Skip to content

Post-Quantum Cryptography: Four Steps to Prepare for Quantum Computers

To the point: CISOs must now begin inventorying their encryption landscapes for post-quantum cryptography and establish migration plans before standardized quantum-secure algorithms must be implemented across the board.

Quantum computers could break asymmetric encryption methods on which critical IT infrastructures are based today. Migration to quantum-safe cryptography is no longer a technical future project, but a regulatory and governance task for every CISO.

The performance of quantum computers is based on fundamental physical principles that revolutionize computational processes. Particularly relevant to IT security: quantum computers can solve mathematical problems on which modern asymmetric cryptography is based. RSA, ECDSA and similar methods that today ensure the protection of encryption, digital signatures and key exchange are considered vulnerable to sufficiently powerful quantum computers.

For CISOs this concretely means: data encrypted today with RSA or ECC could be decoded in five to ten years by a sufficiently large quantum computer – even if the data has already been archived for years. These “Harvest Now, Decrypt Later” attacks make archived data a target as well. Regulatory requirements such as BSI regulations and future EU directives will therefore increasingly require organizations to demonstrate a transition path to post-quantum cryptography (PQC).

The four practical steps are: (1) Take inventory – identify all systems, devices and data streams that use RSA, ECC or other vulnerable methods. (2) Prioritize risks – distinguish between long-lived data (high risk, early migration necessary) and short-lived transactions (lower risk, later migration possible). (3) Evaluate post-quantum algorithms – test algorithms already standardized by NIST such as ML-KEM (Kyber) and ML-DSA (Dilithium) and validate them in test environments. (4) Establish migration plan – set timeline, resource allocation and compliance tracking aligned with regulatory deadlines and criticality of assets.

Important for CISOs: This migration is not an isolated technical task. It requires coordinated work between security, architecture, operations and legal – and should be integrated into existing zero-trust and encryption governance processes, not run as a separate project alongside them.


Source: www.security-insider.de · Published 29 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: