Why Post-Quantum Cryptography Should Matter to Every Organization
Ken Russman, Director, Strategy and Risk

“PQC is a business resilience issue, not just a technology upgrade.“
Key Takeaways
- NIST has finalized its first post-quantum cryptography standards, and organizations should begin a phased migration to quantum-resistant cryptography.
- Long-lived sensitive information is one of the most immediate concerns because attackers can collect encrypted data now and attempt to decrypt it later.
- PQC readiness is not only an internal IT issue. An organization’s transition will also depend on software vendors, cloud providers, identity platforms, network devices, and other third-party technologies and services.
- Organizations can start now by identifying where their systems use quantum-vulnerable cryptography, assigning ownership, talking to key vendors, and incorporating PQC into normal technology refresh cycles.
You Do Not Need a Quantum Computer to Start Preparing
PQC is a business resilience issue, not just a technology upgrade. Organizations that begin planning now can better protect long-lived sensitive information, avoid costly disruption, and maintain customer and stakeholder trust as cryptographic standards evolve.
Most organizations do not need to complete a PQC migration tomorrow. They do need to understand where they rely on quantum-vulnerable cryptography.
Post-quantum cryptography, or PQC, refers to cryptographic methods designed to resist attacks from both conventional and quantum computers.1
That distinction matters because the transition has moved beyond theory. NIST finalized its first three PQC standards in 2024, and organizations should begin applying them now while NIST continues to develop additional standards.2
Waiting until quantum computers pose an immediate cryptographic threat would leave very little time to make those changes carefully.
The Risk Starts Before the Technology Arrives
NSA, CISA, and NIST have warned about “harvest now, decrypt later.” In this scenario, an attacker steals encrypted information today and stores it. If future quantum capabilities make it possible to break the quantum-vulnerable cryptography protecting that information, the attacker can attempt to decrypt it later.3
How long sensitive information needs to remain confidential is an important part of PQC risk.
Customer information, employee records, intellectual property, financial information, contracts, strategic plans, health information, Social Security numbers, and sensitive communications may need to remain confidential for years.
If the information is still valuable when quantum capabilities mature, protecting it is not just a future problem. evaluate vendor terms. The policy should make clear which tools, account types, and uses the organization has approved.
Your Vendors Are Part of the Migration
PQC planning also extends beyond your own environment.
Most organizations depend on third-party software, cloud providers, network equipment, identity platforms, managed services, and embedded technologies. Those systems may use encryption, certificates, authentication mechanisms, or digital signatures that the organization does not directly control.
Start with a direct question for critical vendors: What is your PQC roadmap?
Ask what they support today, what is on their roadmap, and how they plan to make PQC support available to customers.4
Organizations do not need every answer today. But they should know which vendors and systems their migration will depend on.
Start by Finding Where Cryptography Matters
Before building a PQC roadmap, organizations need to understand where they rely on quantum-vulnerable public-key cryptography.
That means identifying its use across hardware, software, and services, including certificates, key establishment, digital signatures, and authentication. Understanding where these cryptographic dependencies protect critical data and systems provides the foundation for risk-based PQC migration priorities.5
A useful inventory should show where cryptographic change would have the greatest business impact, which information has the longest confidentiality requirements, which systems will be difficult to replace, and where migration depends on a third party. ed uses from those that require approval. For uses that require approval, identify who can authorize the task and what review is needed.
Build PQC Into Work You Are Already Doing
Once organizations understand where cryptography matters most, leaders should treat PQC readiness as a business initiative.
That means prioritizing systems that protect long-lived sensitive data, engaging critical vendors, planning around normal technology refresh cycles, and making sure future technology decisions can support cryptographic changes with minimal disruption. Products, services, and protocols will need updates, and organizations will need to identify where their systems use quantum-vulnerable algorithms and plan to replace or update them.2
Many organizations, especially small and midsize businesses, can fold this work into existing cybersecurity planning, vendor management, budgeting, and technology refresh processes instead of creating a separate transformation program.
Practical steps include:
- Assign an executive owner for PQC readiness and include it in normal cybersecurity planning.
- Identify the sensitive information and business systems that must remain trustworthy for many years.
- Ask critical vendors whether they have a PQC roadmap and whether their products support, or will support, NIST’s PQC standards.
- Use planned technology refreshes to retire unsupported systems and reduce future migration friction.
- Include PQC expectations in vendor reviews, contract language, and risk registers—and, where material, in board-level cybersecurity reporting.
Starting early gives organizations time to make these changes through normal planning and technology refresh cycles rather than under pressure.
Some Industries Will Feel the Impact Differently
The impact of PQC will not look exactly the same in every industry. What matters is where cryptography protects information that needs to remain secure for years and where a future migration would be especially difficult or disruptive.
Healthcare. Patient records, medical research data, identity systems, portals, and encrypted clinical communications may need protection for many years. NIST specifically uses medical records as an example of confidential electronic information protected by encryption.1
Financial services. Banks, insurers, lenders, and payment firms depend on certificates, encrypted transactions, customer records, and signed data. NIST also identifies financial statements as an example of information protected by encryption.1
Government and defense suppliers. Sensitive mission, contract, identity, and controlled information may have long secrecy lifetimes. NSA notes that PQC preparation is especially important for sensitive information with long-term secrecy requirements.3
Manufacturing and technology. Product designs, source code, firmware updates, intellectual property, and connected devices often rely on digital signatures, certificates, and secure communications that may eventually require PQC migration.
Retail and professional services. Customer data, payment-related systems, supplier portals, websites, VPNs, and cloud services can all rely on quantum-vulnerable cryptography. Organizations will need to inventory those dependencies and plan how to update the affected systems and services over time.
Across industries, the same question applies:
Which data and systems will still depend on cryptographic protection years from now?
Don’t Wait Until It Becomes an Emergency
The transition to post-quantum cryptography will likely be gradual and will depend on vendors, budgets, contracts, standards, and normal technology refresh cycles. For some organizations, that migration could take 10 to 20 years.
No one knows exactly when a cryptographically relevant quantum computer will exist.1
Organizations that understand their cryptographic dependencies now will have more flexibility to address PQC through normal technology and risk-management processes instead of making those decisions under pressure.
References
1 NIST, “What Is Post-Quantum Cryptography?” https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography
2 NIST CSRC, “Post-Quantum Cryptography Project.” https://csrc.nist.gov/projects/post-quantum-cryptography
3 NSA, “Post-Quantum Cryptography: CISA, NIST, and NSA Recommend How to Prepare Now.” https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3498776/post-quantum-cryptography-cisa-nist-and-nsa-recommend-how-to-prepare-now/
4 CISA, “Quantum-Readiness: Migration to Post-Quantum Cryptography.” https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography
5 NIST NCCoE, “Migration to Post-Quantum Cryptography.” https://www.nccoe.nist.gov/applied-cryptography/migration-to-pqc