When Should an Organization Start With a Post-Quantum Migration?

1 September 2026 | John van Lopik

Organizations should start a post-quantum migration now, even though quantum computers capable of breaking current encryption are not yet operational. The reason: attackers are already collecting encrypted data today to decrypt it later once quantum hardware becomes available. This is known as the “harvest now, decrypt later” principle. The more sensitive the data your organization manages and the longer that data must remain confidential, the more urgent the migration is. In this article, we answer the most frequently asked questions about post-quantum migration, from identifying vulnerability to drawing up a concrete migration plan.

How do you know if your organization is vulnerable to quantum threats?

Your organization is vulnerable to quantum threats if you use asymmetric cryptography such as RSA, ECC, or Diffie-Hellman. These are the most common algorithms for securing network communications, digital signatures, and key exchange. Virtually every organization that encrypts data or uses secure connections falls into this category.

The vulnerability lies not only in the technology itself, but also in the data you protect with it. Ask yourself these questions:

  • Does your organization hold data that must remain confidential for the next ten to fifteen years?
  • Do you use digital signatures for authentication or document integrity?
  • Are there compliance obligations that require long-term confidentiality, such as in healthcare or critical infrastructure?

If you answer yes to one or more of these questions, the risk is real. Sectors such as healthcare, finance, government, and critical infrastructure face an elevated risk because their data remains sensitive for a long time. But industrial environments and data centers are also vulnerable due to the long lifespan of their systems and the sensitivity of their communications.

What is the right time to start a post-quantum migration?

The right time to start a post-quantum migration is as early as possible, but no later than 2030. By 2026, the NIST post-quantum standards will have been published and governments and regulatory bodies worldwide will begin establishing concrete migration requirements. Waiting until quantum computers are operational is too late.

A post-quantum migration is not a simple software update. It is an architectural change that requires time, resources, and careful planning. Organizations that start now have the space to work in phases and manage risks. Organizations that wait will be forced to migrate critical systems under time pressure, increasing the likelihood of errors and vulnerabilities.

Moreover, the already-mentioned “harvest now, decrypt later” risk applies: data intercepted today can be decrypted in a few years. This means the urgency for sensitive data already exists now, not only when quantum computers become available.

Which systems and protocols should be migrated first?

The systems and protocols that should be migrated first are those that process the most sensitive data or have the longest lifespan. Prioritize systems based on two criteria: the sensitivity of the data and the time required to migrate the system.

Concretely, this means you address the following categories first:

  1. Key exchange protocols such as TLS and SSH, which are used daily for secure communications
  2. VPN connections and network tunnels that protect sensitive business communications
  3. Digital signatures for authentication, documents, and code signing
  4. Long-term storage systems that archive confidential data
  5. Critical infrastructure with long operational lifespans, such as industrial control systems

Systems with a longer lifespan deserve extra attention. If a network device or encryption solution lasts ten years, then the post-quantum migration must be factored into the procurement and design cycle now. Encryption solutions at layer 1 and layer 2 are a logical starting point here, as they protect data before higher-layer protocols are reached.

What are the NIST post-quantum standards and why are they important?

The NIST post-quantum standards are a set of cryptographic algorithms developed and certified by the American National Institute of Standards and Technology (NIST) to withstand attacks from quantum computers. The three primary standards are ML-KEM (for key exchange), ML-DSA and SLH-DSA (for digital signatures).

They are important because they form the international reference for quantum-safe security. Governments, regulatory bodies, and major technology vendors base their migration requirements on these standards. Organizations that comply with the NIST standards are not only technically prepared for the quantum threat, but also better positioned for future compliance requirements.

For organizations in Europe, it is also relevant that the NIST standards are being followed by European bodies such as ENISA. Those who migrate to these algorithms now are building a future-proof cryptographic foundation that aligns with both international and European regulations.

How does a post-quantum migration differ from a regular security upgrade?

A post-quantum migration differs fundamentally from a regular security upgrade because it is not a matter of patching a vulnerability, but of replacing the cryptographic foundations of your network infrastructure. Regular upgrades resolve known issues. A post-quantum migration prepares you for a future threat that renders the current mathematics behind encryption obsolete.

Concrete differences:

  • Scope: A regular upgrade affects one system or protocol. A post-quantum migration affects all systems that use asymmetric cryptography, across the entire organization.
  • Time horizon: Regular upgrades are reactive. Post-quantum migration is proactive and requires long-term planning spanning multiple years.
  • Complexity: New algorithms have different key sizes and performance characteristics, which affect hardware, software, and network capacity.
  • Interoperability: During the migration, systems must temporarily support both classical and post-quantum algorithms, an approach known as “cryptographic hybridization.”

This makes post-quantum migration a strategic project that requires alignment between IT, security, and management — not a technical task you handle on the side.

What steps does an organization take in a post-quantum migration plan?

A post-quantum migration plan consists of five concrete steps: inventory, prioritize, plan, migrate, and monitor. This approach ensures a controlled transition without unnecessary risks to business continuity.

Below is an overview of the steps:

  1. Cryptographic inventory: Map out which systems, protocols, and algorithms you use. This is the foundation of everything. Without complete visibility, you cannot prioritize.
  2. Risk assessment: Determine which data is most sensitive and how long it must remain confidential. This determines the urgency per system.
  3. Migration strategy per system: Choose the right approach for each system: hybrid implementation (classical and post-quantum), direct replacement, or phasing over multiple years.
  4. Implementation and testing: Carry out the migration in phases, starting with the most critical systems. Test thoroughly for performance and interoperability before switching over production systems.
  5. Ongoing management and monitoring: Post-quantum cryptography is an evolving field. Keep track of standards and threats and adjust your cryptographic policy where necessary.

For organizations looking to start this journey, external expertise is often valuable. We help organizations navigate this process, from the initial inventory to the implementation of protection against quantum threats at the network level. A good migration plan also takes the broader network security architecture into account, so that post-quantum cryptography integrates seamlessly with existing security layers.

The core of a successful plan is realism: start small, learn from the first migrations, and scale up. Organizations that approach this in a structured way not only build resilience against quantum threats, but simultaneously strengthen their overall security posture.

 

Ready for the next step?

Explore our solutions or get in touch directly with one of our experts.

 

Smart Connections for Your Organization

Would you like to learn more about what we can do for your IT organization? Our experts would be happy to help!