Why this is a board issue now
The Australian Signals Directorate (ASD) guidance on planning for post-quantum cryptography sets the end of 2030 as the point to stop using traditional asymmetric cryptography, such as RSA, Diffie-Hellman and elliptic-curve algorithms, and to move to approved post-quantum algorithms.
The reason it matters before a capable quantum computer exists is harvest now, decrypt later. An adversary can copy your encrypted traffic and data today and decrypt it once the technology arrives. If your data must stay confidential for five, ten or twenty years, such as health records, intellectual property, legal matters or national security information, it is already exposed.
What is changing
In August 2024, the US National Institute of Standards and Technology (NIST) published the first post-quantum standards:
- ML-KEM (FIPS 203) for establishing shared keys, replacing RSA and elliptic-curve key exchange
- ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures
Australian guidance points organisations to these algorithms at their strongest parameter settings, alongside larger symmetric keys and hashes such as AES-256 and SHA-384 or above. Symmetric cryptography is far less affected; the urgent work is on public-key cryptography.
Why migration takes years
- Cryptography is everywhere: TLS, VPNs, certificates, code signing, databases, identity systems, devices and vendor products.
- Much of it is inside software you do not control, so you depend on suppliers' roadmaps.
- Post-quantum keys and signatures are larger, which can break assumptions in protocols, hardware and performance budgets.
- Long-lived devices and embedded systems may need replacement, not an update.
A practical plan
- Build a cryptographic inventory. Find where public-key cryptography is used across applications, infrastructure, vendors and devices.
- Rank by risk. Prioritise systems that protect long-lived sensitive data or critical operations.
- Assess crypto-agility. Identify which systems can switch algorithms through configuration and which need re-engineering.
- Engage suppliers. Ask every critical vendor for their post-quantum roadmap and dates, and write it into contracts and renewals.
- Pilot hybrid approaches that combine classical and post-quantum algorithms where your platforms support them.
- Sequence and budget the migration across the years to 2030, aligned with your existing replacement cycles to avoid paying twice.
You cannot migrate cryptography you cannot find. Every credible plan starts with the inventory.
How we help
Our Quantum-Safe Readiness engagement delivers the inventory, risk ranking, crypto-agility assessment, vendor questions and a staged roadmap in three to four weeks, led by people with hands-on quantum computing expertise.