Enterprises face post-quantum cryptography deadline — the stakes rival Y2K
The threat from quantum computers to existing encryption has shifted from theoretical to operational reality. Google has committed to completing its post-quantum cryptographic migration by 2029, the UK's NCSC by 2035, and the G7 by 2034. NIST has finalised its first post-quantum standards, triggering mandatory migration planning across regulated industries, in what experts are comparing to the Y2K challenge.
Full text
Quantum risk has moved from theoretical to operational in 2026, and this shift is now impossible for enterprises to ignore. Google has committed to completing its post-quantum migration by 2029, the NCSC 2035, and the G7 says 2034. NIST has finalized its first full suite of post‑quantum cryptographic standards, triggering mandatory migration planning across regulated industries.
The timelines might not be perfectly aligned, but the message they send is: the risk is real, and the time to act is now. Breakthroughs in quantum hardware and AI‑accelerated quantum optimization are bringing “Q‑Day”ever closer. This is elevating quantum‑safe visibility, cryptographic discovery, and encrypted‑traffic intelligence to a now‑priority for every enterprise.
This is not the first time the industry has faced a widely anticipated but imperfectly understood threat. The parallels between quantum computing and Y2K are difficult to ignore. What began as stories of a supermarket system rejecting food as 80 years out of date, or a 104-year-old being invited to school because a computer registered her as four, soon evolved into fear as the scale of the problem became clear.
By 1995 the New York Stock Exchange had spent over $30 million remediating its systems. Y2k evolved into a defining moment for risk management and the key lesson was that organizations must understand and respond to exposure quickly and decisively.
Successfully addressing the threat quantum computing poses to encryption demands the same mindset, although this time applied across a far more complex and interconnected digital landscape.
The invisible threat already underway
A key distinction between Y2K and quantum computing is that the latter is not anchored to a single moment in time. The phrase “harvest now, decrypt later” describes the practice of adversaries collecting encrypted data today with the expectation that quantum capabilities will allow them to decrypt it in the future.
The implications of this tactic are significant, with 87 percent of organizations expressing concern about such scenarios as quantum computing advances.
Financial records, personal data , and intellectual property retain their value long past creation and the information encrypted today may still be sensitive well into the future. Decisions made now about cryptographic resilience will directly shape an organization's future security and reputation.
Why PQC is fundamentally more complex than Y2K
At its core, the Y2K challenge was a remediation problem with a relatively well-defined scope. Migrating to post-quantum cryptography is fundamentally different.
Cryptographic controls are deeply embedded across modern digital infrastructure, underpinning applications, APIs, cloud services , IoT devices, operational technology, and a growing web of third-party integrations. In many cases, they operate invisibly and are poorly documented. Organizations are not simply upgrading known systems, but first discovering what encryption levels have been used and where.
Addressing this means building a comprehensive inventory of cryptographic assets. All weak cipher suites, expired certificates, and non-compliant encryption methods must be identified.
Once found, organizations should standardize on stronger protocols such as Transport Layer Security (TLS) 1.3. This faster, more streamlined and longer protocol is ultimately more secure than older versions like TLS 1.1 and TLS 1.2, which will be broken by quantum computers in a matter of hours, minutes, or even seconds.
You cannot secure what you cannot see
In addressing both Y2K and today’s cybersecurity challenges, one principle consistently determines success: visibility. As organizations plan for a post-quantum future, 91 percent report that visibility into encrypted traffic is critical for PQC readiness.
Network-derived telemetry provides a scalable way to gain this. By analyzing traffic flows and metadata, organizations can build a comprehensive picture of cryptographic usage across both managed and unmanaged assets. This outside-in perspective complements internal inventories and helps uncover dependencies that might otherwise remain hidden.
With improved visibility comes the ability to assess risk more accurately, prioritize remediation, and ensure that the adoption of quantum-resistant approaches does not introduce unintended vulnerabilities.
Avoiding a repeat of history
The response to Y2K ultimately succeeded because organizations acknowledged the threat and took action. It was a forcing function that led to massive technology infrastructure upgrades and tech stack modernization.
Like Y2K, today’s quantum challenge isn’t just the potential event itself, it’s the scale of the remediation effort required across systems, applications, and embedded technologies, which makes early action critical.
The transition to post-quantum cryptography will not be achieved overnight. It will require a coordinated effort across security , infrastructure , development, and compliance functions, alongside close collaboration with vendors and strategic partners.
More importantly, it requires a shift in how the challenge is framed. Organizations that take proactive steps now by establishing a comprehensive inventory of cryptographic assets, improving visibility across their environments, and developing structured transition plans will be far better positioned to navigate the shift.
They will retain control over their timelines and reduce the likelihood of disruptive, last-minute change.
Those that delay may find themselves in a position that feels uncomfortably familiar. A known problem with a shrinking window in which to respond.
We've featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives , our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
Similar stories
Similar stories
Will enterprises manage to implement post-quantum cryptography before Q-Day?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!