Post-Quantum Cryptography Report for Professionals

Explore top LinkedIn content from expert professionals.

  • View profile for Dr. Robert Campbell, FBBA

    IBM Quantum-Safe Executive | PQC, AI Security & Federal Cryptographic Modernization | OpenAI Trusted Access for Cyber (TAC) Participant | Daybreak Blue Access | Former Naval Cryptology Officer | FBBA

    29,553 followers

    🚨 NEW PEER-REVIEWED RESEARCH: PQC Migration Timelines Excited to share my latest paper published in MDPI Computers: "Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks." The transition to Post-Quantum Cryptography (PQC) represents a watershed moment in the history of our digital civilization. Organizations planning for a 3-5 year "upgrade" will fail. The reality is a 10-15-year systemic transformation. Key Contributions: 📊 Realistic Timeline Estimates by Enterprise Size: Small (≤500 employees): 5-7 years Medium (500-5K): 8-12 years Large (>5K): 12-15+ years ⚠️ Critical Finding: With FTQC expected 2028-2033, large enterprises face a 3-5 year vulnerability window—migration may not complete before quantum computers break RSA/ECC. 🔬 Novel Framework Analysis: Causal dependency mapping (HSM certification, partner coordination as critical paths) "Zombie algorithm" maintenance overhead quantified (20-40%) Zero Trust Architecture implications for PQC 💡 Practical Guidance: Crypto-agility frameworks and phased migration strategies for immediate action. Strategic Recommendations for Leadership: 1. Prioritize by Data Value, Not System Criticality: Invert the traditional triage model. Systems protecting long-lived data (IP, PII, Secrets) must migrate first, regardless of their operational uptime criticality, to mitigate SNDL. 2. Fund the "Invisible" Infrastructure: Budget immediately for the expansion of PKI repositories, bandwidth upgrades, and HSM replacements. These are long-lead items that cannot be rushed. 3. Establish a Crypto-Competency Center: Do not rely solely on generalist security staff. Invest in specialized training or retain dedicated PQC counsel to navigate the mathematical and implementation nuances. The talent shortage will only worsen. 4. Demand Vendor Roadmaps: Contractual language must shift. Procurement should require vendors to provide binding roadmaps for PQC support. "We are working on it" is no longer an acceptable answer for critical supply chain partners. 5. Embrace Hybridity: Accept that the future is hybrid. Design architectures that can support dual-stack cryptography indefinitely, viewing it not as a temporary bridge but as a long-term operational state. 6. Implement Automated Discovery: You cannot migrate what you cannot see. Deploy automated cryptographic discovery tools to continuously map the cryptographic posture of the estate, identifying shadow IT and legacy instances that manual surveys miss. The quantum clock is ticking. Start planning NOW. https://lnkd.in/eHZBD-5Y 📄 DOI: https://lnkd.in/ejA9YpsG #PostQuantumCryptography #Cybersecurity #QuantumComputing #PQC #InfoSec #NIST #CryptoAgility

  • View profile for Malak Trabelsi Loeb

    Founder shaping quantum, AI, and space innovation. NATO SME. Driving high-stakes legal frameworks across national security, tech transfer, and policy at the frontier of sovereign systems. UNESCO Quantum100. 🇦🇪🇧🇪🇪🇺

