In brief: Due to growing investment in quantum computing, EU requirements running through 2030, and the risk of “harvest now, decrypt later” attacks, companies should plan their migration to post-quantum cryptography now on a risk-based basis rather than waiting.
Giesecke+Devrient (G+D) is urging companies and operators of critical infrastructure to prepare for the transition to post-quantum cryptography before powerful quantum computers become available. One reason is the risk of “harvest now, decrypt later” attacks, in which data encrypted today is collected for decryption at a later date.
Sufficiently powerful quantum computers could in the future break the cryptographic methods that today underpin payment systems, digital identities, mobile networks, IoT infrastructures and government systems. G+D points out that new scientific papers suggest that certain attacks may require less powerful quantum computers than previously assumed. According to McKinsey, global investment in quantum computing has increased sixfold within a single year. Google and Cloudflare have formulated their own migration timelines and are aiming to complete their transition to post-quantum cryptography by 2029.
Regulatory pressure is also mounting: in June 2024, the EU published a coordinated roadmap for migration, according to which particularly critical use cases should be transitioned to quantum-safe methods by the end of 2030 at the latest. In parallel, standardization organizations such as GSMA, 3GPP, ICAO and IETF are working on further developing existing standards and protocols for post-quantum cryptography. For CISOs, this means the migration is no longer a purely academic topic for the distant future, but a concrete compliance and security task with implementation deadlines.
The topic gains particular urgency due to “harvest now, decrypt later” attacks: attackers are already collecting encrypted information today in order to decrypt it later using sufficiently powerful quantum computers. This primarily affects data with a long protection period — anyone holding information that must remain confidential for ten or twenty years cannot postpone securing it until quantum computers actually become available.
According to G+D, the transition itself cannot be accomplished in the short term, since cryptography is deeply embedded in applications, networks, identity systems and digital infrastructures. As a first step, companies should take stock of the cryptographic methods currently in use, the locations where particularly sensitive data is processed, and systems with long lifespans. On this basis, a risk-based, step-by-step migration can be carried out, prioritizing particularly critical systems — such as digital identity documents with long-term integrity-critical signatures, as well as mobile network and eSIM infrastructures.
Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.