Decoding the world of cybersecurity

Fragmented Quantum Timelines Are Leaving Long-Life Data Exposed

Fragmented post-quantum cryptography deadlines are leaving long-life data exposed. Daryl Flack, Partner at Avella Security, argues that boards must treat quantum readiness as long-term resilience.

Fragmented Quantum Timelines Are Leaving Long-Life Data Exposed
Summary
  • Governments are setting different post-quantum cryptography migration deadlines, creating overlapping compliance and operational timelines for multinational organisations.
  • “Harvest now, decrypt later” risk means long-life data may already be exposed, even where formal migration deadlines sit years away.
  • Boards, procurement teams, and suppliers need cryptographic inventories, crypto-agility, and clear accountability for quantum readiness.

By Daryl Flack, Partner at Avella Security

The post-quantum cryptography (PQC) transition is gathering momentum. Governments are publishing migration roadmaps, regulators are signalling future expectations, and technology providers are gradually starting to incorporate quantum-safe capabilities into their platforms.

However, organisational preparedness remains limited, and the gap between emerging requirements and current readiness is becoming increasingly apparent as governments set clearer expectations for migration. Most recently, the US introduced mandatory federal migration deadlines of 2030 for key establishments and 2031 for digital signatures across high-value and high-impact systems.

Organisations operating across different geographies have no choice but to navigate several competing quantum migration timelines simultaneously. This challenge is made significantly harder by the fact that many organisations have yet to begin meaningful preparation.

While organisations debate whether migration should begin in 2028, 2030 or 2031, adversaries are already operating on a completely different schedule. Their strategy is harsh, harvest encrypted information today and decrypt it later when quantum capabilities become available.

The threat operates on a different clock

Governments around the world recognise that post-quantum cryptography migration must begin now. The United States is driving towards the mandatory 2030 deadline. The European Union is encouraging critical infrastructure providers towards broadly similar timeframes.

The UK’s National Cyber Security Centre (NCSC) has adopted a phased approach, targeting discovery and planning by 2028, migration of priority systems by 2031, and full adoption by 2035. Germany has taken a more prescriptive stance, recommending that applications with very high protection requirements complete migration by 2030, while indicating the progressive deprecation of classical cryptography through the early 2030s. France has taken a different approach, increasingly linking quantum readiness to certification and procurement requirements, signalling that market access may become as important as regulation itself. Across Europe, certification schemes, procurement frameworks and sector-specific guidance are emerging to drive adoption through different mechanisms.

What this means is that multinational organisations are now expected to comply with overlapping regulatory expectations while coordinating migrations across thousands of applications, suppliers and interconnected systems. But the greatest challenge is that the lifespan of sensitive information rarely aligns with migration programmes.

Healthcare records may need to remain confidential for a century. Intellectual property can retain value for decades. Government archives, defence information, scientific research and critical infrastructure data all significantly outlive the technologies used to protect them.

The uncomfortable truth is that sensitive data does not care whether an organisation’s migration programme completes in 2030 or 2035. If adversaries have already copied it, the countdown has already started.

Fragmented timelines, enduring consequences

“Harvest now, decrypt later” attacks have become the defining post-quantum risk.

Attackers are not attempting to break today’s encryption immediately. Instead, they are collecting encrypted communications, databases and archives with the expectation that future quantum computers will eventually render current cryptographic protections obsolete.

Traditionally, security programmes have focused on defending systems in the present. Quantum computing introduces a new challenge, protecting information against attacks that may not fully materialise for another decade or more.

Every year of delayed migration increases the volume of encrypted information entering adversary-controlled archives.

Cryptographic discovery across large enterprises is not a six-month exercise. Encryption is deeply embedded throughout applications, operating systems, network protocols, Internet of Things (IoT) devices, cloud services and operational technology environments. Many implementations remain undocumented, inherited through acquisitions, or tied to legacy platforms that were never designed for crypto-agility.

By the time some organisations complete discovery, establish governance, align suppliers and prioritise migration activities, they may already be approaching the deadlines currently being discussed.

Fragmented global migration timelines only exacerbate this problem. Governments may disagree on implementation dates. Suppliers may operate to different roadmaps. Legacy systems may not be scheduled for replacement until the next investment cycle.

Meanwhile, the accumulation of long-life data by adversaries continues.

In effect, organisations are caught between multiple clocks, regulatory clocks, procurement clocks, technology clocks and quantum clocks. Attackers only need one of them to run out first.

Supply chains are becoming the critical dependency

The success of post-quantum migration will ultimately be determined by supply chains.

Modern enterprises depend on extensive ecosystems of cloud providers, software vendors, managed service providers, hardware manufacturers and critical infrastructure partners. Cryptography underpins every one of these relationships, from software updates and digital signatures to secure communications and authentication.

A financial institution may identify its cryptographic exposure and establish a PQC programme, but if a key software provider has not completed discovery or is working to a different timetable, risk persists. The same is true across healthcare, manufacturing, government and critical national infrastructure.

This challenge is amplified by a lack of visibility.

Most organisations are still attempting to answer a fundamental question. Where does cryptography exist across the estate?

Without that visibility, migration planning becomes significantly more difficult.

The challenge extends beyond internal systems. Organisations must also understand whether suppliers have established migration plans, whether contractual obligations need updating, and whether critical third parties are building quantum readiness into their own products and services.

Long-life data should determine priorities

Some sectors are further ahead than others.

Financial services are starting to invest in understanding the impact of PQC, driven by regulatory expectations, operational complexity and the need to protect high-value information. Work undertaken by international financial institutions has demonstrated that migration is technically achievable, but has also highlighted significant challenges around interoperability, supplier coordination and implementation at scale.

However, even the most mature sectors are not ready.

Across industries, many organisations have yet to identify which data assets require protection beyond 2035. That question should become one of the first considerations in every PQC programme.

Organisations should begin by asking:

  • Which information must remain confidential for ten, twenty or fifty years?
  • Where is that information stored, transmitted and shared?
  • Which suppliers process or retain it?
  • How quickly could cryptographic protections be replaced if standards evolve?
  • Who owns PQC readiness at the executive level?

The answers will often reveal that the most critical assets are not necessarily the newest systems, but the oldest and most enduring data.

Building resilience across fragmented timelines

The global transition to PQC was always expected to be one of the largest technology migrations organisations would undertake. Waiting for governments to align their approaches is not a viable strategy. 

Organisations should focus on building crypto-agility. The ability to replace cryptographic algorithms without extensive redesign. Procurement teams should incorporate quantum readiness into supplier assessments. Security teams should establish cryptographic inventories and identify long-life data requiring prioritised protection.

Most importantly, boards should recognise that quantum readiness is not simply another cybersecurity initiative. It is a long-term resilience programme spanning technology, procurement, governance and enterprise risk management.

The transition to post-quantum cryptography is often described as a race against quantum computing. In reality, it is a race against time itself. Governments may be working to different deadlines, but adversaries have already started the clock.

×