    39,791 followers

    📌The financial sector has now moved from quantum awareness to quantum execution. Europol , FS-ISAC , and the Quantum Safe Financial Forum (QSFF), together with major financial institutions, published: “Prioritising Post-Quantum Cryptography Migration Activities in Financial Services” ; a practical migration framework designed specifically for financial institutions. What makes this report particularly relevant for #boards, #regulators, and #CISOs? It introduces a structured prioritisation methodology based on two measurable dimensions: 1️⃣ Quantum Risk Score Derived from: • Shelf life of protected data • Exposure • Severity of compromise 2️⃣ Migration Time Score Derived from: • Solution availability • Execution cost and time • External dependencies Migration Priority is determined by combining both scores into a risk–time matrix (see pages 8–10) of the Report below ⬇️ . ♨️ This shifts the conversation from “When will Q-Day happen?” to “Which business use cases require action now, and which require long-term orchestration?” Two examples in the report illustrate this distinction: 🔹 Points of Sale (#PoS) Medium quantum risk but high migration complexity due to hardware lifecycles, ecosystem coordination, and standardisation uncertainty (pages 12–15) . ⛔️Early planning is essential to avoid costly out-of-cycle replacements. 🔹 Public Websites (#TLS_confidentiality) Medium quantum risk but low migration time due to hybrid schemes such as X25519MLKEM768 already supported by major browsers and CDNs (pages 16–19) . ⛔️This is one of the earliest practical deployment opportunities for quantum-safe protection in production environments. Another important contribution of the report is its focus on cryptographic antipatterns (pages 21–24) . Before large-scale PQC migration, institutions can implement no-regret actions: • Automate TLS certificate lifecycle management • Standardise TLS configurations (TLS 1.3 baseline) • Eliminate legacy cipher dependencies • Remove hard-coded credentials • Strengthen key management governance This approach aligns closely with supervisory expectations: #quantum_readiness must integrate into existing risk frameworks, asset lifecycle planning, and vendor coordination. For financial institutions, the message is clear: ❌Quantum safety is not a single migration event. ❌It is a prioritised, staged governance programme that integrates cryptography, procurement, architecture, and regulatory alignment. Full publication: Europol (2026), Prioritising Post-Quantum Cryptography Migration Activities in Financial Services Available via Europol Publications Office: https://lnkd.in/d2bgsVKm #PostQuantumCryptography #PQC #QuantumRisk #FinancialServices #CybersecurityGovernance #DigitalResilience #CryptoAgility #QuantumTransition #FinancialStability

  • View profile for Marin Ivezic

    CEO, Applied Quantum | Author, PostQuantum.com | Quantum Systems Integration, Quantum Security & Post-Quantum Cryptography (PQC) | ex-Fortune Global 500 CISO/CTO & Big 4 Partner

    35,527 followers

    We just published the full Applied Quantum PQC Migration Framework - the complete methodology for migrating enterprise cryptography to post-quantum standards - freely, under Creative Commons (CC BY 4.0). https://pqcframework.com The framework is an 8-phase lifecycle covering everything from executive mandate and business case through discovery, CBOM, risk scoring, roadmap, pilots, infrastructure modernization, and vendor governance. It includes cross-cutting sections on crypto-agility architecture, maturity models, metrics, regulatory mapping, and skills. It comes with four sector-specific extensions: - Financial Services (banking, payments, capital markets) - Telecommunications - Government & Defense - Critical Infrastructure / OT This is not another repackaging of NIST guidance or a theoretical migration model. I embedded some hard-earned lessons into it. The framework in parts deliberately diverges from conventional industry approaches where practical experience has shown they don't work. E.g. minimum-viable CBOM, risk-driven discovery scoping, vendor governance first. When I take these more pragmatic positions, I defend each one with evidence, and importantly, we've worked with regulators who have accepted and in some cases adopted these approaches. If you've been reading PostQuantum.com, you know I've always shared what I've learned openly - the articles on CBOM, crypto-agility, hybrid cryptography, vendor governance, the "Rethinking" series. This framework is the most structured version of that same commitment: putting the complete methodology out there so practitioners can use it, adapt it, and build on it. Publishing under CC BY 4.0 means anyone can use it - including commercially - with proper attribution. No ambiguity about where this work originates. If you're a CISO figuring out how to start, a program manager staring at a multi-year migration, a security architect navigating hybrid deployment, or a consultant helping clients get quantum-ready - this is for you. https://pqcframework.com #pqc #postquantum #quantumsecurity #quantumready #quantumresistance #pqcframework #pqcmigration #pqcmigrationframework

