Preparing for the Quantum Threat

The quantum threat is uncertain in timing but certain in impact—making post-quantum cryptography, selective QKD and sustained crypto-agility essential to building an organisation capable of adapting before today’s cryptography becomes tomorrow’s vulnerability.

Sanchez P.

10/1/202656 min read

Abstract

The emergence of cryptographically relevant quantum computing poses a significant long-term challenge to contemporary cybersecurity because sufficiently capable quantum computers could undermine widely deployed public-key cryptographic systems. Shor’s algorithm demonstrates that integer factorisation and discrete logarithms can be solved efficiently on a sufficiently capable quantum computer, threatening cryptographic mechanisms such as RSA and elliptic-curve cryptography (Shor, 1994). Although the timing of such a capability remains uncertain, this uncertainty does not eliminate the need for preparation. In particular, the ‘harvest now, decrypt later’ threat means that encrypted information captured today may become vulnerable if sufficiently capable quantum computers emerge in the future.

This paper examines how organisations can prepare for this transition by evaluating three interconnected approaches: post-quantum cryptography (PQC), quantum key distribution (QKD), and crypto-agility. PQC provides a scalable approach to replacing quantum-vulnerable public-key mechanisms using conventional computing infrastructure, while QKD offers a fundamentally different approach to key establishment based on quantum communication. The analysis finds that these approaches should not be treated as interchangeable. PQC is generally more suitable for broad organisational migration, whereas QKD may provide a specialised complement for selected high-value communications where its infrastructure and operational requirements can be justified. Crypto-agility provides the organisational and architectural capability required to adopt, replace and reassess cryptographic mechanisms as the threat landscape develops.

The paper argues that post-quantum readiness should therefore not be understood as the selection of a single ‘quantum-safe’ algorithm or the completion of a one-time migration. Instead, it should be understood as an organisational capability encompassing cryptographic visibility, data classification, dependency management, migration planning, interoperability testing and the ability to transition between cryptographic mechanisms with limited disruption. The analysis concludes that uncertainty surrounding the arrival of a cryptographically relevant quantum computer strengthens rather than weakens the case for preparation, because organisations control their migration capability to a greater extent than they control the development of quantum computing. Consequently, effective quantum preparedness is best approached as a continuing programme of cryptographic risk management, supported by PQC, selective use of QKD where appropriate, and sustained crypto-agility.

Keywords: post-quantum cryptography; quantum computing; cryptographic agility; quantum key distribution; RSA; elliptic-curve cryptography; harvest now decrypt later; cybersecurity

1. Introduction

Cryptography is a foundational layer of contemporary digital infrastructure. Public-key cryptographic mechanisms underpin secure communications, digital signatures, authentication, certificates, software distribution and public-key infrastructures, while symmetric cryptography provides confidentiality for data in transit and at rest. The security of these systems, however, depends on computational assumptions that are not immutable. The emergence of large-scale quantum computing presents a particularly significant challenge because quantum algorithms can fundamentally alter the computational difficulty of problems on which widely deployed public-key cryptosystems depend.

The nature of this challenge was established theoretically with Shor's (1994) quantum algorithm for integer factorisation and discrete logarithms. If a sufficiently capable, fault-tolerant quantum computer becomes available, Shor's algorithm would render the mathematical assumptions underlying widely deployed public-key systems such as RSA and elliptic-curve cryptography (ECC) computationally insecure. The implications extend beyond confidentiality: public-key mechanisms are deeply embedded in authentication, digital signatures, certificate infrastructures and software-signing processes. Resource estimates further demonstrate that attacks against elliptic-curve systems are not merely abstract possibilities, but can be expressed in terms of concrete quantum computational requirements (Roetteler et al., 2017). Symmetric cryptography faces a different, less fundamental threat. Grover's (1996) quantum search algorithm provides a quadratic speed-up for exhaustive search, reducing the effective security of an -bit symmetric key to approximately bits under an idealised quantum search model. The resulting mitigation is correspondingly different: larger symmetric keys can substantially restore the desired security margin, whereas RSA and ECC require replacement rather than simple parameter enlargement.

Against this technical background, Swisscom's Post Quantum Security white paper frames quantum risk as a problem that organisations must address before a cryptographically relevant quantum computer (CRQC) becomes operationally available (Swisscom, 2025). The paper identifies post-quantum cryptography (PQC) and quantum key distribution (QKD) as two principal technological responses, while placing considerable emphasis on organisational capabilities such as data classification, cryptographic inventories, threat modelling, migration planning and crypto-agility. This emphasis is consistent with the broader post-quantum literature, which increasingly treats the transition as a systems and governance challenge rather than simply as the selection of replacement algorithms (Bernstein and Lange, 2017; NIST, 2021).

The most important characteristic of the quantum threat is therefore not simply its technical severity, but its temporal asymmetry. The precise date on which a CRQC will become capable of compromising deployed cryptography remains uncertain. Expert assessments continue to show substantial variation in estimates of when such capabilities may emerge (Mosca and Piani, 2024). By contrast, organisations can often estimate how long particular information must remain confidential and how long their technology estates would require to migrate away from vulnerable cryptographic mechanisms. This asymmetry creates a strategic problem: the absence of a reliable quantum-computing deadline does not imply the absence of a migration deadline.

Mosca (2018) captures this problem through what has become known as the Mosca inequality. The relevant consideration is whether the sum of the time for which information must remain secure and the time required to migrate the associated systems exceeds the remaining time before a quantum threat becomes operationally relevant. If migration and information shelf-life extend beyond the anticipated threat horizon, postponing action can result in information becoming vulnerable before the organisation has completed its transition. This reasoning is particularly important for so-called harvest now, decrypt later attacks, in which adversaries collect encrypted information today with the expectation that future technological capabilities will permit its decryption. For information with a long confidentiality lifetime, the relevant security event is therefore not necessarily the future moment at which a CRQC performs the decryption; it may be the present moment at which vulnerable ciphertext is collected.

This temporal dimension changes the character of quantum-risk management. Organisations cannot reasonably wait for definitive evidence that a CRQC exists before beginning migration, because the migration itself may require many years and because some information must remain confidential for periods that extend well beyond current technology cycles. The appropriate response is therefore not to predict the arrival date of quantum computing with precision, but to reduce the time and uncertainty associated with cryptographic migration.

This observation provides the central link between the technical literature and Swisscom's organisational recommendations. PQC addresses the problem of constructing cryptographic mechanisms that are believed to withstand known quantum attacks using conventional computing infrastructure. NIST's standardisation of ML-KEM, ML-DSA and SLH-DSA represents a significant step towards operational deployment of such mechanisms (NIST, 2024a; NIST, 2024b; NIST, 2024c). Yet the availability of standards does not by itself resolve the migration problem. Organisations must first establish where vulnerable cryptography is deployed, understand which business processes depend upon it, determine the confidentiality lifetime of the information being protected and assess the technical and operational dependencies that could make replacement difficult. NIST (2021) consequently emphasises the challenges associated with identifying cryptographic dependencies, evaluating algorithm performance and preparing systems for the eventual transition to post-quantum mechanisms.

QKD represents a fundamentally different response. Rather than replacing vulnerable mathematical assumptions with alternative classical computational assumptions, QKD uses properties of quantum mechanics to establish shared cryptographic keys. Its theoretical security properties distinguish it from conventional and post-quantum cryptography, but practical deployment introduces substantial engineering and operational constraints. Research on practical QKD has identified challenges involving transmission distance, optical loss, key-generation rates, infrastructure requirements and implementation security (Brassard et al., 2000; Diamanti et al., 2016; Lo, Curty and Tamaki, 2020). More recent work further demonstrates that the security proofs of practical QKD must be understood in relation to implementation assumptions, device imperfections and gaps between idealised models and real-world systems (Tupkary et al., 2026). QKD should therefore not be regarded as a universal replacement for PQC, but as a specialised technology whose applicability depends on the threat model, communication architecture and value of the information being protected.

The resulting challenge is broader than the identification of quantum-resistant algorithms. Cryptographic mechanisms are frequently embedded throughout applications, operating systems, communication protocols, certificate infrastructures, hardware security modules and third-party products. An organisation may therefore be unable to replace a vulnerable algorithm simply by installing a new software library. The ability to discover cryptographic dependencies and replace algorithms without unacceptable disruption becomes a security capability in its own right. This is the underlying rationale for crypto-agility: the architectural and organisational capacity to change cryptographic mechanisms as algorithms, standards, threats and technological assumptions evolve.

The central argument of this paper is consequently that quantum readiness should be understood principally as a cryptographic transition and systems-engineering problem, rather than as a discrete algorithm-selection exercise. The relevant question is not only which cryptographic algorithms can resist quantum attacks, but whether organisations can identify vulnerable assets, prioritise them according to information lifetime and business impact, migrate them within the available time, and retain sufficient flexibility to respond to future developments in both quantum computing and cryptanalysis.

The analysis that follows develops this argument by examining five interconnected issues. First, it considers the capabilities that a sufficiently powerful quantum computer would bring to bear against contemporary cryptography, distinguishing the fundamentally different effects of Shor's and Grover's algorithms. Second, it examines why uncertainty over the timing of CRQCs does not remove the need for immediate preparation, particularly in the context of long-lived information and harvest now, decrypt later threats. Third, it evaluates PQC and QKD as alternative and potentially complementary approaches to quantum-resistant security, drawing on both their theoretical foundations and practical limitations. Fourth, it considers crypto-agility as an organisational capability required to manage not only the current quantum transition but also future cryptographic change. Finally, it develops a risk-based migration perspective that connects cryptographic vulnerability with information shelf-life, technological dependencies and organisational capacity to execute change.

Taken together, the literature suggests that the post-quantum transition should not be conceived as a single future migration event triggered by the arrival of a CRQC. It is better understood as a progressive transformation of cryptographic governance, architecture and operational practice. The objective is not merely to achieve a static state of "quantum-safe" security, but to establish the capability to identify, assess and replace cryptographic mechanisms before changing computational capabilities render existing protections inadequate.

2. Quantum Computing and the Cryptographic Threat

The security implications of quantum computing arise from the fact that quantum algorithms can change the computational complexity of problems on which contemporary cryptography depends. The threat is not uniform across all cryptographic mechanisms. Public-key cryptography is exposed to a potentially fundamental break, whereas symmetric cryptography experiences a more limited reduction in its effective security strength. This distinction is critical for determining migration priorities and for understanding why the transition to post-quantum security cannot be reduced to a single, uniform replacement strategy.

2.1 Shor's Algorithm and Public-Key Cryptography

The most consequential cryptographic threat posed by quantum computing originates from Shor's algorithm. Shor (1994) demonstrated quantum algorithms for solving integer factorisation and discrete logarithms in polynomial time. These results are particularly significant because the computational difficulty of these problems underpins major classes of contemporary public-key cryptography.

