With the rise of quantum, current encryption systems could become obsolete by 2030, making it necessary to anticipate the transition to a “quantum-safe” environment today.
With the rise of quantum computing, considerable opportunities are opening up in terms of research, optimization and fraud detection. This advance has its downside: the day the quantum computer is fully operational (the famous “Q-Day”), it will be capable of breaking current encryption algorithms. Many of the mechanisms that protect trade today will become vulnerable.
Many place this deadline around 2030. On the scale of IT transformations, it is tomorrow. Especially since the threat is already there, it does not wait until the algorithms are actually broken. So-called “harvest now, decrypt later” attacks consist of intercepting encrypted data today to store it and decrypt it later. High-value, long-life information (health data, industrial secrets, intellectual property) is particularly exposed.
At the same time, the regulatory framework is becoming clearer. The National Institute of Standards and Technologies (NIST) in the United States plans to begin gradually removing current encryption algorithms from official standards and usage by 2030. For its part, the European Union is pushing critical infrastructures to adopt post-quantum cryptography mechanisms within the same horizon, notably through its initiatives around the European Quantum Act, which aims to structure and accelerate the adoption of quantum technologies. The trajectory is clear: the transition to a “quantum-safe” environment must begin now.
Structuring the preparation
While quantum risk may still seem distant, the decisions to be made are immediate. They are as much about strategy as technique. Quantum assessments make it possible to transform a theoretical threat into an operational roadmap.
Several projects must be undertaken without delay:
● Identify the most exposed systems and data, by mapping critical environments and assessing their vulnerability to “harvest now, decrypt later” scenarios.
● Define a migration trajectory towards post-quantum cryptography (PQC), progressive and consistent with regulatory deadlines, in order to avoid a rushed transformation as 2030 approaches.
● Align the technological ecosystem and suppliers with emerging standards, by integrating appropriate compliance requirements into investment choices.
● Clarify the governance of quantum risk, by designating a manager, structuring a dedicated task force and integrating this subject into overall risk management systems.
● Strengthen cryptographic agility, that is to say the ability to quickly replace algorithms that have become vulnerable as standards evolve.
Modernize to anticipate
Preparing for Q-day also reveals a broader issue: the real maturity of existing infrastructures. Obsolete environments, poorly or poorly maintained equipment, or insufficiently structured incident management processes weaken the entire security system. Post-quantum cryptography alone will not compensate for structural weaknesses.
Hence the interest in immediately integrating the quantum dimension into current modernization programs (cloud migration, network overhaul, application transformation). This avoids treating the subject separately and smoothing out the investment over time. Each new technological project should now be evaluated based on its compatibility with a “quantum-safe” environment.
Q-day may not have a specific date, but the technological and regulatory signals are already there. Anticipating today helps avoid urgent transformations tomorrow. Quantum preparation is now emerging as a strategic issue of digital resilience.
Ultimately, the real question may not be when it will arrive, but whether organizations will be ready when the time comes. Between anticipation and wait-and-see, the choices made today matter: endure quantum, or make it an opportunity.