  • View profile for Alexander Leslie

    National Security, Defense & Cyber Intelligence | Senior Advisor, Recorded Future | Government Affairs, Strategic Communications & Executive Engagement | Cybercrime, Espionage & Influence Operations

    13,154 followers

    Recorded Future released a new Executive Insights Report that examines quantum risk through a practical security and policy lens, focusing less on speculative timelines and more on the consequences unfolding today. One of the most important points is that quantum risk does not begin with the arrival of a cryptographically relevant quantum computer. In many respects, it has already started. “Harvest now, decrypt later” activity fundamentally changes how organizations should think about sensitive data. The compromise occurs at the point of collection, even if decryption remains years away. For governments, critical infrastructure operators, defense contractors, and firms handling long-lived intellectual property, the exposure horizon is measured in decades. That dynamic has broader implications than encryption alone. Public-key cryptography quietly underpins digital trust across modern economies. The eventual disruption of those trust anchors would challenge the integrity assumptions embedded across global digital infrastructure. What makes the issue significant is the mismatch between uncertainty and infrastructure permanence. There is still no definitive timeline for cryptographically relevant quantum computers, but many systems being deployed today will remain operational long enough to encounter them. That means current decisions are becoming future security liabilities or future resilience advantages depending on how organizations prepare. The policy environment is beginning to reflect this reality. Post-quantum cryptography is moving from research priority to governance expectation. Over time, this will likely evolve into a market differentiator. Organizations able to demonstrate cryptographic agility and credible migration planning may increasingly be viewed as lower-risk partners across government and critical infrastructure ecosystems. There is also an operational dimension that deserves more attention. The convergence of AI-enabled automation with quantum-enhanced optimization has the potential to compress defender response windows substantially. The organizations most exposed may not be those lacking sophisticated security tooling, but those carrying accumulated security debt, rigid architectures, and slow remediation cycles. The encouraging reality is that the core mitigation pathways are already visible. Cryptographic inventory, crypto-agility, supplier scrutiny, and prioritization of long-lived sensitive data are actionable steps that can be pursued now, well before quantum capabilities mature. In that sense, quantum preparedness is becoming less about predicting “Q-Day” and more about institutional adaptability. The organizations and governments that approach this transition early will likely experience it as a managed modernization effort. Those that delay may eventually confront it as a compressed operational and regulatory crisis.

  • View profile for Alex Pruden

    CEO/Co-Founder, Project Eleven | Post-Quantum Security for Digital Assets | fmr. Aleo, a16z, US Army Special Forces

    1,970 followers

    Trillions of dollars in digital assets are currently secured by cryptography that quantum computers will break. Project Eleven just released The Quantum Threat to Blockchains: 2026 Report, written with my co-author Conor Deegan. The core finding: Q-Day, when quantum computers can crack today's cryptography, could arrive by as soon as 2030. However, our model places Q-Day timing at a baseline of 2033, with optimistic and pessimistic scenarios at 2030 and 2042. Three major developments in the past year have accelerated the field: - Google, along with several other quantum hardware teams, have demonstrated quantum error correction below critical thresholds - Breaking Bitcoin's cryptography now requires as few as 10,000 physical qubits, and could be possible in as little as 9 minutes - Recent advances in error correction and algorithm optimizations have dropped resource requirements by orders of magnitude This report breaks down the quantum computing landscape, blockchain vulnerabilities, NIST post-quantum standards, and what migration actually requires. The trajectory of quantum development potentially follows a "nothing-and-then-all-at-once" exponential curve. Small improvements in error correction or qubit connectivity may compound to create feedback loops that may collapse the timeline with little warning. Blockchains face a unique challenge. Traditional systems can more easily rotate keys when necessary, compared with blockchain addresses that in some cases hold $B under the same keys for years. Migration across distributed networks could take up to a decade, which is longer than we may have under our baseline model forecast. The window to act is narrowing. Migration to quantum-resistant cryptography is no longer optional. It's imperative for any blockchain-based digital asset network expected to secure value into the future. Report link here: https://lnkd.in/djrnd2mD

  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 20,000+ direct connections & 55,000+ followers.