RSA derives its security from the practical difficulty of factoring the product of two large prime numbers. Elliptic-curve cryptography (ECC), by contrast, relies on the computational difficulty of solving the elliptic-curve discrete logarithm problem. Both assumptions are considered tractable for appropriately designed classical cryptographic systems precisely because no efficient classical algorithms are known for solving the underlying problems at the scales used in practice. Shor's algorithm changes this assumption fundamentally. A sufficiently large and fault-tolerant quantum computer could solve these problems efficiently, transforming RSA and ECC from computationally hard problems into problems that are, in principle, efficiently solvable.

The distinction between theoretical vulnerability and operational feasibility is nevertheless important. Shor's algorithm establishes the cryptographic consequence of sufficiently capable quantum computation; it does not establish that current quantum computers can already break deployed RSA or ECC systems. The practical challenge is to construct a fault-tolerant quantum computer with sufficient logical-qubit capacity, gate fidelity and computational depth to execute the required algorithms at cryptographically relevant scales. Consequently, the existence of a quantum algorithm that breaks RSA or ECC should not be interpreted as evidence that those systems are currently insecure against quantum attack. Rather, it establishes a future dependency that organisations must address during the potentially lengthy period required for cryptographic migration.

Resource-estimation research provides an important bridge between the theoretical result and this practical question. Roetteler et al. (2017), for example, developed resource estimates for quantum attacks against elliptic-curve discrete logarithms and demonstrated that the required resources can be expressed in concrete terms for widely used elliptic curves. Their analysis illustrates an important feature of the quantum threat: the security of ECC cannot be assessed solely by considering classical key sizes. Once a sufficiently capable quantum computer exists, the relevant question becomes the resources required to implement the quantum algorithm rather than the classical computational cost of solving the discrete logarithm problem.

This has direct consequences for cybersecurity architecture. The quantum threat to public-key cryptography is not confined to the encryption of confidential information. Public-key mechanisms are embedded throughout digital trust infrastructures, including digital signatures, certificate authorities, authentication protocols, public-key infrastructures, software-signing systems and secure communication protocols. A quantum attack against the underlying mathematical assumptions could therefore affect both confidentiality and authenticity.

The distinction is particularly important for digital signatures. Encryption protects information against unauthorised disclosure, whereas digital signatures provide authenticity and integrity. If a quantum adversary can efficiently solve the mathematical problem underlying a signature scheme, the adversary may potentially generate fraudulent signatures or impersonate legitimate entities. A migration programme that focuses exclusively on encrypted data could therefore leave critical authentication and software-supply-chain mechanisms exposed.

This broader systems perspective is consistent with Bernstein and Lange's (2017) treatment of post-quantum cryptography (PQC). PQC is not simply a new form of encryption intended to replace RSA. It encompasses cryptographic constructions designed to remain secure against adversaries equipped with quantum computers, including mechanisms for key establishment and digital signatures. The central research challenge is to construct cryptographic systems whose underlying mathematical problems do not appear to admit quantum algorithms comparable to Shor's algorithm.

The resulting implication is that the quantum threat to public-key cryptography should be understood as a cryptographic infrastructure problem. Replacing RSA or ECC in one application does not necessarily remove the organisation's exposure if the same algorithms remain embedded in certificates, identity systems, VPNs, application programming interfaces, hardware security modules or third-party services. The migration challenge is consequently one of identifying and replacing cryptographic dependencies across interconnected systems.

This also explains why the precise timing of a cryptographically relevant quantum computer is not the only relevant variable. Public-key cryptography can remain vulnerable even where the quantum threat is years away because certificates, signatures and encrypted communications created today may need to remain trustworthy or confidential for many years. The practical question for an organisation is therefore not simply whether a CRQC exists today, but whether the organisation can complete the transition before information or trust relationships protected by quantum-vulnerable algorithms become exposed.

2.2 Grover's Algorithm and Symmetric Cryptography

The impact of quantum computing on symmetric cryptography is fundamentally different. Grover (1996) demonstrated a quantum search algorithm that provides a quadratic speed-up for searching an unstructured space. In the context of cryptography, the result is significant because exhaustive key search is essentially an unstructured search problem.

For a classical brute-force attack against an ideal -bit symmetric key, the search space contains possible keys and requires, in the worst case, a number of operations proportional to . An idealised implementation of Grover's algorithm reduces this to approximately quantum operations. The commonly used security interpretation is therefore that an -bit symmetric key provides approximately bits of effective security against an idealised Grover search.

This does not mean that symmetric cryptography becomes insecure in the same sense as RSA or ECC. The distinction is fundamental. Grover's algorithm reduces the security margin of symmetric cryptography but does not provide a general polynomial-time algorithm that renders sufficiently large symmetric keys computationally trivial. Increasing the key size can therefore compensate for the quantum speed-up. In broad terms, a 256-bit symmetric key provides a substantially larger security margin against exhaustive quantum search than a 128-bit key.

The practical significance of Grover's algorithm should nevertheless be treated with some caution. The theoretical quadratic speed-up assumes an idealised quantum search process, whereas a real cryptanalytic implementation would require a large fault-tolerant quantum computer and substantial quantum resources. The cost of constructing the quantum circuit, performing error correction and executing the search at scale can be considerable. The theoretical complexity should therefore not be interpreted as a direct prediction of the practical cost of a real-world quantum attack.

Nevertheless, the distinction between symmetric and asymmetric cryptography has important consequences for migration strategy. RSA and ECC require fundamentally different cryptographic constructions because increasing their key sizes does not provide a comparable defence against Shor's algorithm. Symmetric cryptography, by contrast, can generally be strengthened through larger security parameters. This makes the quantum transition asymmetric: the greatest architectural disruption is associated with public-key cryptography, while symmetric cryptography can, in principle, be hardened through parameter selection.

This distinction also supports the risk prioritisation proposed by Swisscom (2025). Organisations should not treat every cryptographic mechanism as equally exposed or assume that quantum readiness requires the wholesale replacement of all cryptographic primitives. Instead, migration should distinguish between cryptographic systems that are fundamentally vulnerable to known quantum algorithms and those for which increased security parameters can provide an appropriate mitigation.

For symmetric cryptography, this may involve moving towards stronger configurations, such as the use of 256-bit keys where appropriate, while maintaining sound key-management practices. For public-key cryptography, the corresponding response is more substantial: organisations must identify dependencies on RSA, ECC and other quantum-vulnerable mechanisms and plan their replacement with appropriate post-quantum alternatives.

The difference can therefore be expressed as one between cryptographic degradation and cryptographic displacement. Grover's algorithm reduces the effective security of symmetric cryptography but leaves a viable path for strengthening existing designs. Shor's algorithm, by contrast, undermines the computational foundations of RSA and ECC and consequently requires their eventual displacement by cryptographic mechanisms based on different hardness assumptions.

This distinction is central to the post-quantum migration problem. It suggests that organisations should not begin with the assumption that every cryptographic component requires immediate replacement. Instead, they should first establish a detailed cryptographic inventory, determine which algorithms are deployed and where, assess the confidentiality and integrity requirements of the assets they protect, and then prioritise migration according to the nature and consequence of the quantum threat.

The broader lesson is that quantum computing does not create a single cryptographic problem. It creates different levels and forms of exposure across the cryptographic stack. Public-key systems face the possibility of fundamental algorithmic compromise; symmetric systems face a reduction in effective security strength; and the systems that combine these mechanisms may contain dependencies that are not immediately visible at the application level. Effective quantum readiness must therefore combine an understanding of quantum algorithms with architectural visibility and disciplined migration planning.

3. Uncertainty and the 'Harvest Now, Decrypt Later' Problem

One of the central challenges in managing the quantum threat is that the timing of a cryptographically relevant quantum computer (CRQC) cannot currently be established with sufficient precision to support conventional technology planning. There is an important distinction, however, between uncertainty about when a CRQC will become available and uncertainty about whether sufficiently capable quantum computation would undermine vulnerable cryptographic systems. The former remains highly uncertain; the latter follows from well-established quantum algorithms and the mathematical assumptions on which current public-key cryptography depends (Shor, 1994). The resulting risk-management problem is therefore not one of predicting a precise technological deadline, but of making rational migration decisions under uncertainty.

Swisscom's Post Quantum Security white paper highlights this distinction by separating the rapid progress of quantum hardware from the substantially more demanding task of constructing a fault-tolerant quantum computer capable of executing cryptographically relevant algorithms at scale (Swisscom, 2025). The number of physical qubits deployed by a quantum computer is consequently an insufficient indicator of its cryptographic capability. What matters is the ability to construct reliable logical qubits and execute sufficiently deep quantum circuits while controlling the accumulation of errors. Logical-qubit overhead, physical error rates, error-correction requirements, gate fidelity, circuit depth and computational throughput all influence whether a particular quantum system can perform a cryptanalytic computation of practical significance.

This distinction is particularly important because headline measures of quantum-computing progress can obscure the difference between experimental scale and cryptographic capability. A system may contain a large number of physical qubits while still being incapable of sustaining the logical operations required by Shor's algorithm at the scale necessary to attack contemporary cryptographic systems. Conversely, improvements in error correction and fault-tolerant architectures could alter the relationship between physical hardware and cryptographic capability relatively rapidly. Consequently, physical-qubit counts should not be treated as a standalone measure of the time remaining before cryptographically relevant quantum computation becomes possible.

Expert assessments reflect this uncertainty. The Global Risk Institute's Quantum Threat Timeline Report 2024, based on a survey of 32 international experts, illustrates the range of professional expectations concerning the emergence of cryptographically relevant quantum computers (Mosca and Piani, 2024). Such assessments are useful for risk analysis, but they should not be interpreted as precise forecasts. They represent expert judgements concerning a rapidly developing technological field in which improvements in hardware, error correction, algorithms and engineering may interact in ways that are difficult to predict. The absence of a reliable date therefore constitutes a genuine uncertainty rather than a temporary information gap that can simply be resolved through better forecasting.

For cybersecurity decision-making, however, uncertainty does not necessarily justify delay. Indeed, it can increase the importance of reducing the time required for migration. An organisation that waits for greater certainty may obtain better information about the quantum threat while simultaneously reducing the time available to respond to it. The strategic objective should therefore be to reduce those components of risk that are within organisational control, particularly the time and complexity associated with cryptographic migration.

This consideration becomes especially important in the context of the harvest now, decrypt later (HNDL) threat. Under this model, an adversary collects encrypted information before possessing the technological capability to decrypt it. The ciphertext can then be retained until a sufficiently capable quantum computer becomes available. The threat is consequently relevant today even though a CRQC capable of breaking the underlying cryptography may not yet exist.

