Speakers urge organisations to begin practical post-quantum testing while acknowledging that mapping dependencies and coordinating migration remain difficult
Organisations preparing for post-quantum cryptography need not wait for a complete inventory before testing how changes will affect critical systems, speakers at World Quantum Readiness Day 2026 concurred.
Their accounts pointed to a challenge beyond choosing new algorithms: finding where cryptography is used, identifying dependencies and coordinating changes across an organisation.
Some perspectives from the event are:
- Colin Soutar, Global Quantum Cyber Readiness Leader, Deloitte, described the transition as a risk-management and cybersecurity task rather than one requiring expertise in quantum physics.
- Sadaaki Yamazaki, Senior Security Specialist, Daiwa Institute of Research, said a proof of concept found the technical impact of adopting post-quantum cryptography more manageable than expected. Mapping cryptographic use and establishing governance were harder in that trial, he said. Its results may not reflect the demands of a wider production rollout.
- Christian Pfister, LGT Financial Services, said his firm had reached an initial milestone within six months by pursuing a targeted pilot instead of waiting for a complete cryptographic inventory. The account illustrates one way to begin testing, but the event report did not define the milestone or establish whether the approach would work equally well elsewhere.
- Government guidance gives organizations a reason to start that work, although timelines differ by jurisdiction. The Australian Signals Directorate recommends refining a transition plan by the end of 2026, beginning the transition of critical systems by the end of 2028 and completing migration by the end of 2030. Those are recommended milestones, not a blanket statutory deadline for every organization.
- Singapore’s Cyber Security Agency has published a migration handbook and self-assessment tool in July, with particular attention to critical information infrastructure owners and government agencies.
- The timing of a quantum computer capable of breaking widely used asymmetric cryptography remains uncertain. Planning can nevertheless begin with sensitive data and systems that will be difficult to change, while deployments need to account for implementation and interoperability risks
The discussion took place at the virtual event hosted by DigiCert.