    55,148 followers

    NIST – Migration to Post-Quantum Cryptography Quantum Readiness outlines a comprehensive framework for transitioning cryptographic systems to post-quantum cryptography (PQC) in response to the emerging threat of quantum computers. Quantum technology is advancing rapidly and poses a significant risk to current public-key cryptographic methods like RSA, ECC, and DSA. This guide aims to assist organizations in preparing for and implementing PQC to safeguard sensitive data and critical systems. Key Points  The Quantum Threat Quantum computers are expected to disrupt cryptography by efficiently solving mathematical problems that underpin widely used encryption and key exchange methods. This would render current public-key systems ineffective in protecting sensitive data, emphasizing the need for cryptographic agility.  NIST PQC Standards NIST is spearheading efforts to standardize quantum-resistant algorithms through an open competition and evaluation process. These algorithms, designed to withstand quantum attacks, focus on two primary areas: 1. Key Establishment: Protecting methods like Diffie-Hellman and RSA key exchange. 2. Digital Signatures: Securing authentication processes.  Migration Framework The document provides a phased approach to migrating cryptographic systems to PQC: 1. Assessment Phase:    - Inventory cryptographic dependencies in current systems.    - Evaluate systems at risk from quantum threats based on sensitivity and lifespan. 2. Preparation Phase:    - Conduct pilot testing of candidate PQC algorithms in existing infrastructure.    - Develop a hybrid approach that combines classical and post-quantum algorithms to ensure interoperability during transition. 3. Implementation Phase:    - Replace vulnerable cryptographic methods with PQC in a phased manner.    - Ensure scalability, performance, and compatibility with existing systems. 4. Monitoring and Updates:    - Continuously monitor the effectiveness of implemented solutions.  Challenges in PQC Migration - Performance Impact: PQC algorithms often have larger key sizes, increased latency, and greater computational demands compared to classical algorithms. - Interoperability: Ensuring smooth integration with legacy systems poses significant technical challenges.  Best Practices - Use hybrid encryption to maintain compatibility while testing PQC algorithms. - Engage in collaboration with vendors, industry groups, and government initiatives to align with best practices and standards. Conclusion The transition to post-quantum cryptography is a proactive measure to secure data and communications against future threats. NIST emphasizes the importance of starting preparations immediately to mitigate risks and ensure a smooth, efficient migration process. Organizations should focus on inventorying dependencies, piloting PQC solutions, and developing cryptographic agility to adapt to this transformative technological shift.

  • View profile for Jaime Gómez García

    Global Head of Santander Quantum Threat Program | Chair of Europol Quantum Safe Financial Forum | Quantum Security 25 | Quantum Leap Award 2025 | Representative at EU QuIC, AMETIC

    18,258 followers

    ✏️CEPS (Centre for European Policy Studies) has just published the report "Strengthening the EU transition to a quantum-safe world" This 125-page publication offers a comprehensive and very timely analysis of the global transition toward quantum-safety, highlighting key recommendations and identifying the hurdles that we, as a community, still need to overcome. Accross its 10 general recommendations and 16 additional sector-specific ones, two key aspects take a prominent role: 👉 Operational challenges of the transition, like establishing business-level priorities, building executive support, addressing the limited cryptographic talent issue, cryptographic homogeneization in products, and building cryptographic inventories based on priorities. 👉 Coordination and the role for regulators, identifying that the EU lacks a coherent, unified transition framework, the need to ensure alignment and coherence across roadmaps and the risks of a fragmented transition. Key conclusions on the later, aligned with previous statements from the Europol Quantum Safe Financial Forum and FS-ISAC, is that quantum-safety is already part of the EU's operational resilience compliance through the “state of the art” security principle embedded in GDPR, DORA, CRA and NIS2. However, there is a recognised need for further guidance that can be achieved through open collaboration between the public and private sector. Although the report focuses on the financial, public, and defence sectors, its main takeaways can easily be extended to other critical domains—transport, energy, healthcare, and many more. The principles are the same, and the urgency is the same. This report is an important step forward, and my hope is that the ideas it lays out help shape the conversations and, more importantly, the actions we need across the EU. A well-aligned and coordinated transition is essential if we want the whole ecosystem to move toward a new age where we manage cryptography in a more mature, proactive, and resilient way. Kudos to CEPS, lorenzo pupillo, Carolina Polito, Swann A. and Afonso Ferreira, PhD for achieving this milestone. https://lnkd.in/dpWJ86q2

