In brief: Because encrypted data intercepted today could be decrypted by quantum computers in the future, G+D recommends a risk-based, early migration to post-quantum cryptography.
Giesecke+Devrient (G+D) is calling on companies and operators of critical infrastructure to start preparing for the transition to Post-Quantum Cryptography (PQC) now – even before powerful quantum computers become available. The reason is the threat posed by “harvest now, decrypt later” attacks, in which data encrypted today is collected for later decryption.
Giesecke+Devrient (G+D) sees a concrete need for action on the transition to Post-Quantum Cryptography (PQC) already today. This is based on the assessment that sufficiently powerful quantum computers could in future render commonly used encryption methods vulnerable. According to G+D, this would affect payment systems, digital identities, mobile networks, IoT infrastructures and government systems, among others. A successful attack could expose confidential communications, compromise digital identities and make transactions susceptible to manipulation.
According to G+D, several developments suggest that the topic should no longer be treated as a purely long-term issue. New scientific research indicates that certain attacks may require less powerful quantum computers than previously assumed. In addition, global investment in quantum computing has increased sixfold within a year, according to McKinsey. Google and Cloudflare have formulated their own migration timelines, aiming to complete the transition by 2029. In June 2024, the EU published a coordinated roadmap under which particularly critical use cases are to be migrated to quantum-safe methods by the end of 2030 at the latest. At the same time, standardisation bodies such as GSMA, 3GPP, ICAO and IETF are working on further developing existing protocols for PQC.
This creates an immediate risk for CISOs, regardless of when powerful quantum computers actually become available: in “harvest now, decrypt later” attacks, attackers are already collecting encrypted information today in order to decrypt it later. This makes data with long protection periods particularly relevant – for example, information that must remain confidential even in ten or twenty years. Such data cannot be secured only once corresponding quantum computers already exist.
According to G+D, the migration itself does not affect individual algorithms alone, but extends deep into applications, networks, identity systems and digital infrastructures. Companies should therefore first determine which cryptographic methods are in use, where particularly sensitive data is processed, and which systems have a long lifespan. On this basis, a risk-based, step-by-step prioritisation is recommended – starting with particularly critical systems such as digital identity documents, whose signatures must ensure the long-term integrity and authenticity of stored information, as well as mobile network and eSIM infrastructures.
Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.