The significance of HNDL depends on the relationship between the value of information and its confidentiality lifetime. Information that loses its sensitivity within a short period may have limited retrospective value to an adversary. By contrast, information concerning long-term intellectual property, strategic research, personal records, financial information, confidential legal matters or other sensitive material may retain value for many years or decades. For such information, the relevant security question is not simply whether the current encryption can be broken today, but whether the encryption applied today will remain secure for the entire period during which confidentiality is required.

This creates a temporal asymmetry at the heart of post-quantum risk. An organisation may be able to estimate the period for which a dataset must remain confidential and may also estimate how long it would take to migrate the systems protecting that dataset. It cannot, with comparable precision, determine the date on which a CRQC will become available. Consequently, the organisation must make decisions using an uncertain threat horizon while dealing with comparatively concrete information-lifetime and migration constraints.

Mosca (2018) formalises this problem through what is commonly referred to as the Mosca inequality. The framework compares three periods: the time for which information must remain secure, the time required to migrate the relevant systems to quantum-resistant cryptography, and the time remaining before a quantum computer becomes capable of compromising the cryptographic mechanisms in question. Where the confidentiality lifetime of the information and the required migration period together exceed the remaining time before a relevant quantum threat emerges, the organisation faces a potential security gap.

The importance of the framework lies less in the precise numerical values assigned to these variables than in the way it structures organisational decision-making. The quantum threat horizon is uncertain and largely outside the organisation's control. The confidentiality lifetime of information is partly determined by business, legal and regulatory requirements and is therefore more readily characterised. Most importantly, the migration period is a variable that the organisation can influence. Investments in cryptographic discovery, architectural redesign, vendor engagement, testing, automation and crypto-agility can reduce the time required to complete a transition.

The Mosca inequality should therefore be understood not as a prediction of when quantum computers will arrive, but as a deadline-feasibility test under uncertainty. Its purpose is to determine whether an organisation can complete migration within the period during which the information concerned must remain protected. This interpretation is particularly useful because it avoids the false precision associated with assigning a single date to the arrival of a CRQC. Instead, it asks a more operationally relevant question: given the information that must remain secure and the systems that must be changed, how much migration time can the organisation afford to consume before the residual uncertainty becomes unacceptable?

Consider an organisation holding information that must remain confidential for twenty years. If the systems protecting that information require several years to identify, redesign, test and migrate, postponing action until a CRQC has been demonstrated would potentially leave insufficient time to complete the transition. This remains the case even if estimates of the arrival of a CRQC have wide confidence intervals. The uncertainty surrounding the threat date does not remove the relatively concrete constraints imposed by information shelf-life and organisational migration capacity.

The HNDL threat reinforces this conclusion because migration must protect not only future communications but potentially the confidentiality of information being transmitted or stored today. An organisation that successfully migrates its systems after a CRQC becomes available may still be unable to recover information that was intercepted and archived before the migration. For long-lived secrets, therefore, post-quantum migration is partly a form of forward-looking information protection: the objective is to ensure that data generated today remains confidential against capabilities that may emerge in the future.

This temporal perspective also clarifies why quantum readiness cannot be reduced to monitoring technological developments. Monitoring quantum hardware is necessary, but it addresses only one component of the problem. An organisation that continuously revises its estimate of the quantum threat while leaving its migration programme unchanged may gain increasingly precise knowledge without materially improving its security position. By contrast, an organisation that establishes a comprehensive cryptographic inventory, classifies information according to confidentiality lifetime and systematically reduces its migration time becomes less dependent on the accuracy of any particular quantum forecast.

The appropriate strategic response to uncertainty is therefore preparedness rather than prediction. Organisations cannot control the pace of quantum-computing development, but they can influence their ability to respond to it. This provides a direct rationale for the emphasis placed by Swisscom (2025) on cryptographic inventories, data classification, threat modelling, migration planning and crypto-agility. These measures do not eliminate uncertainty about when a CRQC will emerge; rather, they reduce the consequences of being wrong about its timing.

The HNDL problem consequently transforms the quantum threat from a distant technological possibility into a present information-security consideration. For data with sufficiently long confidentiality lifetimes, the relevant migration deadline may arrive well before the quantum computer itself. The strategic implication is that organisations should assess their exposure according to the intersection of information shelf-life, migration time and quantum threat horizon, rather than treating the eventual arrival of a CRQC as the starting point for action.

4. Post-Quantum Cryptography

4.1 Principles

Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to remain secure against adversaries equipped with sufficiently capable quantum computers while continuing to operate on conventional computing and communications infrastructure. Its primary purpose is therefore to replace or augment public-key mechanisms that are vulnerable to quantum algorithms, particularly RSA and elliptic-curve cryptography (ECC), without requiring organisations to construct quantum communication networks. PQC represents a response to the cryptographic consequences of quantum computing rather than an attempt to prevent quantum computation itself.

PQC algorithms are based on mathematical problems for which no efficient classical or quantum attacks are currently known. Major research directions include lattice-based, hash-based, code-based and other structured mathematical constructions (Bernstein and Lange, 2017). These approaches differ in their underlying security assumptions and operational characteristics, meaning that post-quantum security cannot be treated as a single cryptographic property. Algorithm selection must instead consider security strength, computational performance, key and signature sizes, implementation complexity, interoperability and the consequences of potential weaknesses in the underlying mathematical assumptions.

This distinction is important because the security of PQC is necessarily conditional. The absence of a known efficient quantum attack does not constitute proof that an algorithm will remain secure indefinitely. As with conventional cryptography, confidence in PQC depends on continued cryptanalysis, implementation scrutiny, standardisation and operational experience. Bernstein and Lange (2017) therefore frame post-quantum cryptography as a process of selecting cryptographic constructions that provide an appropriate balance between security assumptions, efficiency and practical usability rather than as the identification of a permanently 'quantum-proof' algorithm.

PQC also differs fundamentally from quantum key distribution (QKD). PQC can be deployed using existing classical networks, processors, protocols and security infrastructure, although software and hardware modifications may still be necessary. QKD, by contrast, relies on quantum communication systems and specialised physical infrastructure. The distinction has important consequences for scalability and migration. PQC can, in principle, be incorporated into existing cryptographic protocols and infrastructure, making it applicable across a broad range of enterprise and governmental environments. QKD is more dependent on physical deployment conditions, distance, hardware and network architecture. PQC therefore provides the principal mechanism for integrating post-quantum protection into conventional digital systems, while QKD represents a more specialised approach for circumstances in which its additional infrastructure requirements can be justified.

The practical significance of PQC consequently extends beyond the replacement of individual algorithms. Public-key cryptography is embedded throughout modern digital infrastructure, including secure communications, authentication, certificates, digital signatures, software distribution and key establishment. Replacing vulnerable algorithms therefore involves identifying dependencies between cryptographic primitives, protocols, applications and infrastructure. PQC migration is consequently better understood as a systems-engineering and lifecycle-management problem than as a simple algorithm substitution.

4.2 Standardisation

The transition of PQC from an academic research field towards operational deployment has been significantly accelerated by international standardisation. In August 2024, the National Institute of Standards and Technology (NIST) finalised three principal post-quantum cryptographic standards: FIPS 203, specifying the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM); FIPS 204, specifying the Module-Lattice-Based Digital Signature Algorithm (ML-DSA); and FIPS 205, specifying the Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) (NIST, 2024a; NIST, 2024b; NIST, 2024c). ML-KEM is derived from CRYSTALS-Kyber, ML-DSA from CRYSTALS-Dilithium, and SLH-DSA from SPHINCS+.

This standardisation milestone is significant because large-scale cryptographic migration cannot rely solely on research algorithms or experimental implementations. Organisations require stable specifications against which products can be developed, tested and procured. They also require interoperable implementations, vendor support, implementation guidance and mechanisms for managing cryptographic algorithms throughout their operational lifecycles. Standardisation therefore reduces uncertainty at precisely the point where organisations must begin making long-term architectural and procurement decisions.

NIST's work also illustrates why migration cannot begin with algorithm deployment alone. An organisation must first establish where cryptography is used, which algorithms and key sizes are deployed, what protocols depend upon them, and which systems may be affected by their replacement. Cryptographic discovery is consequently a prerequisite for meaningful migration planning. Without sufficient visibility, organisations may replace cryptography in visible applications while leaving vulnerable algorithms embedded within legacy systems, certificates, devices, libraries or third-party services.

Interoperability presents a related challenge. Cryptographic systems rarely operate in isolation, and a change to one cryptographic mechanism can create dependencies across applications, operating systems, network protocols, hardware, identity systems and external suppliers. Testing PQC implementations across these dependencies is therefore necessary before production deployment. NIST's emphasis on cryptographic discovery and interoperability testing reflects this broader reality: post-quantum migration is not simply a question of whether an algorithm is theoretically secure, but whether it can be deployed consistently across a complex technological environment.

This reinforces the migration principle identified in the Swisscom white paper. A cryptographic inventory provides the visibility required to determine where quantum-vulnerable mechanisms are deployed, while subsequent testing and prioritisation establish how those mechanisms can be replaced without unacceptable operational disruption (Swisscom, 2025). The resulting transition is therefore likely to be iterative rather than instantaneous, with organisations progressively introducing post-quantum mechanisms as standards, implementations and vendor support mature.

The emergence of formal standards also strengthens the case for beginning migration before a cryptographically relevant quantum computer exists. Standardisation reduces some of the uncertainty surrounding algorithm selection, but it does not eliminate the time required for discovery, testing, procurement, implementation and system replacement. As established in Chapter 3, the relevant organisational deadline is therefore determined not only by when a quantum threat materialises, but also by how long the organisation requires to migrate its cryptographic infrastructure. PQC standardisation provides the technical foundation for that migration; cryptographic inventory, interoperability testing and crypto-agile architecture determine whether an organisation can implement it in time.

5. Crypto-Agility as an Organisational Capability

One of the central organisational implications of the quantum threat is that cryptographic migration cannot be treated solely as an algorithm-selection exercise. The Swisscom analysis places particular emphasis on crypto-agility, understood as an organisation's ability to identify, replace and adapt cryptographic mechanisms with limited operational disruption (Swisscom, 2025). This shifts the focus from selecting a single 'quantum-safe' solution towards developing an enduring capability to manage cryptographic change.

Cryptographic mechanisms are rarely isolated components. They are embedded throughout applications, operating systems, network protocols, digital certificates, identity and access-management systems, hardware security modules, databases and third-party products. Cryptography may also be incorporated into systems whose owners do not have direct visibility of the underlying implementation. Consequently, replacing an algorithm can require coordinated changes across multiple technical and organisational dependencies. NIST (2021) identifies this broader challenge in its guidance on preparing for post-quantum cryptography, emphasising the need for organisations to understand their existing cryptographic dependencies before attempting large-scale migration.

Crypto-agility addresses this problem by reducing the dependency between applications and particular cryptographic mechanisms. Where algorithms are tightly embedded within application code or hardware, replacement may require extensive redevelopment, testing and certification. By contrast, architectures that separate cryptographic functions from application logic can make algorithm replacement more manageable. Abstraction layers, configurable cryptographic libraries, algorithm negotiation, centralised key-management services and comprehensive cryptographic inventories can all contribute to this flexibility. The objective is not to eliminate the technical consequences of cryptographic change, but to reduce the time, cost and operational disruption associated with it.

The importance of this capability extends beyond the quantum transition. Cryptographic assumptions can become inadequate for a variety of reasons, including the discovery of new mathematical attacks, implementation vulnerabilities, weaknesses in parameter selection and changes in regulatory or interoperability requirements. Even post-quantum algorithms should not be assumed to be permanently secure. Continued cryptanalysis may reveal weaknesses that require parameter changes, algorithm replacement or the introduction of alternative cryptographic mechanisms. Crypto-agility therefore provides value under conditions of uncertainty regardless of whether the triggering event is a quantum breakthrough or a more conventional cryptographic failure.

This perspective also changes the way cryptographic risk should be understood. An organisation with cryptography that is difficult to replace may remain exposed even after an appropriate replacement algorithm has been identified. The relevant question is therefore not simply whether a secure algorithm exists, but whether the organisation can deploy that algorithm across its technology estate within the required timeframe. Crypto-agility consequently connects the technical problem of cryptographic vulnerability with the organisational problem of migration capacity.

The concept can therefore be understood as an option-preserving architectural property. An agile architecture preserves the organisation's ability to respond when cryptographic requirements change, whereas tightly coupled cryptographic dependencies can create technological lock-in and increase the cost of future transitions. This is particularly significant in the post-quantum context because the timing of the quantum threat remains uncertain while the migration process itself may take many years. Increasing the organisation's capacity to change cryptography reduces its dependence on accurately predicting when a cryptographically relevant quantum computer will emerge.

Crypto-agility should not, however, be confused with quantum security. It does not make an algorithm resistant to quantum attack, nor does it remove the need to select and validate appropriate cryptographic mechanisms. Rather, it addresses a different layer of the problem. PQC provides cryptographic mechanisms intended to withstand quantum attacks; crypto-agility provides the organisational and architectural capacity to deploy, replace and manage those mechanisms as requirements evolve. This distinction is important because a technically secure algorithm provides limited practical protection if an organisation cannot implement it across the systems that depend upon vulnerable cryptography.

The Swisscom analysis therefore supports viewing crypto-agility as part of broader organisational preparedness rather than as an optional technical enhancement (Swisscom, 2025). Effective post-quantum migration requires visibility of existing cryptographic dependencies, mechanisms for introducing replacement algorithms, testing and governance processes, and the ability to coordinate change across technology suppliers and internal systems. In this sense, crypto-agility converts cryptographic migration from a one-time remediation project into a continuing organisational capability.

The relationship between the concepts developed in the preceding chapters can consequently be expressed in three layers. The quantum threat creates the need for change; PQC provides the principal cryptographic mechanism for addressing that threat within conventional computing infrastructure; and crypto-agility determines how effectively an organisation can introduce and subsequently replace those mechanisms. This makes crypto-agility particularly important under uncertainty: organisations cannot control the development of quantum computing, but they can reduce the time and disruption associated with changing their own cryptographic infrastructure.

6. Quantum Key Distribution

Quantum key distribution (QKD) represents a fundamentally different response to the quantum threat from post-quantum cryptography. Whereas PQC seeks to construct classical cryptographic algorithms that remain secure against quantum-capable adversaries, QKD uses the properties of quantum-mechanical systems to establish shared secret keys between communicating parties. Its security model is therefore based on physical principles rather than on the assumed computational difficulty of a particular mathematical problem.

6.1 Security Properties

The principal theoretical attraction of QKD is that attempts to obtain information from a quantum communication channel can, under the assumptions of the relevant protocol and security model, introduce detectable disturbances. This creates a fundamentally different basis for key establishment from conventional public-key cryptography. The security of the resulting key does not depend upon assuming that a problem such as integer factorisation or discrete logarithms remains computationally infeasible for a sufficiently powerful quantum computer.

This distinction is particularly important in the context of the limitations of classical public-key cryptography identified in Chapter 2. Shor's algorithm demonstrates that the security assumptions underlying RSA and ECC would fail against a sufficiently capable cryptographically relevant quantum computer. QKD instead seeks to derive security from the physical behaviour of the communication system itself. It therefore addresses the quantum threat through a different security paradigm rather than through the replacement of one computational assumption with another.

However, descriptions of QKD as providing 'unconditional security' require careful qualification. Security proofs establish security within explicitly defined mathematical and physical models; they do not automatically guarantee the security of every physical implementation. Real QKD systems contain photon sources, detectors, optical components, control electronics, classical communication systems and software, all of which may deviate from the assumptions made in an idealised security proof.

Lo, Curty and Tamaki (2020) emphasise this distinction in their review of QKD with realistic devices. The security of a practical system depends not only on the underlying protocol but also on whether its implementation satisfies the assumptions on which the security analysis is based. This creates an important distinction between protocol-level security and implementation-level security. A protocol may have a rigorous security proof while a particular implementation remains vulnerable if physical imperfections create an exploitable side channel.

This issue has motivated substantial research into methods for reducing the dependence of security on specific device assumptions. Measurement-device-independent QKD, for example, was developed partly in response to vulnerabilities associated with imperfect detection systems. More broadly, the literature on practical QKD demonstrates that security analysis must encompass both the mathematical protocol and the physical system through which it is implemented (Lo, Curty and Tamaki, 2020; Tupkary et al., 2026).

QKD should therefore not be characterised simply as eliminating cryptographic assumptions. Rather, it changes the nature of those assumptions. Instead of relying primarily on the computational hardness of mathematical problems, QKD relies on the validity of physical models, protocol assumptions and implementation controls. Its security advantage must consequently be assessed in conjunction with the engineering conditions required to realise it.

6.2 Practical Constraints

The principal challenge for QKD is that its theoretical security properties must be delivered through specialised physical infrastructure. This creates constraints that do not arise to the same extent in conventional cryptography or PQC.

One important limitation is the effect of optical loss on quantum communication. In fibre-based systems, attenuation increases with distance and reduces the availability of usable quantum signals. This creates a fundamental trade-off between distance and achievable key generation rates. Diamanti et al. (2016) identify distance, key rate, cost, system size and practical security as significant challenges for the widespread deployment of QKD. These constraints mean that QKD cannot simply be assumed to provide a transparent replacement for conventional key-establishment mechanisms across large existing networks.

A second challenge concerns implementation security. Practical QKD systems contain physical components whose imperfections can create attack surfaces that are not present in an idealised protocol model. Research into quantum-hacking attacks has demonstrated that assumptions concerning sources and detectors can have direct security consequences. Countermeasures, including measurement-device-independent approaches, can reduce particular classes of implementation risk, but they also introduce additional technical and operational complexity (Lo, Curty and Tamaki, 2020). The security evaluation of QKD must therefore account for the complete system rather than considering the quantum protocol in isolation.

A third constraint is infrastructure. Unlike PQC, which can generally be implemented through modifications to existing software, protocols and conventional computing infrastructure, QKD requires specialised optical equipment and an appropriate communications environment. Depending on the network architecture, deployment may also involve dedicated fibre, carefully engineered optical links, trusted nodes or other specialised components. These requirements create additional capital, maintenance, interoperability and operational considerations.

The resulting distinction is important for understanding the appropriate role of QKD in a post-quantum security strategy. The technology offers a fundamentally different security model and may be particularly relevant where the confidentiality of information must be maintained over long periods and where the organisation can support the required physical infrastructure. However, its deployment constraints mean that it is not necessarily appropriate or economically practical for every communication system.

The Swisscom analysis therefore positions QKD as a selective rather than universal component of quantum-risk mitigation (Swisscom, 2025). This position is consistent with the broader academic literature, which identifies both the distinctive security properties of QKD and the significant practical challenges involved in implementing those properties in real-world systems (Diamanti et al., 2016; Lo, Curty and Tamaki, 2020). QKD and PQC should consequently be understood as complementary technologies rather than interchangeable alternatives. PQC offers a scalable approach to upgrading conventional cryptographic infrastructure, while QKD provides a specialised physical mechanism for key distribution where its security properties and infrastructure requirements are justified.

This distinction also reinforces the organisational argument developed in Chapter 5. The relevant question is not whether QKD is theoretically stronger than PQC in the abstract, but whether its security properties address a specific organisational risk sufficiently to justify the additional infrastructure and operational requirements. QKD therefore belongs within a risk-based architecture in which the sensitivity, confidentiality lifetime and communication environment of particular assets determine whether its deployment is appropriate.

Ultimately, QKD does not remove the need for cryptographic governance or crypto-agility. QKD systems still require authentication, secure classical communication channels, monitoring, implementation assurance and lifecycle management. Its contribution is instead to provide an additional security mechanism based on a different set of assumptions. A resilient post-quantum strategy can therefore combine conventional cryptographic migration through PQC with selective use of QKD where its distinctive security model provides sufficient value to justify its practical constraints.

7. PQC and QKD: Complementary Rather Than Equivalent Approaches

The preceding chapters demonstrate that post-quantum cryptography (PQC) and quantum key distribution (QKD) address the quantum threat through fundamentally different mechanisms. Although both can contribute to post-quantum security, they should not be treated as interchangeable technologies. Their differences concern not only their underlying security assumptions, but also their functions, infrastructure requirements, scalability and relationship with existing information systems.

PQC is primarily a cryptographic migration technology. It replaces vulnerable public-key mechanisms with algorithms designed to remain secure against known quantum attacks while continuing to operate through conventional computing and communications infrastructure. Its scope extends beyond key establishment to include digital signatures and other cryptographic functions. This makes PQC relevant to a wide range of systems affected by the vulnerability of RSA and ECC, including secure communications, authentication, certificates and software-signing infrastructure. The NIST standards for ML-KEM, ML-DSA and SLH-DSA demonstrate how this approach is being translated into standardised mechanisms for operational deployment (NIST, 2024a; NIST, 2024b; NIST, 2024c).

QKD instead represents a communications infrastructure technology. Its principal purpose is the establishment of shared secret keys using quantum-mechanical properties of a communication channel. Its security model therefore differs from PQC: rather than relying primarily on the computational difficulty of mathematical problems, QKD relies on quantum-mechanical principles together with assumptions concerning the protocol, physical devices and implementation. As discussed in Chapter 6, this does not eliminate security assumptions but changes their nature. Practical QKD remains dependent on the correct implementation and operation of sources, detectors, optical components and associated systems (Lo, Curty and Tamaki, 2020).

