logo
  • Consent
  • Details
  • [#IABV2SETTINGS#]
  • About
This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
[#GPC_BANNER_ICON#]
[#GPC_TOAST_TEXT#]
Consent Selection
Show details
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
    • Pexels
      1
      Learn more about this provideropens in a new window
      _cfuvidThis cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.
      Maximum Storage Duration: SessionType: HTTP Cookie
    • ambcrypto.com
      benzinga.com
      bitcoinmagazine.com
      coingape.com
      decrypt.co
      image.coinpedia.org
      pexels.com
      7
      __cf_bm [x7]This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • newslayer.com
      1
      CookieConsentStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 1 yearType: HTTP Cookie
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • newslayer.com
      3
      __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cross-domain consent[#BULK_CONSENT_DOMAINS_COUNT#]
[#BULK_CONSENT_TITLE#]
List of domains your consent applies to: [#BULK_CONSENT_DOMAINS#]
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$64,374+0.40%ΞETH$1,921+1.35%◎SOL$77.3+1.88%✕XRP$1.01+1.13%ÐDOGE$0.0701+0.43%₳ADA$0.1743+0.74%Total Cap$2.30T+0.51%24H Vol$221.3BLayer Index40 Neutral
Quantum·Crypto
External Reporting发布于 31 分钟前

Why Post-Quantum Cryptography Matters: Preparing Today for Tomorrow’s Security Challenges

(Image generated by generative AI and reviewed under professional human supervision.)

Why Post-Quantum Cryptography Matters: Preparing Today for Tomorrow’s Security Challenges
Publisher Hong Kong Computer Emergency Response Team Coordination Centre 23 分钟阅读
Image via Hong Kong Computer Emergency Response Team Coordination Centre
翻译中…

Layer Index

40

Neutral

Layer Index

↓ 5 pts in 24h

(Image generated by generative AI and reviewed under professional human supervision.)

 

Quantum computing has made significant advances in recent years. Its immense computational power has quickly become a major topic of discussion and concern in the technology sector and is often regarded as a double-edged sword. On the one hand, there is interest in the opportunities and breakthroughs that quantum technology could bring to areas such as drug development and AI training. On the other hand, there are concerns that quantum computers could easily break today’s data encryption technologies by calculating the cryptographic keys involved in a much shorter time (for details, see: How To Protect Your Data in Quantum Age). This could pose significant risks and potential impacts, particularly for sectors that rely heavily on encryption, such as the financial industry and cryptocurrencies.

 

In any case, quantum technology will one day transform the way today’s digital landscape and cybersecurity operate. However, for most organisations, the practical question is not whether a large-scale quantum computer will emerge tomorrow. The more important question is whether today’s systems are adequately prepared for the long-term transition in cryptography.


Post-Quantum Cryptography (PQC) refers to cryptographic algorithms designed to resist against known classical and quantum attacks, including attacks from future cryptographically relevant quantum computers. Around the world, standards bodies and cybersecurity authorities are encouraging organisations to prepare by understanding where cryptography is used, identifying systems that rely on quantum-vulnerable public-key algorithms, and planning for future upgrades.


At the same time, industry bodies, telecommunications operators, research institutions and cybersecurity vendors are exploring how quantum-resistant cryptography may be implemented in real-world environments. These developments show that PQC readiness is not only a theoretical topic. It is becoming a practical issue for product design, procurement, system architecture, interoperability and long-term cyber resilience.


For organisations in Hong Kong, the immediate, large-scale replacement of existing encryption technologies is not realistic, as they are deeply embedded in various systems, often without users even being aware of their presence. The practical priority is risk-based migration planning, inventory, vendor engagement, and adopting PQC where standards and vendor support are ready. Organisations should begin by building visibility over their cryptographic dependencies, understanding which systems may be affected by future quantum risks, and ensuring that future technology investments can adapt as standards and industry practices continue to evolve.

 

 

A Global Shift Towards Post-Quantum Readiness

(Image generated by generative AI and reviewed under professional human supervision.)

 

Post-quantum readiness is not about panic. It is about recognising that cryptographic migration can take many years, particularly when cryptography is embedded deeply inside systems, products, protocols and supply chains.


