
(Image generated by generative AI and reviewed under professional human supervision.)
Quantum computing has made significant advances in recent years. Its immense computational power has quickly become a major topic of discussion and concern in the technology sector and is often regarded as a double-edged sword. On the one hand, there is interest in the opportunities and breakthroughs that quantum technology could bring to areas such as drug development and AI training. On the other hand, there are concerns that quantum computers could easily break today’s data encryption technologies by calculating the cryptographic keys involved in a much shorter time (for details, see: How To Protect Your Data in Quantum Age). This could pose significant risks and potential impacts, particularly for sectors that rely heavily on encryption, such as the financial industry and cryptocurrencies.
In any case, quantum technology will one day transform the way today’s digital landscape and cybersecurity operate. However, for most organisations, the practical question is not whether a large-scale quantum computer will emerge tomorrow. The more important question is whether today’s systems are adequately prepared for the long-term transition in cryptography.
Post-Quantum Cryptography (PQC) refers to cryptographic algorithms designed to resist against known classical and quantum attacks, including attacks from future cryptographically relevant quantum computers. Around the world, standards bodies and cybersecurity authorities are encouraging organisations to prepare by understanding where cryptography is used, identifying systems that rely on quantum-vulnerable public-key algorithms, and planning for future upgrades.
At the same time, industry bodies, telecommunications operators, research institutions and cybersecurity vendors are exploring how quantum-resistant cryptography may be implemented in real-world environments. These developments show that PQC readiness is not only a theoretical topic. It is becoming a practical issue for product design, procurement, system architecture, interoperability and long-term cyber resilience.
For organisations in Hong Kong, the immediate, large-scale replacement of existing encryption technologies is not realistic, as they are deeply embedded in various systems, often without users even being aware of their presence. The practical priority is risk-based migration planning, inventory, vendor engagement, and adopting PQC where standards and vendor support are ready. Organisations should begin by building visibility over their cryptographic dependencies, understanding which systems may be affected by future quantum risks, and ensuring that future technology investments can adapt as standards and industry practices continue to evolve.
A Global Shift Towards Post-Quantum Readiness

(Image generated by generative AI and reviewed under professional human supervision.)
Post-quantum readiness is not about panic. It is about recognising that cryptographic migration can take many years, particularly when cryptography is embedded deeply inside systems, products, protocols and supply chains.
International guidance increasingly points to a common theme: before organisations can migrate to PQC, they must first understand where cryptography is used today. This includes identifying systems that rely on public-key cryptography, assessing their business importance, and prioritising future migration based on risk.
Cryptography is often invisible to business users. It may sit inside VPN gateways, cloud services, identity platforms, web servers, software libraries, digital signature systems, smart cards, hardware security modules, industrial devices and third-party software. Without a cryptographic inventory, organisations may not know which systems will need future updates.
Several international cybersecurity authorities now recommend a staged approach to PQC preparation. The early stages usually focus on discovery, cryptographic inventory, risk assessment, vendor engagement and migration planning. This gives organisations time to understand their exposure before technical migration becomes urgent.
This does not mean every organisation must immediately deploy PQC. Instead, it means that quantum readiness should be treated as a structured, long-term technology transition. The first step is not mass replacement. The first step is visibility.
Why Prepare Now? The “Harvest Now, Decrypt Later” Risk
While cryptographically relevant quantum computers are not yet available, one potential risk already exists today. In a “Harvest Now, Decrypt Later” scenario, adversaries may intercept and store communications protected by current public-key cryptography and attempt to decrypt them in the future once sufficiently capable quantum computers become available. Because many systems use public-key algorithms such as RSA or ECC for key exchange and digital signatures, a future quantum-capable adversary could potentially recover past session keys and decrypt previously captured communications.
This risk is particularly relevant for information with long-term sensitivity. Examples may include customer data, intellectual property, financial records, government information and commercially sensitive information that must remain confidential for many years. Even if current cryptographic protections remain secure today, organisations may need to consider the risk where data confidentiality requirements extend beyond the expected security lifetime of existing public-key cryptography.
For this reason, many organisations are beginning PQC readiness activities not because they expect an immediate quantum threat, but because identifying sensitive data, building cryptographic inventories and planning migration roadmaps can take considerable time. For organisations that need to protect information over the long term, early preparation can help reduce future transition risk and operational pressure.
Global Timelines for Post-Quantum Readiness
The United States, European Union, United Kingdom and Australia have all established official timelines for migrating to post-quantum cryptography (PQC).
The EU plans to begin coordinating Member States’ transition to PQC by the end of 2026. Critical infrastructure is expected to complete the migration as soon as possible, and no later than the end of 2030. The EU’s coordinated roadmap also identifies 2035 as a key deadline for broader migration.
The UK aims to complete the definition of migration goals, asset inventories and initial plans by 2028, complete the highest-priority migration activities by 2031, and migrate all systems, services and products to PQC by 2035.
