Skip to main contentSkip to footer
Post Quantum Cryptography
HomeAdvisoryPost-Quantum Cryptography

Your data encrypted today can be decrypted tomorrow

Post-Quantum Cryptography Assessments

Quantum computing isn't a distant hypothetical anymore.

Microsoft and IBM both expect to deliver scalable, fault-tolerant quantum computers by 2029. On the defensive side, Google and Cloudflare have set the same year as their target for full post-quantum migration, and Let's Encrypt is rolling out Merkle Tree Certificates for the post-quantum Web PKI starting in 2027.

The builders and the defenders agree on 2029.

The only question is whether your organisation will be ready.

Growth

75% of Swiss traffic to Cloudflare is already post-quantum secure.

Race flag

<1% network overhead, zero user-visible impact when enabling PQC TLS key exchange on your webapp.

Alarm clock

Today adversaries are already harvesting encrypted data

Calendar

3 years until the 2029 industry target.

Regulatory Direction

The signals are converging fast.

Switzerland

Switzerland. The Swiss NCSC recommended PQC adoption in December 2025 to counter harvest-now-decrypt-later attacks. The BIT is already migrating the Swiss Government PKI. In July 2026, FINMA published guidance for financial institutions to adopt a PQC roadmap by mid-2027. Both the Swiss Bankers Association and SIX have flagged PQC migration as urgent for the financial sector.

Europe

Europe. The EU PQC Roadmap recommends that products entering the market with an expected lifetime beyond 2030 be upgradable to PQC and the EU Cyber Resilience Act requires state-of-the-art encryption for products entering the EU market after 2027. France's ANSSI plans to stop certifying security products that lack quantum-resistant cryptography from 2027.

US

United States. NIST deprecates quantum-vulnerable algorithms after 2030. An executive order from June 2026 sets hard deadlines for federal PQC migration: key establishment by December 2030 and digital signatures by December 2031.

UK

United Kingdom. The NCSC expects companies to complete cryptographic discovery by 2028 and priority migration by 2031.

Organisations that start now migrate on their terms. Those that wait will migrate under pressure.

Where is cryptography used? Which systems rely on quantum-vulnerable algorithms?

Our vendor-neutral PQC assessment

SOS