Insight · Quantum security

Post-quantum cryptography: a 2030 plan for leaders.

Quantum computers will eventually break the public-key cryptography that protects almost everything you run. Australia has set a date. Here is how to get ahead of it without wasting money.

Published 5 October 20267 minute read

Why this is a board issue now

The Australian Signals Directorate (ASD) guidance on planning for post-quantum cryptography sets the end of 2030 as the point to stop using traditional asymmetric cryptography, such as RSA, Diffie-Hellman and elliptic-curve algorithms, and to move to approved post-quantum algorithms.

The reason it matters before a capable quantum computer exists is harvest now, decrypt later. An adversary can copy your encrypted traffic and data today and decrypt it once the technology arrives. If your data must stay confidential for five, ten or twenty years, such as health records, intellectual property, legal matters or national security information, it is already exposed.

What is changing

In August 2024, the US National Institute of Standards and Technology (NIST) published the first post-quantum standards:

  • ML-KEM (FIPS 203) for establishing shared keys, replacing RSA and elliptic-curve key exchange
  • ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures

Australian guidance points organisations to these algorithms at their strongest parameter settings, alongside larger symmetric keys and hashes such as AES-256 and SHA-384 or above. Symmetric cryptography is far less affected; the urgent work is on public-key cryptography.

Why migration takes years

  • Cryptography is everywhere: TLS, VPNs, certificates, code signing, databases, identity systems, devices and vendor products.
  • Much of it is inside software you do not control, so you depend on suppliers' roadmaps.
  • Post-quantum keys and signatures are larger, which can break assumptions in protocols, hardware and performance budgets.
  • Long-lived devices and embedded systems may need replacement, not an update.

A practical plan

  1. Build a cryptographic inventory. Find where public-key cryptography is used across applications, infrastructure, vendors and devices.
  2. Rank by risk. Prioritise systems that protect long-lived sensitive data or critical operations.
  3. Assess crypto-agility. Identify which systems can switch algorithms through configuration and which need re-engineering.
  4. Engage suppliers. Ask every critical vendor for their post-quantum roadmap and dates, and write it into contracts and renewals.
  5. Pilot hybrid approaches that combine classical and post-quantum algorithms where your platforms support them.
  6. Sequence and budget the migration across the years to 2030, aligned with your existing replacement cycles to avoid paying twice.
You cannot migrate cryptography you cannot find. Every credible plan starts with the inventory.

How we help

Our Quantum-Safe Readiness engagement delivers the inventory, risk ranking, crypto-agility assessment, vendor questions and a staged roadmap in three to four weeks, led by people with hands-on quantum computing expertise.

Sources

FAQ

Quick answers

Anything else? Email contact@sovereignsystemslabs.com.

What is the Australian deadline for post-quantum cryptography?

Australian Signals Directorate guidance sets the end of 2030 to stop using traditional asymmetric cryptography such as RSA and elliptic-curve algorithms.

Which algorithms replace RSA and elliptic curves?

The NIST post-quantum standards published in August 2024: ML-KEM for key establishment, and ML-DSA and SLH-DSA for digital signatures.

Is symmetric encryption like AES affected?

Much less. Larger key sizes such as AES-256 are considered resistant. The urgent problem is public-key cryptography.

Book a free strategy call