Quantum computing has the potential to change one of the core assumptions behind modern cyber security: that today's public key cryptography is too hard to break in practical time. The risk is specific and preparation is urgent given long migration timescales and the ‘harvest now, decrypt later’ threat. The asymmetric algorithms used to create trust, prove identity, exchange keys and sign digital assets are expected to be vulnerable to a sufficiently capable quantum computer.
Public key cryptography is everywhere. It supports TLS, SSH, VPNs, service mesh communications, PKI certificate chains, code signing, document signing, digital identity, KMS integrations, HSM-backed roots of trust, secure boot and firmware assurance. In sectors such as government, defence, finance, healthcare, energy and critical national infrastructure, these mechanisms underpin confidentiality, integrity, authentication and non-repudiation.
Post-Quantum Cryptography (PQC) is the transition to algorithms designed to resist both classical and quantum attacks. NIST finalised the first major PQC standards in 2024, including ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures. The UK National Cyber Security Centre (NCSC) has also set expectations for migration: discovery and assessment by 2028, priority migration by 2031, and migration to PQC by 2035.
What is at risk?
The cryptographic systems most exposed to quantum attack are those based on today's widely used asymmetric algorithms, including RSA, elliptic curve cryptography (ECC), Diffie-Hellman (DH) and DSA.
Data in transit. TLS, SSH, VPN and service mesh encryption often use asymmetric cryptography to authenticate endpoints and establish shared secrets. Even where payload encryption uses symmetric algorithms, the handshake and trust model may depend on RSA, ECC or Diffie-Hellman. If those mechanisms are vulnerable, sensitive communications, remote administration, API traffic and machine-to-machine connections may be exposed. This is made more urgent by the "harvest now, decrypt later" threat. Adversaries can capture encrypted traffic today and store it until future quantum capabilities allow them to decrypt it. For long-lived data, such as defence information, citizen records, health data, intellectual property or critical infrastructure designs, the risk already exists.
Data at rest. At-rest encryption is often based on symmetric algorithms such as AES, which are not affected in the same way as public key systems. However, keys may be wrapped, exchanged, attested, escrowed or protected through KMS, HSM, certificate and identity systems that depend on quantum-vulnerable algorithms. Protecting stored data means understanding the full lifecycle of keys, certificates and secrets, not just the storage layer.
Signing and software integrity. Digital signatures prove that software updates, firmware, code releases, documents, transactions and operational instructions have not been tampered with. In defence and critical infrastructure environments, signatures can validate instructions and protect secure software delivery. PQC risk is not only about attackers reading encrypted data. If today’s signature algorithms fail, they may be able to make false identities, software, or transactions appear trustworthy. It’s important to note that while post-quantum risk is often discussed mainly in terms of encrypted data being read later, Signature failure creates a different kind of risk where attackers may be able to impersonate trusted parties, approve fraudulent transactions, or make malicious software appear legitimate. That means the impact is not just exposure of private information, but a broader breakdown in the trust mechanisms that many digital systems rely on.
Identity, authentication and PKI. Public Key Infrastructure underpins machine identity, user authentication, certificate chains, smart cards, tokens, mutual TLS, secure email and many access control models. Migrating PKI to PQC is not a simple certificate refresh. It may require new roots of trust, parallel PKI models, staged certificate replacement, compatibility testing and supplier coordination.
Key management, OT and long-lived infrastructure. KMS and HSM environments sit close to the heart of enterprise security. PQC migration will affect how they integrate with applications, cloud platforms, secure boot and hardware roots of trust. Operational technology, industrial control systems and IoT devices add complexity because they may be constrained, difficult to service or embedded in assets with long replacement cycles. Symmetric cryptography and hash functions, including AES and SHA-2, are not expected to be broken in the same way as RSA or ECC. However, quantum search techniques reduce the effective security margin, so organisations should review key length, rotation and algorithm policies and use stronger options such as AES-256 and SHA-256 where appropriate.
Why preparation must start now
PQC migration will be a multi-year transformation touching architecture, applications, infrastructure, identity, suppliers, cloud services, embedded technology, operational processes and assurance. Traditional public key cryptography and PQC are likely to coexist in some environments for a period, using hybrid approaches where appropriate while standards, products and protocols mature. Quantum Key Distribution may be explored for specific secure communications use cases, but PQC discovery and migration planning is the broader priority for most organisations.
The first step is not to replace everything. It is to know what you have: cryptographic assets across IT and OT, algorithms and certificates in use, data lifetimes, supplier dependencies, critical systems and the migration choices that best balance risk reduction, continuity and value for money.
How CGI can help
Under PQC essentials and as one of the first NCSC assured Cyber Security consultancies for PQC Discovery and Migration Planning, CGI provides a trusted, standardised route through four connected stages, moving organisations from shared understanding to evidence-based priorities and an actionable transition plan.
The value of PQC Essentials The value is not simply identifying cryptography. PQC Essentials provides a consistent way to determine which data, keys and trust paths create the greatest future exposure - and what should be addressed first.
1. Establish the context and business case Align leaders and stakeholders on quantum risk, HNDL exposure, business impact and the case for action.
2. Discover and assess Examine where vulnerable cryptography and trust dependencies exist across applications, cloud environments, Application Programming Interfaces (APIs), Public Key Infrastructure (PKI), Key Management Systems (KMS) and third parties.
3. Evaluate readiness Test crypto-agility and crypto control-plane readiness across technology, identities, certificates, key wrapping, Bring Your Own Key (BYOK), backup and recovery. Crypto agility is the ability of a system or organisation to change the cryptographic algorithms, keys, protocols it uses without major redesign or disruption.
4. Plan the transition Sequence change against business risk, regulatory pressure, vendor readiness, operational complexity and continuity needs
Your organisation, quantum-ready, with CGI
CGI combines NCSC-assured PQC discovery and migration planning capability with cryptographic expertise, operational understanding and regulatory alignment to help organisations prepare for the post-quantum era with practical, actionable outcomes.
For more information: