The quantum threat to modern cryptography
Quantum computing threatens the cryptography that protects your business. That risk is no longer distant or hypothetical, and it raises two questions for any organisation: is the data you are protecting today already exposed, and will the systems your business runs on still be secure the day quantum computers arrive?
An adversary could capture some of your company's encrypted communications as they travel across the internet, store them for years, and later use a cryptographically relev-ant quantum computer (CRQC) to decrypt them, exposing secrets. This is known as a 'harvest-now-decrypt-later' (HNDL) attack, and it especially matters for data that must remain secret for years, such as client records, contracts, or intellectual property. But why would a CRQC be able to break encryption that is secure today? The answer lies in two quantum algorithms.
The two algorithms behind the threat
Quantum computers don't beat classical ones at everything. They outperform them at a specific set of problems classical computers can't solve in practice. And it is precisely on some of these problems that much of public-key cryptography relies.
Shor's algorithm, published in 1994, efficiently solves, on a sufficiently powerful quantum computer, the underlying maths problems used in RSA, ECDSA and Diffie-Hell-man key exchange, and in doing so breaks the security of algorithms you probably rely on every day to protect your online communications.
A weaker but more generalized attack is Grover's algorithm, which speeds up brute-force search. In theory, this would make it a threat to algorithms like AES and hash func-tions. Thankfully, it is not as fast as Shor's algorithm and parallelizes poorly, which means our current symmetric cryptography is already secure even against quantum at-tacks (e.g. AES-128).
Why this can no longer be ignored
In a November 2025 interview with the BBC, Google CEO Sundar Pichai said:
I would say quantum is there where maybe AI was 5 years ago.
Hardware and algorithms have both moved since.
Microsoft announced and IBM reiterated a target of a scalable, fault-tolerant quantum computer by 2029. Not a cryptographically relevant one, but the decisive step toward it. Meanwhile the estimates of what breaking cryptography actually costs keep falling. Re-cent work from Google and Oratomic suggests public-key cryptography needs far fewer quantum resources to break than previously estimated. Google and Cloudflare have both since set 2029 as their internal deadline for full post-quantum migration.
Faced with these signals, cryptography engineer Filippo Valsorda flipped the question.
The bet is not “are you 100% sure a CRQC will exist in 2030?”, the bet is “are you 100% sure a CRQC will NOT exist in 2030?”
Post-Quantum Cryptography
Quantum computers aren't better at every problem. We still don't know how to solve some maths problems efficiently on either classical or quantum computers. Fortunately, that means we can build public-key schemes that resist both. In 2024, after years of design and testing by the global research community, the US National Institute of Stand-ards and Technology (NIST) released its first three Post-Quantum Cryptography (PQC) standards: ML-KEM for key exchange, and ML-DSA and SLH-DSA for digital signatures. Even though these are US standards, NIST standards often become industry best prac-tices well beyond the US.
And they aren't theoretical. They're widely deployed. As our TLS deep dive will show, around 75% of Swiss web traffic to Cloudflare was already protected against HNDL as of September 2026. Nearly all PQC deployments today run in hybrid mode, pairing the post-quantum algorithm with a classical one so an attacker has to break both. Whether and when to drop the classical half is still debated.
A compliance deadline, not only a technical one
Regulators are moving too, Switzerland included. In December 2025, the Swiss NCSC re-commended adopting PQC to counter HNDL attacks. SIX and the Swiss Bankers Associ-ation had already called the migration urgent when, in July 2026, FINMA told financial in-stitutions it expects a PQC roadmap by mid-2027. The rest of the world is heading the same way. NIST plans to deprecate most of today's public-key algorithms after 2030 and disallow them entirely after 2035.
Market access is at stake too. A June 2026 US executive order will require federal con-tractors delivering IT systems to meet post-quantum standards by 2030. From 2027, the
EU's Cyber Resilience Act will require state-of-the-art encryption for digital products sold in the EU. For Swiss companies selling into either market, PQC readiness becomes a con-dition of doing business.
A migration, not a switch
Quantum computers won't break everything. Disk, database and backup encryption mostly rely on symmetric cryptography, which stays secure. PQC matters where systems exchange keys or authenticate each other (TLS, VPNs, SSH, PKI), and in most organisa-tions that means standard protocols your vendors implement. Some of these protocols will switch to PQC with little friction. For others, dropping in PQC won't work because of the overhead. Telling them apart starts with a cryptographic inventory, a map of where you use cryptography and for what. It's the first step of any PQC roadmap.
In the rest of this series, we go through the protocols that make up most of the crypto-graphic usage in a typical organisation and, for each one, show what the move to PQC costs in practice. Our analysis is backed by real-world measurements from our lab, where we benchmark post-quantum variants of today's most widely used internet proto-cols.