International guidance increasingly points to a common theme: before organisations can migrate to PQC, they must first understand where cryptography is used today. This includes identifying systems that rely on public-key cryptography, assessing their business importance, and prioritising future migration based on risk.


Cryptography is often invisible to business users. It may sit inside VPN gateways, cloud services, identity platforms, web servers, software libraries, digital signature systems, smart cards, hardware security modules, industrial devices and third-party software. Without a cryptographic inventory, organisations may not know which systems will need future updates.


Several international cybersecurity authorities now recommend a staged approach to PQC preparation. The early stages usually focus on discovery, cryptographic inventory, risk assessment, vendor engagement and migration planning. This gives organisations time to understand their exposure before technical migration becomes urgent.


This does not mean every organisation must immediately deploy PQC. Instead, it means that quantum readiness should be treated as a structured, long-term technology transition. The first step is not mass replacement. The first step is visibility.

 

 

Why Prepare Now? The “Harvest Now, Decrypt Later” Risk 

While cryptographically relevant quantum computers are not yet available, one potential risk already exists today. In a “Harvest Now, Decrypt Later” scenario, adversaries may intercept and store communications protected by current public-key cryptography and attempt to decrypt them in the future once sufficiently capable quantum computers become available. Because many systems use public-key algorithms such as RSA or ECC for key exchange and digital signatures, a future quantum-capable adversary could potentially recover past session keys and decrypt previously captured communications.


This risk is particularly relevant for information with long-term sensitivity. Examples may include customer data, intellectual property, financial records, government information and commercially sensitive information that must remain confidential for many years. Even if current cryptographic protections remain secure today, organisations may need to consider the risk where data confidentiality requirements extend beyond the expected security lifetime of existing public-key cryptography.


For this reason, many organisations are beginning PQC readiness activities not because they expect an immediate quantum threat, but because identifying sensitive data, building cryptographic inventories and planning migration roadmaps can take considerable time. For organisations that need to protect information over the long term, early preparation can help reduce future transition risk and operational pressure.

 

 

Global Timelines for Post-Quantum Readiness

The United States, European Union, United Kingdom and Australia have all established official timelines for migrating to post-quantum cryptography (PQC).


The EU plans to begin coordinating Member States’ transition to PQC by the end of 2026. Critical infrastructure is expected to complete the migration as soon as possible, and no later than the end of 2030. The EU’s coordinated roadmap also identifies 2035 as a key deadline for broader migration.


The UK aims to complete the definition of migration goals, asset inventories and initial plans by 2028, complete the highest-priority migration activities by 2031, and migrate all systems, services and products to PQC by 2035.


In the United States, official policy requires federal agencies to accelerate their migration to PQC. High-value assets and high-impact systems must complete the migration to PQC for cryptographic key establishment by the end of 2030 and for digital signatures by the end of 2031. The federal migration plan also identifies 2035 as the deadline for completing the migration of remaining systems.


The Australian Government recommends that organisations stop using traditional asymmetric cryptographic algorithms by the end of 2030 and transition to post-quantum cryptographic algorithms to reduce the future risks that quantum computing may pose to existing encryption technologies.

 

 

What International Standards and Guidance Are Telling Organisations

International standards and guidance provide a practical direction for organisations: identify affected systems, prioritise risk, engage vendors and design systems that can support future cryptographic changes.

 

In 2024, the U.S. National Institute of Standards and Technology (NIST) finalised its first three PQC standards. These include:

  • FIPS 203: ML-KEM, a module-lattice-based key-encapsulation mechanism for key establishment
  • FIPS 204: ML-DSA, a module-lattice-based digital signature standard
  • FIPS 205: SLH-DSA, a stateless hash-based digital signature standard

 

These standards are important because public-key cryptography is widely used to establish trust, authenticate systems and protect digital communications. The transition to PQC will therefore affect technologies such as TLS, VPNs, PKI, digital signatures, code signing and identity systems.

 

Security FunctionCommon Technologies TodayPost-Quantum Direction
Key establishmentRSA, Diffie-Hellman, ECDHML-KEM or hybrid key establishment using both classical and post-quantum algorithms
Digital signaturesRSA, ECDSAML-DSA or SLH-DSA, depending on use case and ecosystem support
Website and server certificatesRSA or ECC certificatesPQC-enabled or hybrid certificate mechanisms when supported by browsers, certificate authorities and vendors
VPNs and secure remote accessRSA, Diffie-Hellman, ECDH, ECDSAPQC-enabled or hybrid VPN mechanisms when supported by vendors and protocols
Code signing and software updatesRSA or ECDSA signaturesPQC-capable signing mechanisms when supported by software ecosystems and trust stores

 

International guidance also highlights the importance of phased migration. Organisations are encouraged to identify where vulnerable public-key cryptography is used, assess the sensitivity and lifespan of protected data, and plan upgrades in a risk-based manner.

 

Another important concept is hybrid cryptography. A hybrid approach combines a classical algorithm with a PQC algorithm during the transition period. This may help organisations maintain compatibility while introducing protection against future quantum-related risks. However, hybrid cryptography also introduces complexity and must be tested carefully before production deployment.

 

Across international guidance, the common lesson is consistent: organisations should not wait until migration becomes urgent. They should begin with discovery, inventory, planning and flexibility.

 

 

Industry Exploration and Ecosystem Development in China

(Image generated by generative AI and reviewed under professional human supervision.)

 

In Mainland China, industry bodies, telecommunications operators, financial-sector organisations, research institutions and cybersecurity vendors are also laying groundwork for future quantum-resistant security. For example, the Institute of Commercial Cryptography Standards (ICCS) announced a global solicitation for next-generation commercial cryptographic algorithms to address quantum-computing threats and support future standardisation work. The solicitation covers public-key cryptographic algorithms, cryptographic hash algorithms and block cipher algorithms, and states that submissions will be evaluated in areas such as security, performance and technical characteristics.


The ICCS also published detailed submission requirements for new public-key and hash algorithms. These requirements cover algorithm descriptions, implementation code, test vectors, security analysis, performance evaluation, intellectual property declarations and public review. The public-key algorithm requirements also refer to quantum security strength, while the hash algorithm requirements state that algorithms should resist known classical and quantum-computing attacks.


Industry migration studies further show that PQC transition is being examined as a practical systems-engineering challenge. The Post-Quantum Cryptography Migration White Paper (2024) involved participants from telecommunications, financial services, universities, research institutes and cybersecurity companies, including China Telecom Group, Huaxia Bank, Xidian University, Fudan University, Shanghai Jiao Tong University, Jinan University, Tianyi Cybersecurity Technology and other cryptography-related organisations. The white paper describes PQC migration as a process involving discovery of quantum-vulnerable cryptography, risk assessment, secure implementation, orderly deployment, compatibility testing, interoperability evaluation and ecosystem development.


Telecommunications operators in Mainland China are also exploring quantum-resistant and quantum-secure communication scenarios. For example, public reporting on China Telecom Quantum Group described work on post-quantum cryptography chips, systems combining Optical Transport Network (OTN) with Quantum Key Distribution (QKD), and commercial cryptography systems integrating QKD and PQC. These examples indicate that telecom-sector exploration is moving beyond algorithm research into communication, transmission and product scenarios.


These examples show that the industry and professional ecosystem is already investigating what approaches may be suitable, which algorithm families and implementation approaches may be suitable for future quantum-resistant security, how they should be evaluated, and how they may eventually be implemented in real-world systems. This also reinforces a practical message for organisations: the field is developing quickly, and PQC readiness should be built on continuous monitoring, cryptographic inventory and the ability to adapt as standards and technologies mature.

 

Reach crypto's most engaged readers — advertise mid-article on NewsLayer
Sponsored

Reach crypto's most engaged readers — advertise mid-article on NewsLayer

NewsLayer

Ad

 

Hong Kong Is Beginning to Advance Post-Quantum Readiness

Although Hong Kong has not yet established comprehensive mandatory requirements for PQC migration, regulators, research institutions and related industry stakeholders have already started promoting quantum-security readiness from multiple perspectives, including risk management, capability building and technology research.


One notable development is the release of the Whitepaper on Quantum Preparedness of Hong Kong's Banking Sector and the first Quantum Preparedness Index (QPI) by the Hong Kong Monetary Authority (HKMA) in 2026. The QPI assesses the banking sector's readiness across four dimensions: Awareness, Planning, Pilots and Practical Preparedness. Survey results showed an initial QPI score of 2.3 out of 10, indicating that the sector is still in the early stages of preparedness. Approximately 32% of surveyed banks had not yet begun quantum-related transition activities, while around half had not established formal PQC planning. The HKMA has stated its intention to continue supporting the banking sector through guidance, training and industry engagement, with the aim of improving sector-wide readiness by 2030.


Meanwhile, Hong Kong's research community is actively exploring quantum-secure technologies. In 2025, the Research Institute for Quantum Technology (RIQT) at The Hong Kong Polytechnic University announced the successful completion of Hong Kong's first chip-based quantum communication network test. The research team used a self-developed quantum communication chip to conduct a Quantum Key Distribution (QKD) demonstration over approximately 55 kilometres of existing optical fibre infrastructure. While QKD and PQC represent different technological approaches, both are regarded as important components of the future quantum-security ecosystem. QKD focuses on protecting key exchange through the principles of quantum mechanics, whereas PQC uses new cryptographic algorithms designed to resist quantum attacks.


Taken together, these developments suggest that Hong Kong's quantum-security efforts are gradually progressing from conceptual research towards practical planning and technology validation. From sector-wide readiness assessments and maturity-building initiatives to quantum-secure communication research, quantum risk is increasingly being recognised as a long-term strategic issue rather than merely a future technology discussion.

 

 

PQC Is Promising, But the Field Continues to Evolve

Post-quantum cryptography is one of the most important tools for preparing for future quantum-related security risks. However, organisations should understand that cryptography is a living field. Confidence in cryptographic algorithms comes from open evaluation, standardisation, implementation experience and continued research.


This is why standards bodies and industry participants continue to evaluate algorithms, implementation approaches and migration options. Even after major standards are published, further research may continue, additional algorithms may be evaluated, and future cryptanalysis may influence parameter choices or deployment recommendations.


For organisations, the lesson is not that PQC should be avoided. The lesson is that PQC should be approached through standards-based planning, testing and agility. It is not enough to choose a single algorithm and assume the issue is solved permanently.


In simple terms, PQC readiness is not only about finding “the final answer”. It is about building the capability to monitor developments, evaluate practical options and adjust when cryptographic technologies evolve.

 

 

Why Cryptographic Inventory Matters More Than Algorithm Names

For most organisations, the most useful action today is not to deploy PQC everywhere. The most useful action is to understand where cryptography exists. Without this visibility, organisations will struggle to plan future migration, engage vendors or prioritise risk.


A cryptographic inventory records which systems use cryptography, what algorithms are used, who owns the systems, whether the systems can be upgraded and whether third-party vendors are involved. This may sound technical, but the management purpose is simple: identify future migration exposure before it becomes urgent.

 

Organisations should begin by identifying systems that use or depend on:

  • RSA certificates
  • ECC certificates
  • Diffie-Hellman or ECDH key exchange
  • RSA or ECDSA digital signatures
  • Internal or external certificate authorities
  • Cryptographic libraries embedded inside applications
  • Hardware security modules (HSMs)
  • VPN, remote access and secure communications platforms
  • Smart cards, tokens and authentication devices
  • Embedded systems, appliances and operational technology environments

 

For each system, organisations should record:

  • The business owner and technical owner
  • The cryptographic algorithms in use
  • The key lengths and certificate types
  • The certificate authority or trust chain involved
  • The product or software version
  • The vendor or service provider
  • The expected system lifetime
  • Whether the system supports algorithm updates
  • Whether PQC support would require configuration changes, software updates or hardware replacement

 

The cryptographic inventory does not need to be perfect on the first day. Even a basic inventory can help organisations identify critical dependencies, prioritise long-life systems and avoid discovering cryptographic constraints only when migration becomes urgent.

 

 

What Hong Kong Organisations Can Learn

(Image generated by generative AI and reviewed under professional human supervision.)

 

As an international business and technology hub, Hong Kong organisations can benefit from understanding internationally recognised standards, developments within Mainland China, and emerging quantum-security initiatives taking place locally. This does not require choosing one technology direction over another. Rather, organisations can learn from structured guidance, observe how different sectors are approaching quantum readiness, and monitor how practical deployment models continue to evolve.

 

International and Mainland Chinese standards, guidance and industry initiatives provide an important management lesson: begin with discovery, identify quantum-affected cryptographic assets, prioritise high-risk systems and establish migration plans. Recent developments in Hong Kong reinforce the same message. Whether through banking-sector quantum-readiness assessments, maturity-building efforts, or research into quantum-secure communications, quantum readiness is increasingly becoming a governance, planning and technology-management issue rather than solely a research topic.

 

For Hong Kong organisations, the combined message is practical and balanced:

  • Do not assume PQC migration can be completed quickly when the need becomes urgent.
  • Do not assume every product labelled “post-quantum” will be suitable for every environment.
  • Do not focus only on algorithm names; focus on inventory, agility, vendor support and testing.
  • Do not wait for perfect certainty before taking low-risk preparation steps.

 

Instead, organisations should use today’s developments as an opportunity to strengthen long-term cyber resilience. The same activities that support PQC readiness, such as cryptographic inventory, vendor management, certificate lifecycle review and secure system architecture, also improve general cybersecurity governance.


Although Hong Kong has not yet introduced comprehensive PQC migration requirements across all sectors, local financial regulators have already begun assessing quantum-readiness, while industry and research institutions continue to explore relevant technologies and practices. These developments suggest that quantum-security readiness is not a distant concern, but a long-term capability-building effort that benefits from early planning.


As business operations, cloud services and supply chains become increasingly interconnected across borders, organisations may face growing expectations from both mainland and international customers, parent companies, regulators, cloud providers and business partners to demonstrate their understanding of quantum-related risks and their plans for managing them. Even when these expectations initially take the form of risk assessments, inventory requests or migration planning discussions, developing visibility and governance over cryptographic assets today can help organisations respond more effectively to future business, compliance and security requirements.

 

Regular cryptographic inventory reviews and quantum-readiness assessments can therefore serve as practical steps towards building long-term governance capabilities for quantum-security risks.
 

 

Build Cryptographic Agility Into Future Systems

Cryptographic agility is the ability to replace or update cryptographic algorithms without redesigning the entire system. It is one of the most important concepts for PQC readiness because the field will continue to evolve.

 

A system with poor cryptographic agility may hard-code RSA or ECC in ways that are difficult to change. A cryptographically agile system should allow algorithms, libraries, certificate types or protocol configurations to be updated through supported upgrade paths, configuration changes or software updates.
 

When procuring new systems or modernising existing ones, organisations should avoid:

  • Hard-coded cryptographic algorithms
  • Unsupported cryptographic libraries
  • Products that cannot change certificate types
  • Systems without clear upgrade paths
  • Long-term dependencies on outdated protocols

 

Organisations should prefer systems that:

  • Use modern and supported cryptographic libraries
  • Allow algorithms and key lengths to be updated
  • Support certificate lifecycle management
  • Provide clear vendor roadmaps for future standards
  • Can be tested safely before production deployment
  • Support migration through software or configuration changes where possible

 

For SMEs, this does not mean building cryptographic systems from scratch. It means asking vendors better questions, avoiding unnecessary lock-in and ensuring that important systems have realistic upgrade paths.

 

 

Questions to Ask Vendors and Service Providers

Many organisations will depend on technology suppliers, managed service providers, cloud platforms and software vendors for PQC support. Asking whether a product is simply “post-quantum” may not be enough. Organisations should ask more specific questions.

 

  • Which components of the product use public-key cryptography?
  • Does the product use RSA, ECC, Diffie-Hellman, ECDH or ECDSA?
  • Is there a roadmap for PQC or hybrid cryptography support?
  • Will PQC support require software updates, configuration changes, licence changes or hardware replacement?
  • Will the product support standardised algorithms such as ML-KEM, ML-DSA or SLH-DSA where appropriate?
  • How will interoperability with older clients, browsers, devices or applications be handled?
  • Will certificate types, trust stores or PKI integrations need to change?
  • What testing guidance will be provided before production deployment?
  • Will performance, bandwidth, storage or hardware requirements change?
  • What is the vendor’s long-term support plan for cryptographic updates?

 

For critical systems, these questions should be included in procurement, renewal and architecture discussions. PQC readiness is not only a cybersecurity issue; it is also a vendor management and technology lifecycle issue.

