your cryptography well enough to be able to change it. That requires an inventory of assets, a mapping of dependencies, an understanding of how long data must remain confidential, an analysis of vendors, transition governance and, above all, an architecture that makes it possible to replace cryptographic mechanisms when knowledge, standards or risks change.
Quantum Beyond can strengthen internal teams in this work by bringing together post-quantum readiness, cryptographic inventory, Crypto Asset Discovery, Crypto Dependency Mapping, Crypto Risk Assessment, Harvest Now, Decrypt Later risk analysis, crypto-agility, migration prioritization and transition governance. The objective is to develop a durable capacity for adaptation that can serve the organization across several technology cycles, rather than to build a one-off response to a particular threat.
The strategic question of 2026 is therefore no longer only which algorithm will protect our data in 2035. It is whether the organization knows its systems, its data, its dependencies and its vendors well enough to be able to evolve when cryptographic knowledge changes again. An organization genuinely prepared for post-quantum will ultimately be the one that has learned a far more durable lesson: in cryptography, the best long-term protection also lies in the ability to change.
