Your encryption infrastructure faces a critical decision. The Cybersecurity and Infrastructure Security Agency (CISA) and the G7 Cyber Security Working Group have urged organizations to transition to post-quantum cryptography (PQC). You're deciding whether to act now or wait for broader market adoption. The quantum computing threat is real, and your decision on when and how to transition will shape your data protection strategy for the next decade.
This isn't about if you'll transition. It's about which path you'll take and when you'll start.
The Decision You're Facing
You need to determine your organization's transition timeline and approach. Do you start cryptographic inventory and planning now, wait for clearer industry direction, or defer until regulatory requirements force action? Each path has distinct risks and resource needs.
The G7 Cyber Security Working Group outlines five priorities for PQC transition: raising awareness of quantum risks, developing national strategies, advancing research and development for quantum-safe technologies, fostering public-private partnerships, and integrating PQC into cybersecurity requirements and procurement processes. Your decision will determine how you'll engage with these priorities.
Key Factors That Affect Your Choice
Data sensitivity and retention periods are crucial. If you're handling health records, financial transactions, or intellectual property with retention periods beyond five years, your exposure window is already open. Adversaries can harvest encrypted data now and decrypt it once quantum computers become capable.
Regulatory environment influences your timeline. If you're under sector-specific regulations that mandate cryptographic standards (financial services, healthcare, defense contractors), you'll face compliance deadlines whether you're ready or not. The fifth G7 priority specifically calls for integrating PQC into cybersecurity requirements and procurement processes.
Technical debt in your encryption stack affects transition complexity. Organizations with legacy systems and hardcoded cryptographic algorithms face longer, more expensive transitions than those with abstracted cryptography layers.
Supply chain dependencies limit your options. If your critical vendors haven't started their PQC roadmaps, you can't complete your transition regardless of your internal readiness.
Path A: Start Cryptographic Inventory Now
Choose this path if you meet any of these conditions:
- You retain sensitive data for more than five years
- You're subject to sector-specific security requirements
- You're a likely target for state-sponsored threat actors
- Your procurement cycles run 18-24 months or longer
Immediate actions: Catalog every system that performs encryption, authentication, or digital signatures. Document which cryptographic algorithms protect data at rest, in transit, and in use. Identify systems where you control the cryptographic implementation versus those dependent on vendor updates.
Map your data flows to understand where encrypted data crosses organizational boundaries. You'll need this inventory when you assess which systems require PQC migration first.
Engage vendors now about their PQC roadmaps. Ask specific questions: Which products will support hybrid cryptography (combining classical and post-quantum algorithms)? What's their testing timeline? When will production-ready implementations ship?
This path requires: Dedicated resources for 6-12 months of inventory work, budget for potential hardware upgrades (some PQC algorithms require more processing power), and executive sponsorship to prioritize this work against competing initiatives.
Risk profile: You'll invest resources before clear regulatory mandates emerge, but you'll avoid the rushed, expensive migrations that come with late action. You're trading upfront cost for reduced future risk.
Path B: Monitor and Prepare
Choose this path if:
- Your data retention periods are short (under three years)
- You're not in a regulated industry with specific cryptographic requirements
- Your systems use modern, updatable cryptography libraries
- Your threat model doesn't include nation-state adversaries
Immediate actions: Assign someone to track PQC developments quarterly. Monitor NIST's post-quantum cryptography standardization project for algorithm finalization and implementation guidance. Watch for regulatory signals in your jurisdiction.
Build PQC readiness into your technology refresh cycles. When evaluating new systems or major upgrades, ask vendors about PQC support. Don't make it a requirement yet, but gather information.
Establish a cross-functional working group (security, infrastructure, compliance, procurement) that meets quarterly to review PQC developments and reassess your timeline.
This path requires: Minimal dedicated resources now, but you need clear escalation criteria that trigger a move to Path A. Define these criteria explicitly: regulatory announcement, vendor PQC availability in your core systems, or evidence of quantum capability advances.
Risk profile: You're preserving resources for other priorities, but you're accepting the risk of compressed timelines if quantum capabilities advance faster than expected or if regulations arrive suddenly.
Path C: Participate in Public-Private Partnerships
Choose this path if you're a large enterprise, critical infrastructure operator, or technology vendor. The G7's fourth priority specifically calls for fostering public-private partnerships to share expertise and resources.
This isn't an alternative to Path A or B. It's an additional layer for organizations with resources to contribute to industry-wide solutions.
Immediate actions: Join industry working groups focused on PQC implementation in your sector. Financial services, healthcare, and telecommunications sectors have active consortia addressing quantum-safe transitions.
Contribute to open-source PQC implementation projects. Your engineering team's participation helps mature the tools you'll eventually depend on.
Engage with your national cybersecurity authority. CISA's involvement in the call to action signals that government agencies want private sector input on transition strategies.
This path requires: Senior technical staff time for working group participation, legal review of information-sharing arrangements, and executive commitment to collaborative approaches.
Risk profile: You're investing in ecosystem-level solutions that benefit everyone, including competitors. But you're gaining early visibility into implementation challenges and influencing standards that will affect your industry.
Summary Matrix
| Factor | Start Now (Path A) | Monitor (Path B) | Partnership (Path C) |
|---|---|---|---|
| Data retention | >5 years | <3 years | Any duration |
| Regulatory pressure | Sector-specific requirements | General compliance only | Critical infrastructure |
| Resource commitment | High (6-12 months FTE) | Low (quarterly review) | Medium (working group participation) |
| Timeline to action | Immediate | 12-24 months | Immediate (collaborative) |
| Primary risk | Early investment cost | Compressed future timeline | Shared competitive intelligence |
| Best for | Regulated, high-value targets | Standard enterprise | Large organizations, vendors |
Your cryptographic infrastructure decisions today determine whether you'll execute a planned transition or scramble through a crisis migration. The G7 and CISA wouldn't issue a call to action if the timeline weren't compressing. Choose your path based on your risk profile, but choose deliberately.



