There's a security threat sitting in your infrastructure right now that no patch will fix, no firewall will block, and no SOC will detect — because the attack has already happened. Adversaries with long-term ambitions are capturing encrypted traffic today and archiving it, waiting for the day a sufficiently capable quantum computer can break the public-key cryptography protecting it. The industry calls it "harvest now, decrypt later," and it means the migration clock started before most organisations noticed.
This isn't speculative anymore. NIST finalised its first post-quantum cryptography standards in 2024 — ML-KEM for key encapsulation, ML-DSA and SLH-DSA for digital signatures — and guidance points toward deprecating today's classical public-key algorithms by 2030 and disallowing them by 2035. Major browsers and cloud providers have already deployed hybrid post-quantum key exchange in TLS. The question for enterprise IT leaders is no longer whether to migrate, but how to run the migration as a structured programme rather than a panic.
Why This Is a Delivery Problem, Not a Crypto Problem
The mathematics is settled — standards bodies did that work. What remains is the least glamorous, most familiar kind of work in enterprise IT: a multi-year, cross-domain transformation touching every system that uses cryptography. Which is to say: nearly every system you have. TLS endpoints, VPNs, code signing, PKI, email, storage encryption, IoT firmware, payment flows, identity infrastructure, and thousands of embedded certificates nobody has inventoried since they were issued.
"PQC migration will look less like a security project and more like the Y2K programme — except the deadline is fuzzy, the scope is larger, and the systems are more interconnected."
The Data That's Already at Risk
Prioritisation starts with a simple question: which of your data must remain confidential beyond the early 2030s? Health records, financial data, intellectual property, government contracts, M&A material, and anything with a decade-plus confidentiality requirement is already exposed to harvest-now-decrypt-later — every day it transits classically encrypted channels. That data class defines your migration front line.
A Practical PQC Migration Roadmap
Phase 1 — Cryptographic Discovery (start now)
- Build a cryptographic bill of materials (CBOM): every algorithm, key length, certificate, and library across the estate
- Automate discovery — manual certificate inventories are outdated the day they're finished
- Map long-lived confidential data flows first; they carry the harvest-now risk
Phase 2 — Crypto-Agility (the real strategic goal)
- Refactor systems so algorithms are configuration, not code — the organisations that suffer most will be those with cryptography hard-wired into applications
- Prioritise vendor assessments: your PQC readiness is capped by your least-ready critical supplier
- Centralise certificate lifecycle management before the volume of re-issuance multiplies
Phase 3 — Hybrid Deployment
- Deploy hybrid classical + post-quantum key exchange on external TLS first — the pattern browsers and CDNs have already normalised
- Test performance: post-quantum handshakes carry larger keys and signatures, which matters for constrained devices and high-volume APIs
- Run PQC in parallel with classical crypto until interoperability is proven, then cut over domain by domain
What Leadership Should Ask This Quarter
Three questions expose an organisation's real readiness: Do we have a cryptographic inventory, or just a certificate spreadsheet? Which of our data must still be secret in 2035, and how is it protected in transit today? And which of our critical vendors have published a PQC roadmap? If the answers are "no," "unknown," and "none," the programme business case writes itself.
Post-quantum migration rewards early movers not because quantum computers arrive tomorrow, but because discovery, crypto-agility, and vendor alignment take years — and the harvest-now-decrypt-later clock is already running on your most sensitive data.
The organisations that treat PQC as a governed transformation programme — with an inventory, a roadmap, and executive sponsorship — will make the transition without drama. The ones that treat it as next year's problem will eventually run it as an emergency, at emergency prices.