The real threat is not the arrival of quantum, but the difficulty companies face in evolving their cryptography. Cryptographic agility is becoming a major resilience issue.
The post-quantum era is often presented as a coming threat: a technological disruption that would force companies to urgently rethink their cryptographic security. But this vision is reductive.
Quantum computing does not create the problem, it highlights a structural weakness that has already been present for several years in many companies. Because the real question is not only when current algorithms will become obsolete. It is to understand why so many critical systems continue to be designed as if cryptography were capable of resisting indefinitely in the face of technological disruption.
Cryptography has never been set in stone
For a long time, cryptographic security was approached as a one-off choice: select an algorithm, comply with current standards, deploy it, then move on. This approach has long seemed relevant in an environment where technological cycles seemed slow enough to make changes predictable. But this stability has, in reality, never been more than an illusion.
The history of cybersecurity demonstrates, on the contrary, that cryptography is, by nature, a field in perpetual evolution: standards follow one another, the power of calculations progresses, new vulnerabilities emerge, and mechanisms once considered robust gradually end up becoming obsolete. The problem is therefore not that cryptography is evolving but that the systems built around it are becoming more and more rigid.
When the risk is no longer technical, but structural
As digital environments become more complex, cryptography is integrated into hardware, applications, network infrastructures and business processes. Therefore, what should be a controlled development often turns into a heavy, costly and risky project.
This is precisely what distinguishes crypto risk from simple technical debt. As an infrastructure ages, performance can degrade. When a cryptographic foundation becomes obsolete, digital trust is called into question: identity, integrity, authentication, confidentiality. When these mechanisms are weakened, the entire IT ecosystem finds itself exposed.
Quantum sets a deadline, it does not change the nature of the problem
Quantum computing has at least one merit: it imposes on companies a reality that has remained theoretical for a long time; certain data encrypted today will have to remain protected for decades. However, if current mechanisms become vulnerable tomorrow, this information could be compromised retroactively.
The concept of Harvest Now, Decrypt Later already illustrates this risk: collecting encrypted data today to access it tomorrow when technological capabilities allow. But the real danger would be to consider the post-quantum as a unique migration.
Because after this migration, others will inevitably follow. Standards will continue to evolve, as will attack models. The challenge is therefore not only to migrate to new algorithms but to build a permanent capacity for adaptation.
Compliance is no longer enough
Many companies still approach cryptography from the sole angle of compliance: respecting recommendations, applying standards, validating audits. This approach remains essential but it only guarantees one thing: being aligned with the requirements of the moment.
However, no standard is definitive, it is inexorably destined to be replaced one day. Making compliance a goal therefore amounts to agreeing to undergo each technological transition instead of mastering it.
Cryptographic agility becomes a strategic imperative
This is the real paradigm: how to design architectures capable of evolving without disruption?
Concretely, this involves removing cryptography from application code, centralizing security policies, limiting fixed dependencies, and allowing controlled updates, without massive overhaul of systems. Cryptography then ceases to be an invisible technical constraint to become a governed and evolving strategic capability. This issue goes well beyond cybersecurity teams. It directly affects operational resilience, business continuity and the ability of companies to evolve without weakening their digital confidence.
Most businesses don’t start from scratch. You have to start by knowing where the certificates are located, understanding the existing dependencies, identifying which algorithms protect which assets, determining which systems are actually exposed. Only then comes control, then the ability to adapt.
Post-quantum is not an end. This is a signal that cryptographic security is not a one-off project, but an ongoing discipline. Companies that understand this will not only prepare for the next transition but for all those that follow.