In the United States, official policy requires federal agencies to accelerate their migration to PQC. High-value assets and high-impact systems must complete the migration to PQC for cryptographic key establishment by the end of 2030 and for digital signatures by the end of 2031. The federal migration plan also identifies 2035 as the deadline for completing the migration of remaining systems.
The Australian Government recommends that organisations stop using traditional asymmetric cryptographic algorithms by the end of 2030 and transition to post-quantum cryptographic algorithms to reduce the future risks that quantum computing may pose to existing encryption technologies.
What International Standards and Guidance Are Telling Organisations
International standards and guidance provide a practical direction for organisations: identify affected systems, prioritise risk, engage vendors and design systems that can support future cryptographic changes.
In 2024, the U.S. National Institute of Standards and Technology (NIST) finalised its first three PQC standards. These include:
- FIPS 203: ML-KEM, a module-lattice-based key-encapsulation mechanism for key establishment
- FIPS 204: ML-DSA, a module-lattice-based digital signature standard
- FIPS 205: SLH-DSA, a stateless hash-based digital signature standard
These standards are important because public-key cryptography is widely used to establish trust, authenticate systems and protect digital communications. The transition to PQC will therefore affect technologies such as TLS, VPNs, PKI, digital signatures, code signing and identity systems.
| Security Function | Common Technologies Today | Post-Quantum Direction |
|---|---|---|
| Key establishment | RSA, Diffie-Hellman, ECDH | ML-KEM or hybrid key establishment using both classical and post-quantum algorithms |
| Digital signatures | RSA, ECDSA | ML-DSA or SLH-DSA, depending on use case and ecosystem support |
| Website and server certificates | RSA or ECC certificates | PQC-enabled or hybrid certificate mechanisms when supported by browsers, certificate authorities and vendors |
| VPNs and secure remote access | RSA, Diffie-Hellman, ECDH, ECDSA | PQC-enabled or hybrid VPN mechanisms when supported by vendors and protocols |
| Code signing and software updates | RSA or ECDSA signatures | PQC-capable signing mechanisms when supported by software ecosystems and trust stores |
International guidance also highlights the importance of phased migration. Organisations are encouraged to identify where vulnerable public-key cryptography is used, assess the sensitivity and lifespan of protected data, and plan upgrades in a risk-based manner.
Another important concept is hybrid cryptography. A hybrid approach combines a classical algorithm with a PQC algorithm during the transition period. This may help organisations maintain compatibility while introducing protection against future quantum-related risks. However, hybrid cryptography also introduces complexity and must be tested carefully before production deployment.
Across international guidance, the common lesson is consistent: organisations should not wait until migration becomes urgent. They should begin with discovery, inventory, planning and flexibility.
Industry Exploration and Ecosystem Development in China

(Image generated by generative AI and reviewed under professional human supervision.)
In Mainland China, industry bodies, telecommunications operators, financial-sector organisations, research institutions and cybersecurity vendors are also laying groundwork for future quantum-resistant security. For example, the Institute of Commercial Cryptography Standards (ICCS) announced a global solicitation for next-generation commercial cryptographic algorithms to address quantum-computing threats and support future standardisation work. The solicitation covers public-key cryptographic algorithms, cryptographic hash algorithms and block cipher algorithms, and states that submissions will be evaluated in areas such as security, performance and technical characteristics.
The ICCS also published detailed submission requirements for new public-key and hash algorithms. These requirements cover algorithm descriptions, implementation code, test vectors, security analysis, performance evaluation, intellectual property declarations and public review. The public-key algorithm requirements also refer to quantum security strength, while the hash algorithm requirements state that algorithms should resist known classical and quantum-computing attacks.
Industry migration studies further show that PQC transition is being examined as a practical systems-engineering challenge. The Post-Quantum Cryptography Migration White Paper (2024) involved participants from telecommunications, financial services, universities, research institutes and cybersecurity companies, including China Telecom Group, Huaxia Bank, Xidian University, Fudan University, Shanghai Jiao Tong University, Jinan University, Tianyi Cybersecurity Technology and other cryptography-related organisations. The white paper describes PQC migration as a process involving discovery of quantum-vulnerable cryptography, risk assessment, secure implementation, orderly deployment, compatibility testing, interoperability evaluation and ecosystem development.
Telecommunications operators in Mainland China are also exploring quantum-resistant and quantum-secure communication scenarios. For example, public reporting on China Telecom Quantum Group described work on post-quantum cryptography chips, systems combining Optical Transport Network (OTN) with Quantum Key Distribution (QKD), and commercial cryptography systems integrating QKD and PQC. These examples indicate that telecom-sector exploration is moving beyond algorithm research into communication, transmission and product scenarios.
These examples show that the industry and professional ecosystem is already investigating what approaches may be suitable, which algorithm families and implementation approaches may be suitable for future quantum-resistant security, how they should be evaluated, and how they may eventually be implemented in real-world systems. This also reinforces a practical message for organisations: the field is developing quickly, and PQC readiness should be built on continuous monitoring, cryptographic inventory and the ability to adapt as standards and technologies mature.





