Illustrative image generated with AI
G7 Calls for Faster Transition to Post-Quantum Cryptography
G7 and CISA urge immediate migration to post-quantum cryptography to counter harvest-now-decrypt-later threats to sensitive long-term data.
Text generated by artificial intelligence, published without human review. AI transparency
The G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have urged governments and businesses to begin migrating to post-quantum cryptography immediately. Waiting for quantum computers capable of breaking today’s algorithms to emerge, the authorities warn, could be too late.
The joint advisory, released Thursday, does not set a firm date for the arrival of sufficiently powerful quantum systems. It argues, however, that recent advances make early preparation necessary, particularly for data that must remain confidential for many years.
The problem, therefore, is not confined to the future. Encrypted information stolen today could be stored by attackers until more advanced tools become available to decrypt it.
The “harvest now, decrypt later” threat
The scenario described by the G7 and CISA is known as “harvest now, decrypt later.” An attacker intercepts or steals protected data without being able to read it yet, then archives it for a future attack.
This strategy changes how urgency is assessed. An organization must ask not only whether its systems can be compromised today, but also how long stolen information would retain operational, economic or political value.
Particularly exposed are government records, sensitive personal information and corporate trade secrets. A communication that needs to remain confidential for only a few days presents a different risk profile from health data, identities, industrial designs or strategic documents that must remain protected for decades.
Post-quantum cryptography is designed to withstand attacks carried out with both traditional and quantum computers. Its adoption, however, is not a simple, isolated update: it can affect applications, infrastructure, equipment and information-management processes.
For this reason, the G7 is not proposing that organizations wait for a specific technological milestone. The timeline for quantum computing remains uncertain, but the length of the migration process and the long-term value of data make early action necessary.
It is not just confidentiality at stake
The ability to decrypt confidential communications is the most immediate consequence, but the advisory points to a broader range of risks. An actor with sufficient quantum capabilities could impersonate trusted entities, alter information and gain access to protected systems.
The repercussions would affect four essential properties of digital security:
- authentication, if an attacker managed to present themselves as a legitimate entity;
- integrity, in the event of undetected data forgery or alteration;
- confidentiality, if encrypted communications and archives became readable;
- equipment security, if a compromise enabled attackers to interfere with devices and infrastructure.
The risk therefore also affects trust relationships between systems. The goal is not merely to prevent someone from reading a file: organizations must preserve their ability to verify who produced information, whether it has been altered and whether a command genuinely comes from an authorized source.
The potential consequences are commercial as well. Companies that fail to adopt quantum-resistant technologies could lose a competitive advantage or fail to meet future contractual requirements. The advisory explicitly cites the risk of being excluded from certain agreements, including government procurement.
Preparation is therefore becoming a matter of business continuity and market access, not merely a technical decision left to security teams.
Migration should begin with the most sensitive assets
The G7 and CISA advise against replacing every system simultaneously and indiscriminately. Such an approach could increase costs, complexity and disruption without distinguishing between essential infrastructure and less urgent components.
The first recommended step is to identify the systems that store or process the most sensitive information. This assessment should be accompanied by the identification of critical assets—those whose compromise would have the most serious operational consequences.
Priorities should be set based at least on data sensitivity, the length of time the information must remain confidential and the criticality of the system. Information that will retain its value over the long term requires immediate attention because it may already be targeted for collection and storage.
The transition should then be incorporated into routine technology upgrade cycles. The goal is to integrate quantum-resistant solutions progressively as applications, equipment and infrastructure are renewed, rather than accumulating technical debt that must be addressed in a single emergency operation.
Starting early also allows investments and activities to be spread over time. It reduces the risk that multiple systems will need to be replaced simultaneously and provides room to assess compatibility, dependencies and the impact on business processes.
The advisory does not identify vulnerable software versions or specific patches because it does not address a single flaw. It is a strategic recommendation that affects the entire life cycle of cryptographic systems.
Banks, telecoms and governments on the front line
The banking, financial and telecommunications sectors are identified as among the first candidates for migration. They handle large volumes of sensitive information, distributed infrastructure and digital trust relationships that must remain verifiable over time.
Last year, U.K. cybersecurity authorities published a roadmap setting 2035 as the target for completing the transition to quantum-resistant cryptography. The deadline illustrates how long and complex the process is expected to be, despite uncertainty over how quantum computers will develop in practice.
The issue had already entered the international agenda. In 2024, the G7 called on finance ministries and central banks to prepare for what it described as “impending threats” stemming from advances in quantum computing, with a particular focus on the financial sector.
In June, President Donald Trump also signed two executive orders intended to accelerate U.S. development of quantum technologies and strengthen protections for government systems against future quantum-related threats.
The advisory released Thursday extends the message beyond financial and government institutions. Any organization that stores long-term data or operates critical infrastructure should assess its exposure.
What organizations should do now
The first concrete step is to create an inventory of the systems in which cryptography protects critical data, identities and communications. Without this map, organizations cannot determine which components should be migrated first.
They should then classify information according to how long it must remain secret. Data with a long useful life requires higher priority, even when the systems containing it cannot currently be attacked directly with quantum capabilities.
Finally, organizations should link migration to already planned upgrade programs, avoiding large-scale replacements without clear priorities. Starting early is precisely what allows a potential emergency response to become a controlled sequence of upgrades.
No date is known by which quantum computers will be able to compromise the algorithms most widely used today. The advisory’s central point, however, is that this uncertainty does not justify waiting: for some categories of data, the window of risk is already open.
Sources
This article is an original reworking based on the sources below.
