Book an Appointment
IT Security · Response & Resilience

Post-Quantum Cryptography: migrate before Q-Day decides

Quantum computers will break RSA and ECC — and “Harvest now, decrypt later” already puts your data at risk today. We guide you safely through the EU and BSI deadlines of 2030/2035 with a readiness assessment, cryptographic inventory, and migration roadmap.

Aligned with the EU roadmap & BSI TR-02102-1Proven in DORA, NIS2 & PCI DSS engagementsVendor-neutral & audit-ready
> 50%

of human web traffic through Cloudflare already uses quantum-safe key establishment

Cloudflare, 10/2025
< 1M

noisy qubits are enough, according to Google research, to factor RSA-2048 in under a week — 20× fewer than estimated in 2019

Gidney, 05/2025
End of 2030

EU deadline for high-risk use cases — identical to the BSI deadline for very high protection requirements

EU Roadmap · BSI TR-02102-1
End of 2031

last date until which BSI recommends purely classical key establishment at all

BSI TR-02102-1 (2026-01)
The Threat Model

Harvest now, decrypt later: the attack is already underway

The quantum computer that breaks RSA-2048 doesn't exist yet — but attackers don't need to wait for it. Today, they're already capturing encrypted traffic and copied data sets and stockpiling them. As soon as a cryptographically relevant quantum computer (CRQC) becomes available, everything gets decrypted retroactively.

That's why what matters isn't the date of Q-Day, but the confidentiality lifetime of your data: anything that will still need protection in 10 years and is transmitted or stored today using classical encryption is already exposed. NIST and CISA explicitly warn against this pattern.

Especially exposed: data with a long shelf life (confidentiality lifetime)
  • Financial and transaction data
  • Health and insurance data
  • Contracts, M&A, and board documents
  • Design data & intellectual property
  • HR data and identities
  • PKI root keys & signature chains
Today
Capture

TLS traffic, VPN tunnels, backups, and data exfiltration are intercepted — inconspicuously, because the content is (still) unreadable.

In between
Store

Storage is cheap. Intelligence agencies and organized crime deliberately archive ciphertext for the day it can be broken.

Q-Day
Decrypt

A CRQC breaks the key establishment used at the time — unlocking the entire archived data set retroactively.

Interactive: The Mosca Test

Do the math: how much time do you really have?

Mosca's theorem makes the urgency measurable: if shelf life x plus migration time y is greater than the time z remaining until a cryptographically relevant quantum computer exists, your data is already lost — mathematically speaking, today. Set your own values:

x + y > z — you're already too late, mathematically.

Data captured today would be decryptable before its shelf life expires. HNDL-exposed transmission paths need to be prioritized immediately: a readiness assessment, cryptographic inventory, and a hybrid pilot this year.

After Michele Mosca (Institute for Quantum Computing, University of Waterloo). The test doesn't replace a risk analysis — it shows why your start date shouldn't depend on Q-Day.

Deadlines & Milestones

From NIST standards to the EU deadline

Regulators have set the timeline — backed internationally by the NSA (CNSA 2.0: exclusive PQC use per system category by 2030–2033). Click through the milestones:

End of 2026

EU: transition underway, national plans in place

All member states are expected to have started the transition and submitted national implementation plans. In concrete terms for businesses: a cryptographic inventory, risk analysis, and an initial roadmap belong in 2026.

Technology at a Glance

What replaces what: the algorithm explorer

The replacement map for your architecture — from key establishment to PKI. All these algorithms run on classical hardware; only the attackers need quantum hardware.

In Use TodayQuantum-Safe SuccessorStandard / Status
RSA encryption / RSA-KEMML-KEM (Kyber)FIPS 203 · final since 08/2024
ECDH / X25519Hybrid: X25519MLKEM768IETF standardization · default in Chrome, Edge & Firefox
Static DH keysKEM + ephemeral hybrid schemesBSI: hybrid via CatKDF / KeyCombine (SP 800-227)
HQC (reserve)code-based backup KEMNIST selection 03/2025 · standard expected 2027

For the transition period, BSI recommends hybrid key establishment: classical + PQC combined, so that a break in one algorithm doesn't cost you confidentiality.

Our Advisory Portfolio

PQC services: from inventory to operations

Modular and bookable individually — as a compact baseline assessment or as a guided migration program spanning several years.

01

PQC Readiness Assessment

A baseline assessment in 2–4 weeks: where does your organization stand against the EU roadmap, BSI TR-02102-1, DORA, and NIS2 — and what are the three most important next steps?

  • Maturity scoring across eight dimensions (inventory, governance, architecture, supply chain …)
  • Gap analysis against the EU/BSI deadlines of 2030/2031/2035
  • Initial HNDL exposure assessment for your most critical data flows
  • Management report with a decision template and budget framework
02

Cryptographic Inventory & CBOM

You can only migrate what you know about. We survey your cryptographic landscape across network, code, and infrastructure — consolidated into a maintained Cryptography Bill of Materials.

  • Automated TLS, certificate, and protocol scans (external & internal)
  • Code and repository analysis for cryptographic calls and hardcoded algorithms
  • HSM, PKI, KMS, and cloud KMS inventory, including suppliers
  • CBOM (e.g., CycloneDX) as a living inventory — satisfies PCI DSS 4.0.1 Req. 12.3.3 and DORA documentation requirements
03

Quantum Risk Analysis & Prioritization

Not everything needs to migrate immediately — but the right things need to migrate first. We assess systems by shelf life, HNDL exposure, and criticality, and prioritize your migration sequence.

  • Mosca analysis per data class: shelf life × migration time × time remaining
  • Prioritization methodology modeled on Europol/FS-ISAC guidance for the financial sector
  • Risk register with quantum risks for your ISMS (ISO 27001 / BSI IT-Grundschutz)
  • Coordinated migration waves: high-risk first, legacy systems last and under control
04

Migration Roadmap & Crypto-Agility

The roadmap through 2030/2035: a target architecture with centralized key management, governance, and policies — with crypto-agility as a design principle, so the next algorithm change becomes routine.

  • Target state: centralized key management (KMS/HSM orchestration) instead of scattered key stores
  • Crypto-agility embedded in architecture standards, procurement policies, and supplier contracts
  • Phased plan with milestones, budget, and resource path for each migration wave
  • Governance: crypto owners, steering committee, exception register, and KPI reporting
05

Piloting & Implementation Support

From paper to production: we support hybrid pilots and the first migration waves — with testing that realistically models larger keys, handshake latency, and failover.

  • Hybrid TLS pilot (e.g., X25519MLKEM768) on live services
  • PKI pilot with PQC/dual certificates for internal services and code signing
  • HSM/KMS upgrades and library rollout (OpenSSL 3.5+, BouncyCastle, liboqs)
  • Performance, interoperability, and failover testing, including SOC visibility into new algorithms
06

Compliance Mapping & Evidence

Turning deadlines into audit-ready evidence: we translate DORA, NIS2, PCI DSS, and CRA into your cryptographic policies and prepare you for audits and supervisory conversations.

  • DORA mapping: encryption and key management policy under Delegated Regulation (EU) 2024/1774 Art. 6–7
  • NIS2 Art. 21(2)(h): a state-of-the-art cryptography concept, integrated into your ISMS
  • Audit preparation: evidence, exception register, progress reports to supervisory authorities
  • Training for architecture, security, and procurement teams
Approach

Five phases to a quantum-safe organization

A proven sequence drawn from financial-sector and KRITIS projects — each phase with clear deliverables, each phase can be commissioned individually.

Create visibility

Timeframe: Weeks 1–4

Cryptographic inventory and CBOM setup, governance structure with crypto owners, vendor inquiries — and quick wins: SHA-1, 3DES, and RSA-1024 get retired immediately.

Deliverables
  • Cryptographic inventory & CBOM
  • Governance structure & mandate
  • Quick-win list with immediate actions

Timeframes reflect a typical mid-market profile. Enterprise landscapes and heavily regulated institutions should plan longer per wave — which is exactly what prioritization is for.

Regulation & Industries

Where quantum readiness is already becoming mandatory

PQC isn't a distant technology question anymore — it has arrived in supervisory law and standards:

Financial Sector & Insurers

DORA · Delegated Regulation (EU) 2024/1774 · PCI DSS 4.0.1

Since January 2025, DORA has required documented, state-of-the-art encryption and key management policies; PCI DSS 4.0.1 has required a maintained cryptographic inventory since March 2025. Europol (QSFF) and the G7 are pushing the sector to prioritize migration now.

DORA × ISO 27001

KRITIS & NIS2 Entities

NIS2 Art. 21(2)(h) · BSIG

NIS2 explicitly names cryptography and encryption as a mandatory, state-of-the-art measure — and the EU roadmap classifies critical infrastructure as a high-risk use case with a deadline of end of 2030. Your cryptography concept belongs in the ISMS, not in an appendix.

NIS2 Advisory

Products & Industry

CRA · long product life cycles

Products launched under the Cyber Resilience Act from 2027 onward, with 10–15-year field lifetimes, will experience Q-Day while still in service. Crypto-agility and updatable key schemes become a design requirement — from automotive to medical technology.

Product Security

Trust Services & the Public Sector

eIDAS 2.0 · ETSI · national plans

ETSI is tightening minimum requirements (including RSA from 3000 bits for trust services), and EU member states will submit national PQC plans by end of 2026. If you work with government agencies or public tenders, expect to see quantum readiness show up in procurement requirements.

IT Security Audits
Self-Check

How quantum-ready are you?

Six questions, two minutes — an honest baseline assessment along the same checkpoints we use in our own assessments.

  1. Do you have a current, complete cryptographic inventory — algorithms, keys, certificates, protocols, including cloud and suppliers?
  2. Do you know the required confidentiality lifetime (shelf life x in the Mosca test) for your most important data types?
  3. Is crypto-agility embedded as a requirement in architecture standards, procurement policies, and supplier contracts?
  4. Is there a named owner (crypto owner, steering committee) and a management mandate for the PQC migration?
  5. Have you queried and documented the PQC readiness of your HSMs, PKI, KMS, and critical suppliers?
  6. Is a hybrid pilot (e.g., TLS with X25519MLKEM768) already running on a live system?

Answer all six questions to see your results.

FAQ

Frequently asked questions about PQC migration

What is post-quantum cryptography (PQC)?

Post-quantum cryptography (PQC) refers to cryptographic algorithms that remain secure even against attacks using quantum computers — for example, ML-KEM (FIPS 203) for key establishment and ML-DSA (FIPS 204) for signatures. PQC runs on today's classical hardware: you don't need a quantum computer to protect yourself. PQC should be distinguished from Quantum Key Distribution (QKD), which requires specialized hardware and, according to BSI, does not replace classical algorithms.

When will quantum computers be able to break RSA and ECC?

There's no reliable date — estimates for a cryptographically relevant quantum computer (CRQC) range from the early 2030s to 2040. Resource estimates, however, are dropping fast: Google researchers showed in 2025 that under a million noisy qubits could be enough to break RSA-2048 — 20 times fewer than assumed in 2019. Because of Harvest now, decrypt later, the exact date is secondary anyway: long-lived data is already exposed today.

What does “Harvest now, decrypt later” mean?

Attackers record and store today's encrypted communications and data sets so they can decrypt them retroactively once a quantum computer becomes available. NIST and CISA explicitly warn against this pattern. This affects anything whose shelf life extends beyond the expected Q-Day — financial and health data, contracts, design data, identities.

What deadlines apply in the EU and in Germany?

The EU roadmap (NIS Cooperation Group, June 2025) requires: transition start and national plans by end of 2026, migration of high-risk use cases by end of 2030, and completion as far as possible by end of 2035. BSI recommends, in TR-02102-1 (2026-01): very high protection requirements migrated by end of 2030, purely classical key establishment only until end of 2031, and classical signature schemes phased out by end of 2035. NIST (draft IR 8547) plans to classify RSA/ECC as deprecated from 2030 and disallowed from 2035.

What do DORA and NIS2 specifically require for cryptography?

Via the Delegated Regulation (EU) 2024/1774 (Art. 6–7), DORA requires documented policies for encryption and cryptographic key management across the full lifecycle — including a certificate inventory and an obligation to follow leading practices. NIS2, in Art. 21(2)(h), names cryptography and encryption as a mandatory, state-of-the-art measure. In effect, both frameworks presuppose a cryptographic inventory and crypto-agility.

What is crypto-agility — and why isn't a one-time switch enough?

Crypto-agility is the ability to swap out cryptographic algorithms without a redesign — through central libraries, configuration instead of hardcoding, and centralized key management. It's a core requirement of both the EU roadmap and supervisory practice, because algorithms will keep changing: NIST has already selected HQC as a backup KEM, and FN-DSA is nearing finalization. Migrate with agility today, and the next switch becomes routine instead of a project.

What is a CBOM (Cryptography Bill of Materials)?

A CBOM catalogs, in machine-readable form, which cryptographic algorithms, keys, certificates, and libraries are embedded in your systems and products — analogous to an SBOM for software components, for example in CycloneDX format. It's the working tool of migration: without a CBOM, there's no solid prioritization, no supplier management, and no evidence for auditors and supervisory authorities.

Does AES need to be replaced — and what does getting started cost?

Symmetric algorithms and hash functions are considered quantum-resistant: the Grover algorithm effectively halves the security level, which is why AES-256 is recommended over AES-128 — a configuration change, not an architectural overhaul. Migration efforts focus on asymmetric algorithms. Getting started is predictable: our PQC readiness assessment takes two to four weeks and delivers a maturity score, gap analysis, and prioritized roadmap as a basis for decision-making.

Let's talk about your PQC roadmap

30 minutes, a concrete initial assessment: where do you stand against the 2030/2035 deadlines — and what's the most sensible first step for you? No obligation, vendor-neutral, with an NDA on request.

We typically respond within one business day.