The two approaches also differ substantially in their compatibility with existing infrastructure. PQC can generally be incorporated into conventional systems through software updates, cryptographic libraries, protocol modifications, hardware upgrades and changes to certificate or key-management infrastructure. This does not make PQC migration simple, since cryptographic dependencies can be deeply embedded within an organisation's technology estate. Nevertheless, the underlying communication infrastructure can remain largely conventional. QKD, by contrast, requires physical systems capable of transmitting and processing quantum signals. Depending on the architecture, deployment may require specialised optical equipment, dedicated or engineered communication links and additional network infrastructure. These requirements create constraints that are not intrinsic to conventional cryptographic migration (Diamanti et al., 2016).

Their functional scope also differs. PQC can provide both quantum-resistant key establishment and digital signatures, making it relevant to the broader public-key infrastructure on which modern authentication and trust systems depend. QKD primarily addresses key establishment and does not provide a general replacement for digital signatures. Additional mechanisms are therefore required for authentication and other cryptographic functions. This means that an organisation adopting QKD cannot simply remove the wider requirement for cryptographic mechanisms that secure identities, software, certificates and system integrity.

The technologies also respond differently to the threat posed by Shor's algorithm. PQC directly addresses the problem by replacing RSA- and ECC-based mechanisms with constructions for which no efficient quantum attack is currently known (Bernstein and Lange, 2017). QKD takes a different approach by establishing keys without depending on the classical public-key hardness assumptions that would be undermined by Shor's algorithm. However, QKD does not itself solve every cryptographic consequence of quantum computing, particularly the need for quantum-resistant digital signatures and other cryptographic functions.

Distance and deployment constraints further distinguish the approaches. PQC generally operates over existing network infrastructure and therefore inherits the characteristics of the underlying conventional communications systems. QKD is subject to additional physical constraints associated with quantum-channel loss and the practical generation of secure keys over distance. Fibre attenuation can limit both achievable distance and key rates, while extending QKD networks can introduce additional architectural requirements such as trusted nodes or other specialised technologies (Diamanti et al., 2016). Consequently, QKD's deployment feasibility depends more directly on the physical characteristics of the communication environment.

The two approaches also present different implementation-risk profiles. PQC introduces conventional software and hardware security concerns, including coding errors, side-channel vulnerabilities, insecure parameter choices and weaknesses in implementations. QKD retains these general risks while introducing additional attack surfaces associated with quantum-optical components and their physical imperfections. Research into practical QKD has demonstrated that security proofs for idealised systems cannot simply be assumed to apply without qualification to deployed devices (Lo, Curty and Tamaki, 2020; Tupkary et al., 2026).

These differences have implications for organisational applicability. PQC has broad potential applicability because it can be integrated into conventional digital systems and deployed through existing software, hardware and network-management processes. QKD is more specialised because its benefits must be evaluated against the cost and feasibility of deploying the required physical infrastructure. This does not imply that QKD is inherently less valuable; rather, its applicability is more dependent on the characteristics of the communication environment and the sensitivity and longevity of the information being protected.

The relationship with crypto-agility is similarly different. PQC can be incorporated into architectures designed for algorithm substitution, allowing organisations to change cryptographic mechanisms as standards and security assumptions evolve. QKD can also be managed as part of an adaptable security architecture, but its dependence on physical infrastructure means that replacing or modifying the underlying system may involve more substantial operational constraints. Crypto-agility therefore remains relevant to both approaches, although it operates at different levels: for PQC, it can facilitate algorithm and protocol substitution; for QKD, it must also account for the lifecycle of specialised physical infrastructure.

These differences indicate that the choice between PQC and QKD should not be framed as a universal either/or decision. They address overlapping aspects of the quantum threat while operating according to different technical and organisational models. PQC provides a scalable mechanism for upgrading conventional cryptographic infrastructure, whereas QKD provides a specialised means of key establishment based on quantum-mechanical principles. In some environments, PQC may provide the principal migration path, while in others QKD may provide an additional layer of protection for particularly sensitive communications.

Hybrid architectures are therefore possible where the threat model, information sensitivity, confidentiality lifetime and infrastructure requirements justify their additional complexity. Such an architecture does not require the technologies to be treated as competing replacements. Instead, they can be assigned different roles within a broader defence strategy: PQC can address the widespread replacement of vulnerable public-key cryptography, while QKD can be selectively deployed where its distinctive security properties provide sufficient value to justify its infrastructure requirements.

The broader implication is that post-quantum security should be approached as a portfolio of cryptographic and architectural controls rather than a search for a single universal technology. PQC, QKD and crypto-agility address different layers of the problem. PQC changes the cryptographic mechanisms used by conventional systems; QKD changes how keys can be established in specialised communication environments; and crypto-agility determines how effectively an organisation can adapt these mechanisms as technology, standards and threat conditions evolve. This layered perspective provides a more realistic basis for organisational migration than treating PQC and QKD as equivalent alternatives.

8. A Risk-Based Migration Framework

The preceding analysis indicates that post-quantum migration should not be approached as a single technology replacement programme. The uncertainty surrounding the emergence of a cryptographically relevant quantum computer, combined with the long-lived nature of some information and the complexity of modern cryptographic dependencies, requires organisations to adopt a structured and risk-based approach. The Swisscom recommendations can therefore be synthesised with the academic literature into a staged migration framework based on discovery, prioritisation, architectural preparation, controlled deployment and continuous reassessment (Swisscom, 2025; NIST, 2021).

8.1 Phase 1: Cryptographic Discovery

The first requirement for effective migration is visibility. An organisation cannot determine its exposure to quantum-vulnerable cryptography without knowing where cryptographic mechanisms are deployed and how those mechanisms support business processes. A cryptographic inventory should therefore extend beyond algorithms and key lengths to include certificates, public-key infrastructures, TLS configurations, VPNs, identity systems, code-signing mechanisms, hardware security modules, databases, embedded systems, cloud services, third-party services and legacy applications.

NIST (2021) places cryptographic discovery at the centre of post-quantum migration planning because organisations frequently lack complete visibility of their cryptographic dependencies. This problem is particularly significant in large and decentralised technology estates, where cryptographic functions may be inherited from operating systems, software libraries, cloud platforms or supplier products rather than being explicitly selected by the organisation itself.

For this reason, cryptographic discovery should not be treated as a one-off manual exercise. Where technically feasible, discovery should be integrated with configuration management, software asset management, certificate management and security monitoring. Automated mechanisms can help identify cryptographic usage and changes over time, while governance processes should establish ownership for maintaining the resulting inventory. The objective is to create a continuously updated representation of the organisation's cryptographic estate rather than a static document produced solely for the purposes of a migration project.

8.2 Phase 2: Data Classification and Confidentiality Lifetime

Cryptographic exposure cannot be assessed independently of the information being protected. The consequences of a future compromise depend substantially on the value of the information and the period for which confidentiality is required. A short-lived public web session and a strategic research archive may use similar cryptographic protocols while presenting fundamentally different long-term risks.

Organisations should therefore classify information according to factors including confidentiality requirements, expected confidentiality lifetime, potential adversary interest, exposure to harvest-now-decrypt-later (HNDL) activity, cryptographic dependencies and migration complexity. This analysis links the technical properties of cryptography to the business value and temporal characteristics of the information being protected.

Confidentiality lifetime is particularly important because the quantum threat is inherently time-dependent. Information that must remain confidential for decades may need post-quantum protection even if a cryptographically relevant quantum computer does not yet exist. Conversely, information whose value expires rapidly may present a different migration priority. This approach transforms quantum risk from a generic technology concern into a portfolio-management problem in which different information assets require different levels and timings of protection.

8.3 Phase 3: Dependency and Threat Analysis

Once cryptographic assets and information have been identified, organisations must establish how cryptographic dependencies interact with critical business processes. Cryptography is often distributed across several technical layers, meaning that a change to one mechanism can affect multiple components. For example, an application may depend on an API gateway, which relies on TLS, a public-key infrastructure and certificate authority, a hardware security module and software supplied by an external vendor.

The resulting dependency chain means that assessing an individual algorithm in isolation is insufficient. Threat modelling should consider not only whether a cryptographic mechanism is vulnerable to quantum attack, but also where it is used, what systems depend upon it, how its compromise could propagate and how difficult it would be to replace. Particular attention should be given to systems where vulnerable public-key cryptography supports authentication, trust establishment, software signing or access to high-value information.

This analysis also provides a basis for prioritisation. A vulnerable cryptographic mechanism embedded within a low-value, short-lived application does not necessarily present the same urgency as the same mechanism embedded within a system protecting information with a long confidentiality lifetime. Risk is therefore a function of both cryptographic exposure and business context.

8.4 Phase 4: Crypto-Agile Architecture

The next phase is to reduce the architectural barriers that could make future cryptographic migration difficult. New systems should avoid hard-coding cryptographic algorithms and parameters wherever practical. Instead, cryptographic functions should be separated from application logic through appropriate abstraction mechanisms, allowing algorithms and parameters to be changed without requiring extensive redevelopment of dependent applications.

A crypto-agile architecture may incorporate configurable cryptographic mechanisms, centralised parameter management, controlled algorithm negotiation, automated certificate lifecycle management, central policy enforcement and telemetry concerning cryptographic usage. These capabilities can reduce the time and operational disruption associated with future transitions, consistent with the broader role of crypto-agility discussed in Chapter 5.

Crypto-agility must nevertheless be implemented carefully. Greater flexibility does not automatically produce greater security. For example, uncontrolled algorithm negotiation can introduce downgrade vulnerabilities if an attacker can influence the selection of a weaker mechanism. Similarly, excessive algorithm flexibility can make systems difficult to govern and test. Effective crypto-agility therefore requires explicit security policies, authenticated capability negotiation, controlled configuration and clear governance over which cryptographic mechanisms are permitted.

The objective is consequently not to allow unlimited cryptographic choice, but to create a controlled architecture in which approved cryptographic mechanisms can be replaced without fundamentally redesigning the surrounding system.

8.5 Phase 5: PQC Experimentation and Hybrid Deployment

PQC should initially be introduced through controlled experimentation and testing rather than immediate organisation-wide replacement. Although standardised algorithms provide a stable foundation for migration, their practical performance can vary according to the application, protocol and hardware environment in which they are deployed.

Testing should therefore examine computational performance, bandwidth requirements, key and ciphertext sizes, certificate sizes, latency, memory consumption, interoperability, hardware support and failure behaviour. Particular attention should also be given to authentication, downgrade resistance and interactions with existing protocols. These factors are important because a cryptographic mechanism that is secure in isolation may create operational problems when integrated into a complex production environment.

Hybrid mechanisms may provide a transitional approach in which classical and post-quantum cryptographic mechanisms are used together. Such configurations can reduce dependence on either mechanism alone during a period of technological transition, but hybridisation should not automatically be interpreted as providing stronger security. Combining mechanisms increases implementation and testing complexity and can introduce configuration or protocol weaknesses if not designed correctly. Hybrid deployment should therefore be treated as an engineering strategy whose security and operational properties require explicit validation.