 

 

PQC Readiness for Large Enterprises and SMEs

PQC readiness is not only a challenge for governments, financial institutions or large enterprises. Organisations of all sizes rely on digital systems, cloud services, software platforms and third-party providers that may eventually be affected by the transition to post-quantum cryptography.

 

The key difference is not whether organisations need to prepare, but how they should prepare. Large enterprises often manage complex technology environments, large cryptographic estates and long system lifecycles. Their priorities may include building cryptographic inventories, conducting risk assessments and developing phased migration roadmaps. 


SMEs are often more dependent on commercial products, cloud platforms and managed services. Their priorities may include understanding which critical systems they rely upon, engaging vendors on PQC roadmaps and avoiding products that cannot support future cryptographic upgrades.
 

 

Security Recommendations

A HKCERT Suggested Timeline for PQC Readiness

While Hong Kong has yet to establish a specific schedule for PQC migration, local organisations should not merely stand by. On the contrary, they must actively initiate preparations for the upcoming transition. There is broad agreement that cryptographic migration itself can take many years. As a result, PQC readiness planning should not be driven by predictions about when a quantum breakthrough may occur, but by the practical time required for system migration, supplier coordination and technology refresh cycles.


For most organisations, activities such as cryptographic inventory, risk assessment, vendor engagement, testing and deployment involve multiple business units, technology platforms and third-party products. Many critical systems also have lifecycles measured in years or even decades. Consequently, even if quantum-related risks are not considered immediate, preparation should not be postponed until the last moment.


Taking reference from international migration roadmaps and the Hong Kong Monetary Authority's objective of improving banking-sector quantum readiness by 2030, organisations may consider:

  • Initiating cryptographic inventories and risk assessments in 2027;
  • Developing migration roadmaps, vendor-engagement plans and technical evaluations between 2028 and 2030;
  • Progressively migrating higher-priority and longer-lifecycle systems after 2030, based on business risk and technology maturity.

The objective is not necessarily to complete a full migration by a specific date. Rather, it is to ensure that when migration becomes necessary, organisations already possess the visibility, planning capabilities and technical readiness required to manage quantum-related risks in an orderly manner.

 

 

How Organisations of Different Sizes Can Start Preparing for PQC

PQC readiness is not only relevant to banks, government departments or large enterprises. Regardless of size, any organisation that relies on computer systems, cloud services, online communications or third-party software may be affected by future cryptographic transition.

 

 

Actions for All Organisations

PQC readiness should not be treated simply as a technical replacement exercise. Organisations should first understand which information may face long-term risks from advances in quantum computing, and establish basic follow-up and decision-making arrangements so that future preparation can proceed in an orderly manner based on standards, product support and the organisation’s own risk profile.

 

  1. Review Long-Term Sensitive Data

Organisations should identify information that must remain confidential for many years, such as personal data, health records, financial records, legal documents, intellectual property, strategic business information and regulated information.


Such information may face “harvest now, decrypt later” risks, where attackers intercept or store encrypted data today and attempt to decrypt it in the future when quantum computing capabilities mature. The longer information needs to remain confidential, the earlier it should be considered as part of PQC readiness planning.

 

  1. Monitor Standards and Industry Developments

Organisations should continue to monitor PQC-related standards, regulatory guidance and support from major technology vendors, particularly updates relating to browsers, operating systems, cloud platforms, network devices, identity services, certificate services and security products.


As PQC readiness will depend on standards maturity, product support, platform interoperability and vendor upgrade arrangements, organisations should avoid making long-term technical decisions based solely on individual product claims or vendor marketing. A more prudent approach is to continue tracking public standards and major platform developments, and prepare gradually based on the organisation’s own risks and business needs.

 

  1. Assign Responsibility and Establish Follow-Up Arrangements

Organisations should clearly assign responsibility for following up on PQC readiness, such as to information technology, cybersecurity, risk management, procurement or compliance functions. Even for smaller organisations, a responsible person should be assigned to regularly monitor vendor notifications, product updates, regulatory guidance and industry developments.


This helps avoid a situation where PQC readiness is not coordinated because it involves multiple areas, including technology, procurement, contracts and risk management. For large organisations, this can provide a basis for cross-functional coordination. For SMEs, it helps ensure that PQC-related matters are not only dealt with reactively during system renewals, product replacements or incidents.