  • View profile for Marcos Carrera

    💠 Chief Blockchain Officer | Tech & Impact Advisor | Convergence of AI & Blockchain | New Business Models in Digital Assets & Data Privacy | Token Economy Leader

    32,490 followers

    🚨Quantum computing is no longer a theoretical debate for blockchain. It is becoming a strategic infrastructure risk. After reading the latest Coinbase Independent Advisory Board report on Quantum Computing & Blockchain, I believe there are 3 critical points every executive in digital assets, banking and blockchain infrastructure should understand: 1️⃣ The real quantum threat is NOT today… but waiting is dangerous One of the strongest conclusions of the report is surprisingly balanced: 👉 the cryptographic collapse is not imminent 👉 but preparing late would be a massive mistake Breaking current blockchain cryptography requires a fault-tolerant quantum computer (FTQC), something enormously more complex than today’s machines. But here is the critical insight: Migration to post-quantum security may take a decade or more across: • blockchains, wallets • exchanges, custodians • validators, institutions NIST is already recommending PQ migration strategies before 2035. This means the strategic problem is no longer “if”. It becomes: “How do we migrate global blockchain infrastructure without breaking scalability, performance and trust?” 2️⃣ The biggest blockchain challenge is NOT encryption. It is consensus. Most people think the problem is simply replacing wallets signatures. The report explains the real issue is much deeper. Modern blockchains depend heavily on: • BLS aggregation • threshold signatures • validator synchronization • consensus-level cryptography And today… There is NO clean post-quantum replacement for many of these systems. This is critical because: • Ethereum • Sui • Aptos • many PoS chains depend on aggregation mechanisms that quantum-safe cryptography still struggles to replicate efficiently. Meaning: Post-quantum migration may require redesigning parts of blockchain consensus itself. Not just changing wallets. 3️⃣ Quantum simulation may become the hidden accelerator of the threat This is probably the most important strategic takeaway in the entire paper. The report explains that the main commercial driver for quantum computing is NOT breaking crypto. It is: financial, liquidity and reserve business Why does this matter? Because if quantum simulation becomes economically valuable, investment and hardware progress could accelerate dramatically. And cryptographic capabilities would emerge as a byproduct. In other words: The future quantum risk to blockchain may not come from “hackers”. It may come from successful industrial adoption of quantum computing itself. My conclusion? The blockchain industry needs to stop treating post-quantum security as a theoretical research topic. This is becoming: • a governance problem • an infrastructure problem • a migration problem • a consensus architecture problem And the organizations that begin preparing now will likely become the trusted infrastructure providers of the next era of digital finance. Alfredo Joaquim John David

  • View profile for Prof. Dr. Ingrid Vasiliu-Feltes

    Quantum AI Governance I Deep Tech Diplomacy, Investments, Strategy & Orchestration I Cyber-Ethics by Design I DT, DLT & Web 3 Architecture I Board Chair & Advisor I Vice-Rector I Editor I Speaker