Controlled experimentation also provides an opportunity to engage with technology suppliers. Vendor support, product roadmaps, firmware requirements, software compatibility and certification constraints can materially affect the feasibility and timing of migration. These factors should be incorporated into the migration plan rather than discovered only when production systems are being upgraded.

8.6 Phase 6: Migration of Critical Systems

Following discovery, assessment and controlled testing, migration should proceed according to risk rather than through indiscriminate replacement. The highest priority should generally be given to systems in which several risk factors coincide: the use of quantum-vulnerable public-key cryptography, protection of high-value information, long confidentiality requirements, significant adversarial interest, potential HNDL exposure and lengthy or technically complex migration processes.

This approach represents the operational application of the Mosca inequality discussed in Chapter 3. The relevant comparison is between the time required to complete migration and the period for which information must remain protected, on the one hand, and the uncertain arrival of a cryptographically relevant quantum threat, on the other. Organisations cannot control the latter, but they can influence the duration and complexity of their own migration process.

Prioritisation should therefore account for both technical vulnerability and organisational inertia. A system may require early migration not because it is necessarily the most vulnerable system in isolation, but because its combination of information sensitivity, exposure and migration complexity creates a significant risk if remediation is delayed. Conversely, systems with lower-value information or short confidentiality lifetimes may be scheduled differently, allowing limited resources to be concentrated where they have greater risk-reduction value.

8.7 Phase 7: Continuous Reassessment

Post-quantum migration should not be regarded as a project with a permanently fixed completion point. Cryptographic standards can evolve, new attacks can emerge, implementations can develop vulnerabilities and new algorithms may become available. At the same time, quantum-computing capabilities and resource estimates will continue to change.

Continuous reassessment should therefore form part of the organisation's normal security governance. Cryptographic inventories should be updated as systems change, newly identified vulnerabilities should be incorporated into risk assessments, and the performance and security of deployed PQC mechanisms should be monitored. Changes in standards, vendor support and the quantum threat landscape should likewise be reflected in migration priorities.

This creates a fundamentally different conception of the desired end-state. The objective is not simply to reach a static condition described as 'quantum-safe cryptography'. Such a designation could become misleading if the underlying algorithms, assumptions or implementation environment subsequently change. The more resilient objective is to establish an organisation capable of repeated cryptographic transition.

The seven phases therefore form a continuous cycle rather than a strictly linear project. Discovery establishes visibility; data classification establishes the value and confidentiality lifetime of protected information; dependency analysis connects cryptographic exposure to business processes; crypto-agile architecture reduces the cost of future change; experimentation establishes practical feasibility; risk-based migration prioritises implementation; and continuous reassessment ensures that the organisation can respond to subsequent changes.

This framework brings together the principal themes developed throughout this paper. The quantum threat creates uncertainty over the future security of existing cryptography, while HNDL creates a potential present-day consequence for information with long confidentiality lifetimes. PQC provides the principal scalable mechanism for replacing vulnerable public-key cryptography, while QKD may provide a specialised complementary capability in appropriate environments. Crypto-agility provides the architectural and organisational means of managing these changes over time. The resulting strategic objective is therefore not to predict precisely when quantum computing will become cryptographically relevant, but to ensure that the organisation can complete the necessary transition before its existing cryptographic assumptions cease to provide adequate protection.

9. Critical Assessment of the Swisscom White Paper

The Swisscom white paper provides a useful bridge between academic research on quantum cryptography and the practical challenges faced by organisations preparing for post-quantum migration. Its principal contribution is arguably its reframing of quantum security as an organisational preparedness problem rather than solely as a future technological event (Swisscom, 2025). This perspective is broadly consistent with the academic literature, which increasingly emphasises not only the theoretical consequences of quantum algorithms but also the practical challenges of migration, implementation and long-term cryptographic governance.

Several aspects of the Swisscom analysis are particularly well supported by the literature. First, its distinction between the effects of quantum computing on asymmetric and symmetric cryptography is fundamental. Shor's algorithm creates a structural threat to widely deployed public-key mechanisms based on integer factorisation and discrete logarithms, including RSA and ECC, whereas Grover's algorithm provides a quadratic search speed-up against symmetric-key search spaces rather than rendering symmetric cryptography fundamentally insecure (Shor, 1994; Grover, 1996). The resulting asymmetry justifies prioritising public-key migration while recognising that appropriately selected symmetric key sizes can provide continued protection against quantum-enabled search attacks.

Second, Swisscom's emphasis on migration timing is supported by the logic underlying the Mosca framework and the HNDL threat. The security of information cannot be assessed solely according to whether a quantum computer exists today. If information must remain confidential for a period extending beyond the time required to migrate the systems protecting it, an organisation may need to begin migration before the quantum threat becomes operationally demonstrable. This is particularly relevant to information that can be collected and retained by an adversary before future decryption becomes possible. The resulting risk is therefore temporal: the appropriate migration date depends on the confidentiality lifetime of information, the time required to migrate and the uncertain development of quantum computing capabilities (Mosca, 2018; Mosca and Piani, 2024).

Third, Swisscom's emphasis on crypto-agility corresponds closely with contemporary post-quantum migration guidance. NIST (2021) places substantial importance on cryptographic discovery and migration planning, while the development of formal PQC standards provides a basis for organisations to begin replacing vulnerable mechanisms (NIST, 2024a; NIST, 2024b; NIST, 2024c). Swisscom's focus on inventories, staged migration and the ability to change cryptographic mechanisms therefore reflects a broader recognition that post-quantum security is as much an architectural and organisational challenge as a cryptographic one.

The white paper should nevertheless be interpreted critically in several areas.

The first concerns forecasts of when cryptographically relevant quantum computers may emerge. Estimates of the arrival of such systems are necessarily uncertain because they depend on advances across multiple areas of quantum hardware and error correction. The number of physical qubits alone is an inadequate measure of cryptographic capability; relevant factors also include logical qubit requirements, error rates, error-correction overhead, gate fidelity, circuit depth and computational throughput. Expert assessments such as those collected by Mosca and Piani (2024) can therefore inform risk management, but they should not be interpreted as deterministic technological forecasts. The appropriate organisational response to uncertainty is consequently not to select a single predicted date, but to ensure that migration can be completed within a sufficiently short timeframe.

A second area requiring qualification is the interpretation of QKD. Its distinctive security model is an important feature, but theoretical security does not eliminate implementation or operational risk. Practical systems contain sources, detectors, optical components, control electronics and software that may deviate from the assumptions of idealised security proofs. Research into realistic QKD has identified implementation vulnerabilities and the need for security models that account for real devices (Lo, Curty and Tamaki, 2020). Practical deployment also introduces constraints involving distance, key rates, infrastructure, cost and availability (Diamanti et al., 2016). More recent research continues to examine the limitations and assumptions associated with security proofs for practical QKD systems (Tupkary et al., 2026). QKD should therefore be considered within a broader security architecture rather than treated as a standalone guarantee of secure communications.

Third, the recommendations should not be interpreted as implying that the adoption of a particular PQC algorithm represents a permanent endpoint. Cryptographic security is inherently contingent on current mathematical knowledge, implementation quality and the continued validity of underlying security assumptions. An algorithm that is considered secure today may subsequently be weakened by advances in cryptanalysis, implementation research or the discovery of previously unknown attack techniques. The standardisation of ML-KEM, ML-DSA and SLH-DSA therefore represents an important stage in migration, but not the end of cryptographic evolution (NIST, 2024a; NIST, 2024b; NIST, 2024c).

This point is particularly important when assessing the concept of 'quantum-safe' security. The term can imply a static property, whereas post-quantum security is better understood as a risk-management process under changing assumptions. The relevant objective is not to identify a mechanism that can be assumed to remain secure indefinitely, but to establish sufficient visibility, flexibility and governance to replace cryptographic mechanisms when their security assumptions become inadequate. This is where the Swisscom emphasis on crypto-agility becomes particularly significant: agility provides a means of responding to future cryptographic developments rather than assuming that the current generation of PQC mechanisms will remain optimal indefinitely.

A further limitation of the Swisscom analysis is that enterprise recommendations necessarily operate at a level of abstraction that cannot capture every sector-specific constraint. Migration requirements will vary according to regulatory obligations, legacy infrastructure, supply-chain dependencies, hardware lifecycles and the sensitivity and longevity of information. A financial institution, a telecommunications provider, a healthcare organisation and a manufacturer may therefore face substantially different migration pathways even when they use similar cryptographic primitives. The Swisscom framework is most useful when interpreted as a set of general principles rather than as a uniform implementation blueprint.

Overall, the Swisscom white paper is most valuable not because it provides a definitive prediction of the quantum future, but because it translates an uncertain technological threat into a set of organisational questions. Where is vulnerable cryptography deployed? Which information requires long-term confidentiality? How long would migration take? Which systems are dependent upon particular cryptographic mechanisms? Can those mechanisms be replaced without unacceptable disruption? These questions connect the theoretical findings of quantum cryptography with the practical requirements of enterprise security.

The critical assessment therefore supports the central argument developed throughout this paper. The quantum threat should neither be reduced to a prediction about when a cryptographically relevant quantum computer will appear nor treated as a justification for adopting a single technology without qualification. Shor's algorithm establishes a fundamental future threat to important public-key cryptographic mechanisms; Grover's algorithm creates a more limited threat to symmetric-key security; HNDL creates a present-day reason to consider the future confidentiality of stored information; PQC provides a scalable mechanism for migration; QKD offers a specialised complementary security approach; and crypto-agility provides the organisational capability required to adapt as cryptographic assumptions evolve.

The enduring lesson is therefore broader than post-quantum cryptography itself. The most resilient response to an uncertain cryptographic future is not certainty about which algorithm will remain secure, but the organisational capacity to discover, assess and replace cryptographic mechanisms before their underlying security assumptions become inadequate. In this respect, the Swisscom white paper provides a useful practical framework, while the academic literature supplies the theoretical and empirical qualifications necessary for applying that framework responsibly.

10. Discussion

The literature examined throughout this paper suggests that the transition to post-quantum security is best understood through three interacting dimensions: technical vulnerability, temporal exposure and organisational adaptability. Considering these dimensions together provides a more complete account of quantum risk than focusing exclusively on the theoretical capabilities of quantum algorithms or on the selection of individual post-quantum cryptographic mechanisms.