 

  1. Adopt a Cautious and Phased Approach

PQC standards and product support are still maturing. Organisations do not need to replace all relevant systems at once, and should not make major changes in production before they have sufficiently understood compatibility, performance, support arrangements and rollback options.


A more appropriate approach is to first establish basic awareness and follow-up arrangements, and then proceed in phases based on data sensitivity, business criticality, system lifespan, vendor support and available resources.

 

 

Actions for Large Organisations

Large organisations typically have more complex IT environments, internally developed systems and longer technology lifecycles. They should therefore place greater emphasis on building cryptographic inventories, conducting risk assessments and planning phased migration roadmaps, including:

 

  1. Build and Maintain a Cryptographic Inventory

Build a more comprehensive cryptographic inventory to identify systems that use public-key cryptography, including RSA, ECC, Diffie-Hellman, ECDH and ECDSA.


The inventory should, where possible, record system owners, business purposes, vendors, algorithms, certificate types, product versions and upgrade paths. For more complex environments, organisations may also record system dependencies, data types, compliance requirements, key management arrangements and third-party integrations to support subsequent risk assessment and migration planning.

 

  1. Prioritise Systems Based on Risk and Lifespan

Prioritise systems based on their criticality, data sensitivity, external exposure, technology lifecycle and upgrade complexity.

 

Priority should be given to systems that protect sensitive information, support critical business processes, face the internet, or are expected to remain in service for many years. For core systems, legacy platforms, internally developed applications or systems with long technology lifecycles, organisations should allow sufficient time for assessment, testing, modification and migration.

 

  1. Plan a Phased Migration Roadmap

Should not treat PQC migration as a one-off technical replacement. Instead, they should develop a phased migration roadmap based on system risk, business impact, technical feasibility and vendor support.


The roadmap may include asset discovery, risk classification, proof of concept, deployment in test environments, vendor coordination, certificate and key management changes, production rollout arrangements and rollback plans. This can help reduce the impact of large-scale changes on business operations, system compatibility and service stability.

 

  1. Design for Cryptographic Agility

New systems should avoid hard-coded cryptographic dependencies and should, where possible, support future algorithm replacement through standard update or configuration mechanisms.


For internally developed systems or long-term internal platforms, organisations may consider adopting more modular cryptographic designs, allowing algorithms, certificates, key lengths and related parameters to be adjusted in the future based on standards or business needs, without requiring major rewrites of applications or system architecture.

 

  1. Test Before Deployment

Before deploying PQC or hybrid cryptographic mechanisms in production, organisations should conduct compatibility, performance and security testing in controlled environments.


Testing may cover applications, browsers, network devices, identity systems, APIs, certificate management, logging and monitoring, backup systems and third-party integrations. As PQC or hybrid cryptography may involve larger keys, signatures or message sizes, organisations should also assess potential impacts on performance, bandwidth, latency and storage.

 

  1. Avoid Premature Lock-In to Specific Solutions

Avoid becoming prematurely dependent on a single vendor, proprietary implementation or PQC solution that lacks interoperability. Preference should be given to approaches that are based on public standards, clearly documented, testable, reversible and interoperable with existing systems and other platforms.


Organisations should pay particular attention to the long-term switching costs that may arise if standards change, vendor strategies shift, products are discontinued or cross-platform integration becomes necessary. For core systems, identity services, certificate management and cross-departmental platforms, organisations should preserve flexibility to change algorithms, products or vendors in the future.

 

 

SMEs Should Stay Informed About PQC

While PQC migration may not be an immediate priority for many SMEs, organisations should remain aware of developments and consider PQC readiness as part of their longer-term technology planning. A practical and phased approach can help minimise costs and operational impact. SMEs may focus on identifying critical business systems and services, engaging vendors and managed service providers on their PQC roadmap and upgrade plans, and incorporating PQC-related considerations into future procurement and contract renewal processes. By maintaining visibility of key systems and supplier dependencies, SMEs can gradually align with future cryptographic requirements while avoiding unnecessary complexity.

 

 

Common Misconceptions

As PQC becomes more widely discussed, organisations should avoid both unnecessary alarm and false confidence.

 

Myth: Quantum computers will immediately break all encryption.

Reality: The main concern is with certain public-key cryptographic algorithms. Properly configured symmetric encryption is generally considered less directly affected, although organisations should continue following recognised cryptographic best practices.

