top of page

Fragmented PQC Migration Timelines Create Quantum Resilience Headaches

  • 3 days ago
  • 5 min read
July 2026, Daryl Flack, Partner
Published on: Resilienceforward.com

The quantum threat is global and a long-term resilience programme is needed in response. However, post-quantum cryptography migration timelines are fragmented, increasing the complexity of preparatory actions.


The transition to post-quantum cryptography (PQC) is accelerating, but most organizations are not ready. This lack of preparation is becoming increasingly significant as governments bring forward migration expectations.


The United States has raised the stakes considerably by introducing federal requirements for high-value assets and high-impact systems, excluding National Security Systems, to use PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031.


The impact will extend far beyond US government systems. Suppliers, technology providers, cloud platforms, and service partners supporting federal agencies will increasingly face expectations around quantum readiness, creating pressure throughout global technology supply chains.


This fragmentation introduces a new layer of complexity into an already difficult transformation. The United States, European Union, United Kingdom, and France are all moving in the same direction, but on slightly different timelines and through different mechanisms. The result is a fragmented global transition in which organizations, particularly multinational enterprises, must manage multiple, overlapping migration expectations at the same time.


One global threat, multiple migration clocks

Governments around the world recognise that migration to post-quantum cryptography must begin now. Most roadmaps broadly converge around the need to protect high-risk systems by the end of this decade, with wider migration completed during the early-to-mid 2030s.


The United States has set mandatory deadlines of 2030 for key establishment and 2031 for digital signatures for federal high-value assets and high-impact systems, excluding National Security Systems. The European Union recommends that critical infrastructure protection transition to PQC by the end of 2030.


The UK National Cyber Security Centre (NCSC) has outlined a phased approach, with discovery and planning expected by 2028, early, highest-priority migration activities carried out by 2031, and full migration targeted by 2035. The UK’s milestones are currently advisory rather than legally binding.


France has taken a different approach, linking quantum-safe cryptography to security certification and signalling that procurement expectations may become a powerful driver of adoption. For vendors seeking access to government or critical infrastructure markets, quantum readiness may increasingly become a commercial requirement before it becomes a legal one.


For multinational organizations, this means that the quantum transition will not happen against one global timetable. Instead, businesses must navigate different regulatory expectations, certification requirements, supplier readiness levels, and implementation schedules across multiple jurisdictions.


This is becoming a significant structural challenge in post-quantum migration.


Supply-chain readiness will influence the success of quantum migration

The impact of fragmented PQC timelines will be felt particularly across global supply chains.

Modern organizations depend on increasingly complex ecosystems of software vendors, cloud providers, managed service providers, hardware manufacturers, payment platforms, and critical infrastructure partners. Cryptography supports the security of each of those relationships by protecting software updates, authenticating users, securing communications, and enabling trusted digital transactions.


However, organizations do not operate in isolation. Their security also depends on the readiness of the wider ecosystem around them.


Each supplier relationship may introduce cryptographic dependencies. A business may begin its own PQC migration programme, but if a critical software provider, cloud service, or infrastructure partner has not identified its cryptographic exposure or is working to a different migration timetable, quantum-vulnerable dependencies may remain across the wider ecosystem.


The challenge is particularly significant because many organizations lack visibility of where cryptography exists across their own environments, let alone across third-party systems. Cryptographic mechanisms are embedded throughout applications, operating systems, network protocols, Internet of Things (IoT) devices, and operational technology (OT) environments. Legacy systems, undocumented implementations, and supplier dependencies can all make migration considerably more difficult.


Even comparatively prepared sectors face readiness gaps

Some industries are further ahead than others in preparing for the quantum transition. Financial services are often considered one of the more advanced sectors in PQC planning.

This is driven by regulatory scrutiny, operational complexity, and the need to protect long-lived, high-value data. It also reflects the resources available within the sector. Many financial institutions have been able to invest in specialist teams, dedicated programmes, and early cryptographic discovery.


However, being ahead of other sectors does not mean the industry is ready.

Work by the BIS Innovation Hub, SWIFT, and participating European central banks has demonstrated that PQC can be implemented in an operational payment system. At the same time, the work has highlighted significant practical challenges around interoperability, performance, vendor dependencies, and coordinating migration across highly interconnected systems.


Other sectors may be at an earlier stage. Many organizations have yet to establish where cryptography is embedded across their technology estates, assess supplier readiness, or determine which systems and data require prioritised protection.


As policy, regulatory, and procurement expectations develop, this lack of visibility is likely to become an increasingly significant business risk.


Fragmented timelines can prolong exposure to ‘harvest now, decrypt later’ threats

The urgency behind PQC migration is driven by a threat that exists before quantum computers capable of breaking widely used public-key cryptography become available.

‘Harvest now, decrypt later’ involves adversaries collecting encrypted information today, storing it, and attempting to decrypt it in the future once quantum capabilities mature.

For organizations managing information that must remain confidential for years or decades, this creates an immediate concern. Government records, intellectual property, healthcare and financial information, and data relating to defence systems and critical infrastructure all have lifespans that extend far beyond the technology protecting them today.


If this information is captured now and its protection depends on quantum-vulnerable public-key cryptography, a future quantum computer could compromise its confidentiality long after the systems that generated it have been replaced.


Every year of delayed migration may increase the volume of captured encrypted information that could eventually be exposed. Fragmented timelines can make this challenge harder by requiring organizations to balance different regulatory expectations while adversaries may continue collecting encrypted data.


Organizations should not assume that attackers will wait for governments to align their migration strategies.


Regulation, procurement, and certification will shape adoption

The global transition to PQC will not be driven by one mechanism alone.

In the United States, mandatory requirements for federal agencies are accelerating migration. In the UK, advisory guidance provides direction but may require regulatory action before it becomes mandatory. In France, security certification is becoming an additional force shaping adoption, while procurement may become another.


This creates both a challenge and an opportunity. The challenge is that organizations must navigate an increasingly complex regulatory landscape. The opportunity is that businesses that begin preparing early can build resilience before requirements become urgent.


Waiting until every jurisdiction has aligned its timeline is unlikely to be a viable strategy. Organizations need to prepare for fragmentation by building crypto-agility across their own infrastructure and supply chains.


That begins with understanding where cryptography exists, identifying long-lived sensitive data, assessing supplier readiness, and ensuring that future systems can support algorithm changes without extensive redesign.


Procurement teams should begin incorporating PQC requirements into supplier assessments and contracts. Security teams should establish cryptographic inventories and migration priorities. Boards should recognise that quantum readiness is not simply another cyber security initiative but a long-term resilience programme spanning technology, procurement, risk management, and governance.


The transition to post-quantum cryptography was always going to be one of the largest technology migrations that organizations will undertake. The emergence of fragmented global timelines has made that challenge significantly more complex at a time when many organizations remain unprepared.


Organizations cannot risk spending years navigating inconsistent requirements while sensitive encrypted data may continue to accumulate in adversary-controlled archives.

Organizations that begin preparing now and ensure that their suppliers move with them will be best positioned to navigate fragmented timelines and protect their most valuable information against both today’s threats and tomorrow’s quantum capabilities.


The author

Daryl Flack is a Partner at Avella Security.

bottom of page