The first dimension is technical vulnerability. This concerns whether a cryptographic mechanism can be compromised or materially weakened by quantum computation. The most significant examples are RSA and elliptic-curve cryptography (ECC), whose security depends on mathematical problems that can be addressed efficiently by Shor's algorithm on a sufficiently capable quantum computer (Shor, 1994). Symmetric cryptography presents a different situation. Grover's algorithm provides a quadratic search advantage rather than a comparable structural break, meaning that symmetric cryptography is subject to security degradation rather than wholesale displacement (Grover, 1996). This distinction is important because it means that the quantum transition does not affect all cryptographic mechanisms equally and therefore should not be approached as a uniform technology replacement exercise.

The second dimension is temporal exposure. The existence of a theoretical quantum attack does not determine the immediate practical significance of that vulnerability for every asset. The consequences depend partly on how long the information must remain confidential. Information whose value expires within a short period may have substantially different quantum-risk characteristics from information that must remain confidential for several decades. The HNDL threat further demonstrates why this temporal dimension cannot be reduced to the date on which a cryptographically relevant quantum computer becomes operational. Information intercepted and retained today may become vulnerable to future decryption, meaning that the relevant security horizon can extend well beyond the present capabilities of an adversary (Mosca, 2018; Mosca and Piani, 2024).

The third dimension is organisational adaptability. Even when a vulnerable cryptographic mechanism has been identified and a suitable replacement exists, an organisation remains exposed if it cannot implement that replacement within the necessary timeframe. Large technology estates may contain cryptographic dependencies across applications, certificates, identity systems, hardware, cloud services, third-party products and legacy infrastructure. The practical significance of a cryptographic vulnerability is therefore partly determined by the organisation's ability to discover where the mechanism is deployed, understand its dependencies and replace it without unacceptable disruption.

These three dimensions interact rather than operating independently. Technical vulnerability establishes the potential for cryptographic compromise; temporal exposure determines the significance of that vulnerability for a particular asset; and organisational adaptability determines the ability to reduce the resulting risk within the available timeframe. Consequently, the same vulnerable algorithm can have radically different organisational significance in different environments. An RSA implementation protecting short-lived, low-value information may present a different migration priority from an RSA-based mechanism protecting highly sensitive information that must remain confidential for decades.

This interaction also explains why a purely algorithmic response is insufficient. The existence of a theoretically suitable PQC algorithm does not itself create organisational security. For example, an organisation may have access to standardised post-quantum mechanisms but remain unable to migrate effectively if it cannot determine where quantum-vulnerable certificates, keys or protocols are deployed. Conversely, an organisation may possess a comprehensive cryptographic inventory but still face significant exposure if applications contain hard-coded algorithms or if replacing cryptographic mechanisms requires extensive redesign of critical systems.

The practical value of crypto-agility therefore lies in its role as the connecting mechanism between cryptographic capability and organisational resilience. PQC provides mechanisms intended to address the technical vulnerability of conventional public-key cryptography, while crypto-agility determines how effectively those mechanisms can be introduced and subsequently replaced as requirements evolve. This distinction is particularly important because no cryptographic algorithm should be regarded as permanently secure. The emergence of new attacks, implementation weaknesses, changes in standards or advances in computing can all create circumstances in which another transition becomes necessary.

The discussion also highlights why quantum preparedness should not be reduced to a single technological decision. QKD, for example, provides a different security model and may be appropriate for selected high-value communications, but its specialised infrastructure means that it cannot simply substitute for conventional cryptographic migration across an entire technology estate. Similarly, PQC provides a scalable migration mechanism but remains subject to the assumptions and implementation risks associated with any cryptographic technology. The appropriate response is therefore determined by the interaction between the security requirements of particular assets and the technical and organisational environment in which they operate.

This perspective provides a more useful interpretation of uncertainty surrounding the development of quantum computing. Organisations cannot directly control the rate of progress in quantum hardware, nor can they reliably determine the precise date at which a cryptographically relevant quantum computer will become available. They can, however, influence their own migration time, improve visibility of cryptographic dependencies, classify information according to confidentiality lifetime, introduce crypto-agile architectures and establish processes for evaluating emerging cryptographic mechanisms. Organisational adaptability therefore provides a controllable variable within an otherwise highly uncertain threat environment.

The resulting conceptual model is not intended to function as a quantitative risk equation. Rather, it illustrates the relationship between the three dimensions. Technical vulnerability identifies what can be attacked; temporal exposure identifies when the consequences matter; and organisational adaptability determines whether the organisation can respond in time. A meaningful assessment of post-quantum risk therefore requires all three dimensions to be considered together.

This synthesis reinforces the central argument of the paper. The quantum transition is not simply a future event in which existing cryptographic algorithms suddenly become obsolete. It is a prolonged process in which organisations must manage changing technological capabilities, information lifecycles, cryptographic assumptions and infrastructure dependencies. The most important capability is consequently not the ability to predict the precise arrival of a cryptographically relevant quantum computer, but the ability to reduce migration time and maintain sufficient flexibility to respond as the threat develops.

In this sense, post-quantum readiness represents an organisational capability rather than a fixed technological state. An organisation is better prepared not merely when it has adopted a particular set of PQC algorithms, but when it can identify vulnerable cryptography, understand the value and lifetime of the information it protects, prioritise migration according to risk and introduce alternative mechanisms without unacceptable disruption. The interaction of technical vulnerability, temporal exposure and organisational adaptability therefore provides a useful framework for understanding why quantum security is ultimately as much a problem of organisational resilience as it is of cryptographic engineering.

11. Recommendations

The analysis developed throughout this paper indicates that post-quantum preparedness should be implemented as a structured, risk-based programme rather than as a single technology deployment. The Swisscom white paper and academic literature point towards a progression from visibility and governance, through controlled experimentation and prioritised migration, towards continuous cryptographic adaptation (Swisscom, 2025; NIST, 2021). The following recommendations translate these principles into an organisational programme.

11.1 Immediate Priorities

The immediate priority should be to establish visibility of both information assets and the cryptographic mechanisms protecting them. Organisations should first identify information requiring long-term confidentiality and determine which cryptographic systems protect that information. This is particularly important for assets that may be exposed to HNDL activity, since their confidentiality requirements can extend beyond the period in which current cryptographic protection is expected to remain adequate.

Organisations should then establish an automated cryptographic inventory covering, where feasible, algorithms, key sizes, certificates, public-key infrastructures, protocols, applications, hardware and third-party dependencies. Particular attention should be given to identifying RSA and ECC dependencies throughout the technology estate, including systems in which these mechanisms are embedded indirectly through software libraries, operating systems, cloud services or supplier products. NIST (2021) similarly identifies cryptographic discovery as a foundational component of post-quantum migration.

Governance should be established alongside technical discovery. Post-quantum migration should not be treated exclusively as a cybersecurity responsibility because decisions concerning architecture, procurement, risk, legal obligations, technology lifecycles and supplier relationships can materially affect migration feasibility. A cross-functional governance structure should therefore establish ownership, prioritisation criteria, migration milestones and accountability for maintaining the cryptographic inventory.

11.2 Near-Term Priorities

Once visibility has been established, organisations should begin reducing the architectural barriers to future cryptographic change. New systems should incorporate crypto-agility requirements wherever practical, including appropriate abstraction between applications and cryptographic mechanisms, controlled algorithm configuration and automated certificate lifecycle management. This reduces the risk that new technology will reproduce the cryptographic dependencies that make legacy migration difficult.

Supplier engagement should form another important part of this stage. Organisations should determine whether critical vendors support the relevant NIST-standardised PQC mechanisms, whether hardware or firmware changes are required and what migration roadmaps are available. This is particularly important for systems with long procurement and replacement cycles, where migration may depend on supplier product lifecycles rather than solely on internal technical decisions.

Organisations should also begin controlled experimentation with standardised PQC mechanisms, including ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures (NIST, 2024a; NIST, 2024b; NIST, 2024c). Pilot deployments should be conducted in representative environments rather than purely laboratory settings so that organisations can identify practical compatibility and performance issues.

Where operationally appropriate, hybrid mechanisms combining classical and post-quantum approaches should also be evaluated. Hybridisation may provide a useful transitional strategy, but it should not automatically be assumed to provide greater security. Additional cryptographic and protocol complexity can introduce implementation risks, so hybrid configurations should be tested for interoperability, failure behaviour and downgrade resistance before production deployment.

Testing should assess more than cryptographic correctness. Organisations should evaluate computational performance, memory requirements, network overhead, key and ciphertext sizes, certificate sizes, latency, hardware compatibility and interactions with existing protocols. This establishes whether a particular mechanism is suitable for the operational environment in which it will be deployed.

11.3 Medium-Term Priorities

As experimentation produces evidence about technical feasibility, organisations should begin prioritised migration of production systems. Migration should be driven by the characteristics of the information and business processes being protected rather than by a uniform replacement schedule. Systems combining quantum-vulnerable cryptography, high-value information, long confidentiality lifetimes, significant adversarial interest and substantial migration complexity should receive particular attention.

This prioritisation represents the practical application of the Mosca inequality developed earlier in the paper. Organisations should periodically compare the time required to migrate critical systems and the required confidentiality lifetime of the information with the uncertain timeframe associated with the quantum threat (Mosca, 2018; Mosca and Piani, 2024). The purpose is not to predict a precise quantum-computing deadline, but to identify cases where delaying migration could result in insufficient protection.

Public-key infrastructure should receive particular attention during this stage. Certificates, certificate authorities, key-management systems and associated trust relationships can create extensive dependencies across an organisation. Modernising PKI and automating certificate lifecycle management can therefore reduce both existing migration barriers and the cost of future cryptographic transitions.

Legacy systems require separate consideration. Some older applications, embedded devices and operational technologies may not support modern cryptographic mechanisms without hardware replacement, firmware updates or significant redesign. These systems should be explicitly identified and incorporated into long-term technology lifecycle planning rather than excluded from the cryptographic inventory because migration is difficult.

Symmetric cryptographic configurations should also be reviewed. The quantum threat to symmetric cryptography differs from the threat to RSA and ECC, since Grover's algorithm provides a quadratic search advantage rather than an equivalent structural break (Grover, 1996). Organisations should therefore assess whether existing key sizes and configurations provide an appropriate security margin against quantum-enabled search rather than treating symmetric and asymmetric migration as identical problems.

QKD should be assessed selectively during this stage. Its specialised infrastructure, distance limitations and implementation requirements mean that it should be considered primarily where its particular security properties address a clearly identified risk and justify the additional operational complexity (Diamanti et al., 2016; Lo, Curty and Tamaki, 2020). It should complement rather than replace the broader programme of conventional cryptographic migration.

11.4 Long-Term Priorities

Post-quantum migration should ultimately become part of continuous security governance rather than remaining a finite transformation programme. Cryptographic discovery should therefore be maintained as an ongoing capability so that new systems, certificates, applications and supplier dependencies are incorporated into the organisation's understanding of its cryptographic estate.

