At a glance
Quantum computing could eventually undermine some cryptographic protections used today.
While a cryptographically relevant quantum computer does not yet exist, organisations should begin planning now to reduce future risk. Early preparation will help organisations identify cryptographic dependencies, manage complex transitions and protect sensitive data.
Why organisations need to prepare for quantum computing
Many organisations rely on asymmetric cryptography to secure communications, protect sensitive data and verify identities. While these protections remain secure today, a cryptographically relevant quantum computer (CRQC) could break traditional asymmetric cryptographic algorithms that many systems rely on.
The exact timing of a CRQC remains uncertain. However, delaying preparation could leave organisations with too little time to respond. Preparing now allows organisations to reduce future risk and make informed decisions about their technology investments.
Post-quantum cryptography offers a practical path forward
Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist attacks from both classical and quantum computers. These algorithms play a key role in maintaining the security of systems and data in a future where CRQCs exist.
For many organisations, PQC provides a practical and cost-effective approach to protecting data without fundamentally changing how systems operate.
Start planning now
Transitioning to PQC may take longer than many organisations expect. Identifying cryptographic dependencies, upgrading or replacing systems, and implementing cryptographic solutions can be a complex process.
Early planning reduces risk
Early planning is important because:
- transitioning large and complex environments may take several years
- estimating the timeline for a CRQC remains uncertain
- protecting data using traditional asymmetric cryptography may be vulnerable to future attacks on confidentiality and integrity.
The longer data and systems need to remain secure and trustworthy, the more important it is to consider quantum-resistant protections now.
Follow the recommended transition timeline
We provide guidance through the Information security manual (ISM) on approved cryptographic algorithms, key sizes and parameters. The ISM recommends organisations cease using traditional asymmetric cryptography by the end of 2030 and adopt ASD-approved post-quantum cryptographic algorithms.
The diagram below outlines the recommended PQC transition timeline against the increasing risk of a CRQC becoming available over time.
We will continue to update guidance as post-quantum cryptographic algorithms mature and new use cases emerge.
Take the first step
You do not need to replace every cryptographic system immediately. Start by:
- locating where cryptography is used across your organisation
- understanding which systems rely on traditional asymmetric cryptography.
Organisations that begin planning now will be better positioned to manage future risks and securely transition to post-quantum cryptography.
Further information
Jess C