At a glance
Quantum computing has the potential to break some of the cryptographic algorithms that organisations rely on today. While cryptographically relevant quantum computers are not yet available, preparing for post-quantum cryptography (PQC) should start now.
Early planning helps organisations manage long transition timeframes, reduce future risks and align technology investments with evolving standards.
This blog is for organisations looking to understand why PQC planning is a business priority, not just a cyber security challenge.
Start preparing before the threat arrives
It may seem early to think about quantum-resistant cryptography when large-scale quantum computers are still years away. However, waiting until a cryptographically relevant quantum computer emerges could leave organisations with limited time to make complex and potentially disruptive changes.
For many organisations, cryptography is embedded across:
- applications and websites
- authentication and identity systems
- cloud services
- hardware devices
- operational technology environments.
Reduce reliance on legacy technology
Technology vendors are already introducing PQC into products and services. Over time, traditional cryptographic solutions will become increasingly difficult to support as products and services adopt hybrid or PQC-only implementations.
Organisations that delay planning may find themselves reliant on outdated technologies or forced into rushed upgrades. By preparing early, organisations can align procurement, technology refresh cycles and security investments with future requirements.
Follow a structured approach to transition
Planning for PQC does not need to be overwhelming. The LATICE framework provides a practical starting point:
- Locate cryptographic dependencies.
- Assess the value and sensitivity of systems and data.
- Triage systems based on risk and criticality.
- Implement PQC to systems.
- Communicate with vendors and service providers.
- Educate stakeholders across the organisation.

Organisations that start early will be better positioned to manage risk, minimise disruption and maintain trust in their systems and services. While the quantum threat may still be emerging, the work needed to prepare for it has already begun.
Build cryptographic agility
Cryptographic agility is the ability to adapt cryptographic systems as algorithms, threats and standards evolve. Following a structured process helps organisations build this agility. Organisations with strong visibility of their cryptographic dependencies are better positioned to respond to future security challenges.
Further information:
Harry W