Organisations should also monitor developments in quantum algorithms and hardware. Changes in quantum resource estimates, error-correction techniques or hardware capabilities may alter the urgency associated with particular cryptographic mechanisms. However, such monitoring should inform rather than replace migration activity. Waiting for certainty about quantum hardware would leave organisations dependent on an uncertain external timetable while their own migration requirements remain largely within their control.

The security of the PQC ecosystem should likewise be monitored continuously. Standardisation does not establish permanent security, and future cryptanalysis or implementation research may identify weaknesses requiring changes in algorithms, parameters or deployment practices. Organisations should therefore maintain processes for assessing developments affecting the PQC mechanisms on which they depend.

The Mosca inequality should also be periodically reassessed for critical information assets. Changes in data value, confidentiality requirements, system architecture, migration progress and the external threat environment can alter the appropriate migration priority. A risk assessment performed once at the beginning of a migration programme may therefore become obsolete as organisational and technological conditions change.

Finally, cryptographic migration should be incorporated into operational resilience testing. Organisations should periodically exercise the processes required to replace certificates, algorithms, keys and cryptographic libraries under controlled conditions. Such exercises can reveal dependencies that are difficult to identify through documentation alone and can establish whether theoretical crypto-agility translates into practical migration capability.

Taken together, these recommendations define a transition from visibility to adaptability. Organisations should first establish where cryptography is used and which information requires long-term protection. They should then develop the architectural capability to change cryptographic mechanisms, test standardised PQC technologies, prioritise migration according to risk and maintain continuous oversight of cryptographic developments. QKD can be evaluated selectively where its distinctive security model provides sufficient value to justify its infrastructure requirements.

The resulting objective is therefore not simply to complete a one-time migration to post-quantum algorithms. It is to establish an enduring organisational capability in which cryptographic assets are discoverable, migration priorities are risk-based, replacement mechanisms can be tested and deployed, and future cryptographic transitions can be conducted without unacceptable disruption. This approach directly addresses the central uncertainty identified throughout the paper: organisations cannot determine precisely when quantum computing will become a practical threat to current cryptography, but they can improve their ability to respond before existing security assumptions become inadequate.

12. Conclusion

The prospect of cryptographically relevant quantum computing presents a distinctive cybersecurity challenge because the underlying threat is theoretically well established while its practical timing remains uncertain. Shor’s algorithm demonstrates that sufficiently capable quantum computers could efficiently solve the mathematical problems underpinning widely deployed public-key systems such as RSA and elliptic-curve cryptography (Shor, 1994). Consequently, the central question for organisations is not whether current public-key cryptography is theoretically vulnerable to quantum computing, but whether organisations will be capable of transitioning their cryptographic infrastructure before that vulnerability becomes operationally significant.

The analysis undertaken in this paper demonstrates that this challenge has both technical and organisational dimensions. Quantum computing does not affect all cryptographic mechanisms in the same way. Public-key cryptography faces the most fundamental disruption because of Shor’s algorithm, whereas symmetric cryptography is subject to a more limited security reduction associated with Grover’s algorithm (Grover, 1996). This distinction is important because it prevents quantum risk from being treated as a uniform problem requiring the wholesale replacement of all cryptographic mechanisms. Instead, organisations need to understand which cryptographic assets are vulnerable, what information they protect, how long that information must remain confidential, and how difficult those mechanisms will be to replace.

The uncertainty surrounding the development of a cryptographically relevant quantum computer is a further reason for adopting a risk-based approach. Estimates of when such a capability might emerge vary considerably, and current forecasts should not be treated as precise deadlines (Mosca and Piani, 2024). Nevertheless, the absence of a reliable date does not imply that organisations can defer action indefinitely. The ‘harvest now, decrypt later’ threat creates a present-day concern for information whose confidentiality extends into a future period in which quantum attacks may be feasible. Similarly, migration itself can require substantial time because cryptography is embedded across applications, protocols, certificates, hardware, software, supplier products and operational processes (NIST, 2021). The relevant risk therefore emerges from the relationship between information longevity, migration time and the uncertain quantum threat horizon.

Within this context, post-quantum cryptography provides the principal mechanism for large-scale cryptographic migration. Standards such as ML-KEM, ML-DSA and SLH-DSA provide organisations with standardised algorithms that can operate within conventional computing environments (NIST, 2024a; NIST, 2024b; NIST, 2024c). Their standardisation is significant not only because it establishes technical specifications, but also because it enables organisations, vendors and technology providers to begin developing interoperable implementations and migration strategies. However, PQC should not be interpreted as a permanent endpoint. Its security is based on current assumptions about the difficulty of underlying mathematical problems, meaning that future cryptanalytic advances or implementation weaknesses could require further transitions. The objective should therefore be migration capability rather than dependence on any single cryptographic standard.

Quantum key distribution represents a different response. Rather than relying primarily on computational assumptions, QKD uses properties of quantum communication to establish shared keys. This creates a fundamentally different security model, but it also introduces substantial practical constraints, including specialised hardware, distance limitations, optical losses, implementation vulnerabilities, operational complexity and, in some deployments, dependence on trusted nodes (Lo, Curty and Tamaki, 2020; Diamanti et al., 2016). Consequently, QKD cannot be regarded as a universal replacement for conventional cryptographic infrastructure. Its potential role is better understood as a specialised component within a broader security architecture, particularly where the value and longevity of protected communications justify the associated infrastructure and operational requirements.

The comparison between PQC and QKD therefore leads to an important conclusion: they should not be framed as competing solutions to the same problem. PQC primarily represents a cryptographic migration strategy that can be deployed across existing digital infrastructure, whereas QKD represents a specialised communications technology with different assumptions and requirements. Where appropriate, the two approaches can coexist, but their adoption should be determined by asset value, threat exposure, information longevity, infrastructure requirements and organisational capability rather than by the assumption that one technology can universally replace the other.

The analysis further identifies crypto-agility as the connecting organisational capability. Cryptographic algorithms are not isolated technical components. They are embedded within applications, identity systems, public-key infrastructures, protocols, certificates, hardware security modules, operating environments and third-party products. If these dependencies cannot be identified or changed efficiently, even technically mature replacement algorithms cannot provide a timely migration path. Crypto-agility therefore extends beyond algorithm selection. It encompasses cryptographic inventory, abstraction, dependency management, flexible architectures, automated certificate and key management, supplier coordination, interoperability testing and the ability to execute cryptographic transitions with limited operational disruption.

This leads to the central finding of the paper: post-quantum readiness is better understood as an organisational capability than as a fixed technical state. An organisation cannot reliably determine when the quantum threat will become operationally significant, nor can it guarantee that today's cryptographic assumptions will remain valid indefinitely. It can, however, improve its visibility of cryptographic dependencies, prioritise information according to its confidentiality lifetime, reduce migration barriers and establish processes for replacing cryptographic mechanisms when circumstances change. These capabilities remain valuable even if the development of cryptographically relevant quantum computers takes longer than current expectations, because cryptographic systems may also need to change in response to conventional cryptanalytic advances, implementation vulnerabilities, regulatory requirements or new technological developments.

The practical implication is that quantum preparedness should be treated as a continuing programme of cryptographic risk management rather than a one-time compliance exercise. Organisations should progressively establish visibility over their cryptographic estate, prioritise long-lived and high-value information, test post-quantum mechanisms, modernise systems that create migration dependencies and develop architectures capable of supporting future cryptographic transitions. The purpose is not to predict the precise arrival date of a cryptographically relevant quantum computer. Rather, it is to ensure that the organisation can respond within the available window when the technological and threat environment changes.

Ultimately, the quantum transition demonstrates a broader principle of cybersecurity: resilience depends not only on the strength of the security mechanism currently deployed, but also on the ability to replace that mechanism when its assumptions cease to be sufficient. PQC provides a practical foundation for large-scale migration, QKD offers a specialised complementary option in appropriate circumstances, and crypto-agility provides the organisational capability that allows both approaches to evolve as evidence and technology develop. Preparing for the quantum era is therefore not simply a matter of finding a new cryptographic algorithm. It is a matter of building the capacity to understand, adapt and repeatedly transition the cryptographic foundations on which digital systems depend.

References

Bernstein, D.J. and Lange, T. (2017) 'Post-quantum cryptography', Nature, 549, pp. 188–194.

Brassard, G., Lütkenhaus, N., Mor, T. and Sanders, B.C. (2000) 'Limitations on practical quantum cryptography', Physical Review Letters, 85(6), pp. 1330–1333.

Diamanti, E., Lo, H.-K., Qi, B. and Yuan, Z. (2016) 'Practical challenges in quantum key distribution', npj Quantum Information, 2, 16025.

Grover, L.K. (1996) 'A fast quantum mechanical algorithm for database search', in Proceedings of the 28th Annual ACM Symposium on Theory of Computing. New York: ACM, pp. 212–219.

Lo, H.-K., Curty, M. and Tamaki, K. (2020) 'Secure quantum key distribution with realistic devices', Reviews of Modern Physics, 92, 025002.

Mosca, M. (2018) 'Cybersecurity in an era with quantum computers: Will we be ready?', IEEE Security & Privacy, 16(5), pp. 38–41. doi: 10.1109/MSP.2018.3761723.

Mosca, M. and Piani, M. (2024) Quantum Threat Timeline Report 2024. Global Risk Institute.

NIST (2024a) FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard. Gaithersburg, MD: National Institute of Standards and Technology.

NIST (2024b) FIPS 204: Module-Lattice-Based Digital Signature Standard. Gaithersburg, MD: National Institute of Standards and Technology.

NIST (2024c) FIPS 205: Stateless Hash-Based Digital Signature Standard. Gaithersburg, MD: National Institute of Standards and Technology.

NIST (2021) Getting Ready for Post-Quantum Cryptography: Exploring Challenges Associated with Adopting and Using Post-Quantum Cryptographic Algorithms. NIST Cybersecurity White Paper CSWP 15. Gaithersburg, MD: National Institute of Standards and Technology.

Roetteler, M., Naehrig, M., Svore, K.M. and Lauter, K. (2017) 'Quantum resource estimates for computing elliptic curve discrete logarithms', in Advances in Cryptology – ASIACRYPT 2017. Cham: Springer.

Shor, P.W. (1994) 'Algorithms for quantum computation: discrete logarithms and factoring', in Proceedings of the 35th Annual Symposium on Foundations of Computer Science. Los Alamitos, CA: IEEE Computer Society Press, pp. 124–134.

Swisscom (2025) Post Quantum Security: Quantum Computing – All Secrets Unveiled? Swisscom, 30 May.

Tupkary, D., Tan, E.Y.-Z., Nahar, S., Kamin, L. and Lütkenhaus, N. (2026) 'Security proofs for practical QKD: Variations, techniques, gaps, and limitations', Reviews of Modern Physics, 98, 035003

Contact

Reach out via email for inquiries.

Email

Subscribe to newsletter

info@grcadvisory.ch

© 2025. All rights reserved.