TL;DR: Quantum computing will eventually break today’s public-key encryption, forcing businesses to migrate to post-quantum cryptography before “harvest now, decrypt later” attacks mature. The practical response is to inventory cryptographic assets now, pilot NIST-standard algorithms, and treat crypto-agility as a board-level resilience requirement.
The Threat Is Real, Even If the Machine Isn’t
Quantum computers capable of running Shor’s algorithm at scale remain years away, but the risk timeline is shorter than it appears. Adversaries are already intercepting and storing encrypted data, waiting for quantum decryption to catch up. The U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards in August 2024 — ML-KEM, ML-DSA, and SLH-DSA — giving enterprises a concrete migration target for the first time.
If you want to dig deeper, check out our guide on How to Choose the Right Running Shoe for Flat Feet.
Market Momentum
Analysts at McKinsey estimate the quantum technology market could reach $106 billion in revenue by 2040, with cybersecurity among the earliest commercial use cases. Meanwhile, MarketsandMarkets projects the post-quantum cryptography market will grow from roughly $0.3 billion in 2024 to over $3 billion by 2030, a compound annual growth rate near 30%. Spending is being pulled forward by regulation: the U.S. Office of Management and Budget has directed federal agencies to inventory cryptographic systems and begin migration planning, and the EU’s NIS2 and DORA frameworks push similar expectations onto critical-infrastructure operators.
What Experts Say
“The migration, not the quantum computer, is the hard part,” says Dr. Michele Mosca, co-founder of the Institute for Quantum Computing and a leading voice on cryptographic risk. Mosca’s widely cited inequality — if x + y > z, where x is migration time, y is shelf-life of data, and z is time to a quantum break — has become a planning heuristic for CISOs. Industry practitioners add a second warning: many organizations don’t know where their cryptography lives, buried in firmware, VPNs, HSMs, and third-party SDKs.
Predictions for the Next Five Years
Expect three shifts. First, crypto-discovery tooling becomes a standard line item in security budgets by 2026. Second, hybrid deployments — classical plus post-quantum algorithms — dominate early rollouts to avoid breaking legacy systems. Third, regulators will begin requiring documented quantum-readiness plans, turning cryptography from an engineering detail into a compliance artifact.
FAQ
Q: Do we need to act before a quantum computer exists?
A: Yes. Data with a long confidentiality requirement can be harvested today and decrypted later, so migration lead times — often 5 to 10 years — must start before the threat fully materializes.
Q: Which standard should we adopt first?
A: Most enterprises begin with ML-KEM for key establishment and ML-DSA for signatures, deploying them in hybrid mode alongside existing algorithms to preserve compatibility.
Q: What is the single most important first step?
A: Build a cryptographic inventory. You cannot migrate what you cannot find, and discovery typically reveals far more encryption than security teams expect.
Leave a Reply