    54,865 followers

    EY’s perspective on securing against #quantum #risks emphasizes that quantum #computing is rapidly evolving from a theoretical concern into a material cybersecurity threat that requires immediate strategic action. The core issue lies in the vulnerability of widely used cryptographic algorithms, such as RSA and elliptic curve cryptography, which could be broken by sufficiently advanced quantum computers. This creates a systemic risk to sensitive data, including financial information, intellectual property, and personal records. A central concept highlighted is the “harvest now, decrypt later” threat model, in which adversaries collect encrypted data today with the intention of decrypting it in the future as quantum capabilities mature. This makes quantum risk a present-day problem, particularly for data requiring long-term confidentiality. EY stresses that organizations must adopt a proactive and structured approach to quantum readiness. A foundational step is to conduct a comprehensive cryptographic inventory, identify sensitive #data, and map existing #encryption methods. This enables organizations to assess which systems are most exposed and prioritize remediation efforts. Transitioning to post-quantum cryptography (PQC) is a complex, multi-year transformation that requires careful planning, integration into existing #technology roadmaps, and alignment with emerging standards. Organizations are encouraged to build crypto-agility, allowing them to adapt encryption methods as technologies and standards evolve. EY also highlights the importance of #governance, #compliance, and #workforce readiness. Quantum resilience requires enterprise-wide coordination, including policy development, regulatory alignment, continuous monitoring, and personnel training. EY frames quantum cybersecurity not just as a technical upgrade but as a strategic #transformation initiative. Organizations that act early can strengthen resilience, improve cyber maturity, and gain a competitive advantage, while those that delay risk long-term exposure to data breaches, regulatory challenges, and erosion of #digital #trust.

  • View profile for Jen Easterly

    CEO, RSAC | Former Director, CISA | Cyber + AI | Leader | Speaker | Innovator | Optimist | #MoveFast&BuildThings

    127,678 followers

    🔐Word o’ the Day | Year | Decade: Crypto-agility, Baby! Yesterday morning, I did a fun fireside chat with Bethany Gadfield - Netzel at the FIA, Inc. Expo in Chicago. We talked about cyber resilience, artificial intelligence, Rubik’s cubes, and that thing called quantum! A question came up at the end, “What can firms actually do today to begin transitioning to post-quantum cryptography?” So thought I would take the opportunity to share my thoughts more broadly on this important, but not super well understood, topic: 1. Don’t wait. The clock for quantum-safe cryptography is already ticking. NIST released its first set of post-quantum standards last year (https://lnkd.in/esTm8uPw) and CISA put out a “Strategy for Migrating to Automated Post-Quantum Discovery and Inventory Tools” last year as part of its broader Post Quantum Cryptography (PQC) Initiative (https://lnkd.in/evpF4umv). h/t Garfield Jones, D.Eng.! 2. Inventory & prioritize. Map all cryptographic usage: what keys, certificates, protocols, and data streams exist today? Which assets hold long-lived value and are at risk of “harvest-now, decrypt-later”? Build a migration roadmap that prioritizes highest-risk systems (e.g., financial settlement platforms, inter-bank links, legacy encryption). 3. Establish crypto-agility. Ensure your architecture supports swapping algorithms, updating certificates, & layering classical + post-quantum primitives without a full system rebuild. This kind of flexibility is key for resilience. 4. Pilot and migrate. Use the new NIST-approved algorithms; experiment first on less time-sensitive systems, validate performance and interoperability, then scale to mission-critical applications. NIST’s IR 8547 report provides a framework for this transition. 5. Vendor & supply-chain alignment. Ask your vendors & service providers: “What’s your PQC transition plan? When will you support NIST-approved post-quantum algorithms? Are your update paths crypto-agile?” If the answer isn’t clear or (as a former boss of mine used to say) they look at you like a “pig at a wristwatch,” you’ve got a potentially serious third-party risk. 6. Board and Exec engagement. Position this not as an IT problem but a fiduciary risk and resilience imperative. The transition to quantum-safe cryptography is multi-year and multi-layered—waiting until it’s urgent means it will be too late.

Explore categories