Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
post-quantum-cryptographystandards-framework-update

Post-Quantum Cryptography Migration and Its Impact on Security Infrastructure

Updated 2mo agoFirst seen Oct 29, 202512 sources

Security experts are intensifying efforts to develop and implement post-quantum cryptography (PQC) in anticipation of the eventual arrival of quantum computers capable of breaking current encryption algorithms, a milestone referred to as "Q-Day." The transition to PQC is recognized as a complex, multi-year process that requires not only new cryptographic algorithms but also significant changes to cybersecurity infrastructure, including the adoption of hybrid solutions and the integration of PQC into zero-trust architectures. High-security sectors are particularly urged to begin migration early to mitigate the risk of "harvest now, decrypt later" attacks, where adversaries collect encrypted data now to decrypt once quantum capabilities are available.

Industry analysts highlight that the migration to post-quantum encryption presents unique challenges compared to previous cryptographic upgrades, as it involves extensive updates to hardware, software, and system architectures. While some areas, such as blockchain, are not immediately threatened by quantum computing, the scale and complexity of the migration require coordinated efforts across security, product management, and IT operations. Experts emphasize the need for proactive planning and the adoption of best practices to ensure a smooth transition before quantum computers become a practical threat to digital security.

Share:
Post-Quantum Cryptography Migration and Its Impact on Security Infrastructure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
May 5, 20262mo ago

Proton Mail rolls out optional post-quantum encryption to all users

Proton Mail announced immediate availability of post-quantum encryption for newly sent encrypted emails across its platform, including free accounts and its more than 100 million users. The rollout keeps existing RSA and ECC protections as the baseline, adds OpenPGP v6 support, and is framed as a response to the 'harvest now, decrypt later' threat.

Proton Mail rolls out post-quantum encryption for all users as industry braces for 'harvest now, decrypt later' threat - IT Security Guru
Apr 17, 20262mo ago

Microsoft outlines PQC migration strategy with 2033 readiness deadline

Ars Technica reported that Microsoft said its most distant post-quantum cryptography readiness deadline is 2033 and that its migration strategy prioritizes NIST standards, customer compatibility, and platform-led rollout across Windows, Azure, and identity systems. The same reporting also described Amazon, Meta, and Apple as taking differing approaches to PQC readiness, with Meta publishing maturity guidance rather than a public deadline.

Recent advances push Big Tech closer to the Q-Day danger zone - Ars Technica
Apr 9, 20263mo ago

Google says breaking ECC with Shor may need far fewer qubits

Google recently claimed that solving the elliptic curve discrete logarithm problem with Shor’s algorithm may require about 20 times fewer physical qubits than previously estimated. The finding renewed concern about the long-term safety of legacy elliptic-curve cryptography and intensified debate over the urgency of post-quantum migration.

Cryptographers place $5,000 bet whether quantum will matter • The Register
Mar 4, 20264mo ago

Traficom publishes guidance on migrating to quantum-safe cryptography

Finland’s Transport and Communications Agency Traficom Cyber Security Centre published guidance warning that current encryption methods may not remain secure against future quantum computers and advising organizations to begin preparing for migration to quantum-safe cryptography. The guidance highlighted risks to long-term confidentiality for data such as personal, health, trade secret, and classified government information.

Ohje kvanttiturvalliseen salaukseen siirtymisestä julkaistu, infotilaisuus asiantuntijoille 11.5.2026 | Traficom
Oct 28, 20258mo ago

Experts say quantum computing is not yet a practical threat to blockchains

A 2025 expert discussion highlighted that quantum computing does not yet pose an immediate real-world threat to blockchain systems, indicating the risk remains more prospective than operational at present.

Oct 3, 20259mo ago

Finland sets PQC requirements for cryptographic product evaluations

Finland’s national cryptography working group issued policy guidance for national cryptographic product evaluations, requiring products entering evaluation on or after 2026-01-01 to use quantum-safe key establishment based on PQC KEMs and to use quantum-safe signatures or justify how quantum risks are addressed. The guidance also strongly recommended hybrid PQC-classical approaches and aligned Finland’s transition goals with EU timelines through 2030 and 2035.

Suomen kansallisen kryptotyöryhmän linjaukset kansallisiin PQC-salaustuotearviointeihin 1.1.2026 alkaen | Traficom
Jan 1, 20233y ago

Organizations launch post-quantum cryptography initiatives in 2023

Multiple post-quantum cryptography initiatives were launched during 2023 to prepare for future quantum threats, reflecting growing industry and government efforts toward migration readiness for 'Q-Day.' The references do not provide specific initiative dates or names beyond indicating that these efforts began in 2023.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

77 LINKEDOpen in app
Malware
1 linked
Affected products
28 linked
ThunderbirdOpensslOpensslWolfsslKubernetesAzure Active DirectoryWindows 11StripeCloudflareWindows 10GithubTerraformAmazon Web ServicesWindows Server 2025ImessageKafkaAws CloudformationVaultAnsibleAndroidBoringsslAuthenticodePostgresqlChromeAws-LcIosMacosJava
Organizations
48 linked
MozillaProtonGoogleAmazon Web ServicesAppleMeta PlatformsMicrosoft CorporationApplied QuantumCloudflareThalesDigiCertPing IdentityUtimacoThe RegisterOpenSSL Software FoundationJuniper ResearchAtlassianCitigroupWolfsslTom's HardwareSectigoInternational Business MachinesVisaOktaAdvanced Micro DevicesDark ReadingHashicorpAccentureOmdiaAdyenEntrustDockerDeloitteStripeMastercardGitHubRedditTechTargetJCB Co., Ltd.AiStrikeVARBusiness MagazineCRNSunrunTom's Hardware GuideIT ProWorldpayTaurus SASEALSQ
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.