The Question at Hand
Your encryption keys protect everything from employee health records to customer payment data. Within the next decade, quantum computers may render those keys worthless. The question facing privacy officers isn't whether quantum computing will break current encryption standards, it's whether you should act now or wait for the threat to materialize.
This isn't a theoretical exercise. Organizations are making real budget decisions today about post-quantum cryptography (PQC) implementations. Some are building quantum-resistant systems now. Others are deferring investment until standards mature. Both camps have legitimate arguments, and the choice you make will shape your data protection posture for years.
The Case for Acting Now
The "harvest now, decrypt later" threat is real. Adversaries can capture your encrypted data today and store it until quantum computers become powerful enough to break the encryption. If your organization handles data with a long confidentiality horizon, medical records, trade secrets, government communications, waiting means accepting that today's encrypted data may be exposed in the future.
Early adopters point to the cryptographic migration timeline. When SHA-1 was deprecated, organizations spent years replacing it across systems. Transitioning to post-quantum algorithms will be more complex. You're not just swapping one algorithm for another; you're replacing key exchange mechanisms, digital signature schemes, and potentially rearchitecting how your systems handle larger key sizes and signature payloads.
Starting now gives you time to inventory your cryptographic dependencies, test PQC algorithms in non-production environments, and train your team before the transition becomes mandatory. The National Institute of Standards and Technology has already published its first post-quantum cryptographic standards. Organizations that begin hybrid implementations, running classical and quantum-resistant algorithms in parallel, can validate the new approaches while maintaining backward compatibility.
There's also a compliance angle. While GDPR’s requirement for Technical and Organisational Measures doesn't explicitly mandate quantum-resistant encryption yet, the principle of state-of-the-art security could be interpreted to include quantum readiness as the threat becomes more imminent. Early action demonstrates due diligence.
The Case for Waiting
The counterargument is equally pragmatic. Post-quantum cryptography standards are new, and new standards have implementation vulnerabilities. The first wave of PQC deployments will likely uncover edge cases, performance issues, and security flaws that aren't apparent in laboratory testing. Let other organizations find those problems first.
Resource allocation matters. Your team is already managing GDPR compliance, responding to data subject access requests, and implementing Technical and Organisational Measures for current threats. Adding a multi-year cryptographic migration project diverts attention and budget from immediate risks. Ransomware attacks and misconfigured cloud storage buckets are compromising data today. Quantum computers capable of breaking RSA-2048 are not.
The technology itself is still evolving. Quantum computers powerful enough to threaten current encryption require millions of stable qubits. Current systems have hundreds. The timeline for cryptographically relevant quantum computers remains uncertain, estimates range from 10 to 30 years. Investing heavily now means you might need to migrate again as standards and threat models evolve.
There's also a practical implementation challenge. Post-quantum algorithms produce larger keys and signatures. A classical digital signature might be 64 bytes; a quantum-resistant signature can be several kilobytes. That size increase affects network protocols, hardware security modules, and embedded systems. Rushing into deployment before your infrastructure can handle these changes creates new vulnerabilities.
Where Practitioners Actually Land
Most privacy officers are taking a middle path: preparation without full deployment. They're conducting cryptographic inventories to understand where encryption is used and which systems would be hardest to upgrade. They're monitoring NIST standards and vendor roadmaps. They're not ripping out existing systems, but they're ensuring new implementations can support post-quantum algorithms when needed.
The hybrid approach is gaining traction. Organizations are implementing systems that can run both classical and post-quantum algorithms simultaneously. This lets them validate PQC performance and compatibility without abandoning proven encryption methods. If a quantum-resistant algorithm shows unexpected weaknesses, they can fall back to classical encryption. If quantum threats materialize faster than expected, they can switch over without a complete system overhaul.
Industry sector matters. Financial services firms handling long-term sensitive data are moving faster than retailers with shorter data lifecycles. Government agencies subject to Restricted Data retention requirements are prioritizing quantum readiness. Healthcare organizations are weighing the 50-year confidentiality horizon of medical records against immediate operational pressures.
Our Take
Start planning now, but phase your implementation based on data sensitivity and retention periods. You don't need to migrate everything immediately, but you do need to know what you'll need to migrate.
Begin with a cryptographic inventory. Document every system that uses asymmetric encryption, digital signatures, or key exchange protocols. Identify which data has long-term confidentiality requirements. This inventory will guide your migration priority and help you estimate the actual cost and timeline.
For new systems or major upgrades, implement crypto-agility, the ability to swap cryptographic algorithms without redesigning the entire system. This protects you whether the quantum threat arrives sooner or later than expected. Build hybrid implementations where feasible, especially for systems handling high-value data with long retention periods.
Don't wait for a supervisory authority to mandate post-quantum cryptography. By the time regulations catch up to the threat, you'll be competing for limited vendor resources and specialized expertise. But don't let quantum readiness crowd out fundamental security practices either. An organization with poor key management and no encryption at rest won't be saved by quantum-resistant algorithms.
The quantum threat is real, but it's not immediate. Use that window to prepare methodically rather than scrambling reactively or ignoring the problem until it's too late.