 

Myth: PQC migration means replacing every system now.

Reality: For most organisations, the immediate priority is inventory, planning, vendor engagement and cryptographic agility, not immediate mass deployment.

 

Myth: Once one PQC algorithm is selected, the problem is solved forever.

Reality: Cryptography continues to evolve. Standards bodies, researchers and industry participants continue to evaluate algorithms, implementation approaches and deployment models.

 

Myth: PQC readiness is only a technical issue.

Reality: PQC readiness also involves governance, procurement, vendor management, asset management, risk assessment, system architecture and long-term technology planning.

 

 

Conclusion

Post-quantum cryptography is becoming a practical long-term cybersecurity issue. International standards and guidance are helping organisations understand how to prepare, while industry bodies and technology organisations are exploring algorithms, architectures, interoperability and deployment models.


The most important lesson is not that every organisation must immediately deploy PQC. The more important lesson is that organisations should know where cryptography is used, understand which systems may be affected, and ensure that future technology decisions do not make migration unnecessarily difficult.


For Hong Kong organisations, this is an opportunity to take a balanced and practical approach. As an international business and technology hub, Hong Kong can benefit from internationally recognised standards and from practical industry developments taking place across different markets. Together, these perspectives point to the same conclusion: preparation should begin with visibility, agility and continuous monitoring.

 

The post-quantum transition will continue to evolve. Algorithms, products and deployment practices may mature over time. Organisations that maintain cryptographic inventories, engage vendors, protect long-term sensitive data and design systems for future algorithm changes will be better positioned to adapt with confidence.


In the post-quantum era, the strongest organisations will not necessarily be those that move the fastest. They will be those that understand their cryptographic foundations and can adapt when the technology landscape changes.

 

突发新闻

Never miss a breaking story

Follow on X Join Telegram

Advertisement

House — Advertise on NewsLayer
NewsLayerAd
#quantum#crypto

Sourced by

Originally reported by Hong Kong Computer Emergency Response Team Coordination Centre

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

Layer Index

40

Neutral

Layer Index

↓ 5 pts in 24h

突发新闻

Never miss a breaking story

Follow on X Join Telegram

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

相关报道

The Conversation: The Global Race to Make a Practical Quantum Computer Just Took a Big Leap ForwardDEEP DIVE

The Conversation: The Global Race to Make a Practical Quantum Computer Just Took a Big Leap Forward

Guest Post by Animesh Datta, Professor of Quantum Information Science, University of Warwick, for The Conversation In the global race to build bigger and better quantum computers, researchers have taken a step forward. A new machine called Helios is a radically different system compared to other quantum computers. Quantum computers harness the power of quantum mechanics, […]

1 小时前

4 分钟阅读
Quantum Computing’s Revolutionary Promise Is Bringing Real-World SolutionsCRYPTO WIRE

Quantum Computing’s Revolutionary Promise Is Bringing Real-World Solutions

Quantum Computing’s Revolutionary Promise Is Bringing Real-World Solutions Newsweek

8 分钟前

17 分钟阅读
Quantinuum: Trapped-Ion Quantum Computing Looks To Break Out Of The Quantum SiloCRYPTO WIRE

Quantinuum: Trapped-Ion Quantum Computing Looks To Break Out Of The Quantum Silo

Quantinuum: Trapped-Ion Quantum Computing Looks To Break Out Of The Quantum Silo Seeking Alpha

38 分钟前

3 分钟阅读
Quantum Computing Stocks: Key Players and TrendsCRYPTO WIRE

Quantum Computing Stocks: Key Players and Trends

Quantum Computing Stocks: Key Players and Trends Intellectia AI

1 小时前

1 分钟阅读
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Web3
  • Blockchain
  • Policy
  • Explainers

Markets & Tools

  • Market News
  • Live Charts
  • Layer Index
  • Regulation Tracker
  • Regulation Radar
  • Research
  • NewsLayer Originals
  • My Feed
  • Search

Company

  • About NewsLayer
  • Go Premium
  • Advertise
  • PR Publication
  • Become an Author
  • Create Account
  • Sign in

© 2026 NewsLayer.com — The front page of the onchain economy·Privacy Policy·Terms of Service

NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime