Your Cryptography Is Now Legacy
There’s a specific kind of silence that happens in a boardroom when someone mentions "Post-Quantum Cryptography." It's the sound of executives assuming it's a problem for 2035, while the people actually running the servers are staring at a calendar.
NIST has been laying the groundwork for years, but the window for migration is closing faster than most CISO reports suggest. The real alarm isn't coming from a government white paper; it’s coming from the plumbing. Ethereum is pushing a post-quantum roadmap that effectively sets a 2027 deadline for financial institutions to migrate their systems. For anyone under the DORA umbrella, this isn't a suggestion. It's a ticking clock.
Most firms I talk to describe their crypto-agility programmes as 'mature'. Whenever I hear that word, I immediately start looking for the gaps. In my experience, 'mature' usually means they’ve hired a consultancy to produce a very expensive PDF that explains what quantum computing is. It rarely means they know where every single instance of RSA or ECC lives in their environment.
Which brings us to the Tuesday test. If an assessor walked into your office on a Tuesday morning and asked for a comprehensive registry of every encrypted data store, transit tunnel, and third-party API that relies on classical asymmetric cryptography, what would you show them?
If the answer is a slide deck about "strategic alignment," you've already failed. An auditor doesn't want a strategy; they want an inventory. They want to see a list of assets, the current algorithm in use, and a scheduled date for the swap to PQC standards. If you can't produce that list, your programme isn't mature. It's imaginary.
The strongest objection I hear is that cryptographically relevant quantum computers don't exist yet. Why spend millions replacing working encryption for a threat that's still theoretical?
That logic ignores the "harvest now, decrypt later" reality. Attackers aren't just stealing data to use it today; they’re hoarding encrypted archives to crack them the moment a quantum computer becomes viable. Look at the DentaQuest breach from this year. North of 15 million records were exposed. Some of that data is transient, but a lot of it is permanent health history. For an attacker, those 15 million files are just waiting for the key to be broken in three or four years. The theft happened today, but the breach is effectively ongoing until the encryption is upgraded.
This creates a nasty second-order effect for cyber insurance. We're approaching a point where insurers will stop viewing quantum vulnerability as an "unforeseen event." Once NIST standards are fully codified and DORA deadlines hit, failing to migrate isn't a technical hurdle—it's professional negligence. I suspect we'll see a wave of claims denied because the policyholder ignored a public migration window that lasted years.
The auditors will be the first to catch this, but not through some brilliant insight. They'll catch it because they're tired of seeing "in progress" as a status update for three years running. When the 2027 deadline arrives, 'in progress' becomes a finding.
You can't patch your way out of a fundamental cryptographic shift. You have to rebuild the trust layer. Most companies are still trying to figure out how to manage their cloud spend, let alone re-architecting their entire encryption stack.
I’m curious to see who actually has a hardware-backed inventory ready for review. I'll bet it's fewer than five percent of the firms claiming "maturity."
Check your vendor contracts this week. See if they even mention PQC migration. If they don't, you aren't just inheriting their risk; you're subsidising their laziness.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- DentaQuest Breach Affects 15 Million in Largest US Health Data Breach Reported in 2026 - techrepublic.com InfoSec Compliance (Google News)
- French National Bank Authority Breach Exposed 1.2 Million Accounts - The Cyber Express - The Cyber Express Data Privacy (Google News)
- SEC bans capital market firms from dealing with North Korean, Iranian banks - thestreetjournal.org Compliance Week (Google News)
- SEC Bans Capital Market From Dealing With North Korea, Iran - LEADERSHIP Newspapers Compliance Week (Google News)
- French Finance Ministry's Data Breach Shock - Devdiscourse Data Privacy (Google News)
- Why Hub Group (HUBG) Is Down 9.9% After Delaying Its Quarterly 10-Q Filing With SEC - Sahm Compliance Week (Google News)
- SEC Proposes Easing 'Pay-to-Play' Rules: What It Means for Crypto and Asset Management - Binance Compliance Week (Google News)
- California Agency Fines Iowa Data Broker $116,490 in First Dual Enforcement Action - yovenice.com Data Privacy (Google News)