A key benefit of quantum computing is that it may, in the future, enable a very substantial increase in computing power. This could create significant benefits, in the life sciences and financial services sectors (see our prior posts on the potential implications for these sectors here and here). However, it also creates potential risks. In particular, it could lead to the breaking of many of the encryption methods currently used by governments and businesses alike. As commercially-viable quantum computers become an increasing reality, organisations must prioritise “quantum readiness” and specifically migration to post-quantum cryptography (“PQC”).
In this post, we set out a brief overview of the main steps that regulators and industry bodies (including the U.S. National Institute of Standards and Technology (“NIST”), the UK National Cyber Security Centre (“NCSC”), and the EU Agency for Cybersecurity (“ENISA”)) have indicated businesses should take to move towards PQC and protect their data and systems from the risks posed by quantum computing.
At a very basic level, current state-of-the-art encryption protocols — such as RSA — rely on the multiplication of extremely large prime numbers. Breaking that encryption requires an attacker to identify the large prime numbers that were multiplied together. Using classical computers, “brute force” attacks are extremely unlikely to succeed within any sort of reasonable timetable. However, quantum computers could make breaking this sort of encryption trivial.
This threat is not industry specific — organisations across sectors could be vulnerable. For the healthcare sector, medical data is an extremely lucrative target for threat actors, especially given its sensitivity and longevity. For financial institutions, current encryption systems underpin every transaction, transfer, endpoint and protocol, including all online transactions. For governments, encryption is a crucial part of keeping information related to national security, defence and critical infrastructure matters secure.
It is likely to be a number of years more until quantum computers are reliable, accessible and of sufficient power to break current encryption protocols. However, legislators, regulators, and industry bodies are already encouraging organisations to move to new cryptography solutions that are resistant to brute force attacks from quantum computers. In particular, organisations should consider:
- Developing a strategy and governance programme for the transition to PQC. Organisations should think now about their roadmap for transitioning to PQC. In the U.S., NIST has recommended a full transition to post-quantum cryptography by 2035, and on 22 June 2026, President Trump issued an Executive Order (“EO”) on “Securing the Nation Against Advanced Cryptographic Attacks” that sets out initiatives to accelerate the federal government and private sector’s transition to PQC. The EO indicates that high value assets and high impact systems in the federal government should transition to use PQC for key establishment by December 2030 and for digital signatures by December 2031. In the UK NCSC recommends that organisations build an initial migration plan by 2028, carry out high-priority migration by 2031, and complete full system migration by 2035. Similarly, the EU, the NIS Coordination Group has recommended that Member States initiate their migration process by the end of 2026, with critical infrastructure and high-risk sectors — i.e., those subject to the revised Network and Information Systems Directive — required to be quantum-safe by 2030, and as many other systems as possible transitioned by 2035.
- Create a cryptographic inventory. To aid with the transition, it is likely to be helpful for organisations to create a full inventory of their cryptographic assets, including encryption algorithms they use, digital certificates, key exchanges, and signing mechanisms. They may also want to map data flows within and outside their organization to identify where encryption is applied and the systems in which encrypted data is stored. Organisations can then use this inventory to identify quantum-vulnerable encryptions methods (e.g., RSA, ECC, DH, DSA) and any third-party dependencies on these quantum-vulnerable encryption methods.
- Conduct risk assessments and prioritise assets to transition to PQC first. To prioritise the datasets that should be transitioned to PQC first, and the subsequent order of transition, regulators recommend that organisations consider classifying their datasets by the sensitivity of the data contained within them, and the longevity of that data (i.e., how long that data needs to be kept confidential). Regulators also recommend that organisations consider in particular the risks of “harvest now, decrypt later” attacks. These are attacks where a threat actor obtains encrypted data that they cannot access in the clear at present, but hope to do so in the future, e.g., when quantum computing becomes more widely available.
- Identify appropriate PQC algorithms. NIST has published specific, standardized algorithms for PQC, which the UK NCSC and ENISA have referred to in their guidance. These algorithms are, at this stage, regarded as the state-of-the-art of PQC, and organisations will likely wish to consider whether any and of them are appropriate for their transition.
- Pilot and implement PQC. Before rolling PQC out to live systems, organisations will likely want to consider piloting their PQC in non-production environments — consistent with their usual change management processes — to evaluate performance impact, latency, and interoperability. In addition, organisations will likely need to consider how to implement PQC where they are reliant on third-party suppliers for certain services.
- Monitor the implementation. Following implementation, organisations will need to monitor the implementation of PQC to ensure it is effective, and that it remains robust enough to resist new types of attacks. Organisations will also need to consider auditing and testing of their PQC in accordance with their usual processes.
Covington’s Technology and Communications and Privacy and Cybersecurity practices are continuously monitoring developments globally in relation to quantum computing and its implications for cybersecurity. If you would like to discuss anything raised in this blog, or anything related to quantum computing more generally, please do not hesitate to reach out to a member of the team with any inquiries.