• 4 min read
Enterprises face a post-quantum deadline without a date
Google, the NCSC and the G7 set different post-quantum deadlines. Enterprises must inventory encryption now to meet a threat already affecting planning.

Image: TechRadar
Quantum computing is no longer a distant security concern for enterprises. The post-quantum migration deadlines are already arriving, even though the organizations setting them do not agree on a single date: Google has committed to completing its migration by 2029, the UK’s National Cyber Security Centre (NCSC) says 2035, and the G7 says 2034.
The deadlines follow NIST’s completion of its first full suite of post-quantum cryptographic standards, which has prompted mandatory migration planning in regulated industries. TechRadar’s analysis, produced as part of its Pro Perspectives series, argues that the timing differences matter less than the shared conclusion: companies need to begin preparing now.
The “harvest now, decrypt later” threat
Unlike the Y2K problem, quantum risk is not tied to one specific date. Attackers can already collect encrypted data and hold it until sufficiently capable quantum computers become available to decrypt it — a strategy known as “harvest now, decrypt later.”
That creates a problem for information with a long useful life. Financial records, personal data, and intellectual property may remain sensitive for years or decades, meaning encryption decisions made today could affect future security and reputation.
According to the TechRadar article, 87% of organizations are concerned about harvest-now, decrypt-later scenarios as quantum computing advances. Progress in quantum hardware and AI-accelerated quantum optimization is also described as bringing “Q-Day” closer, although the article does not provide a specific forecast for when that capability will arrive.

Recommended reading
Horizon3 raises $250 million at $2 billion valuation
The issue has already been gaining attention beyond cryptography. Researchers have examined both the potential vulnerabilities of quantum communication and ways quantum systems might improve machine-learning predictions, as recent research on quantum randomness and neural networks illustrates. Those developments do not establish a timetable for breaking today’s encryption, but they reinforce why organizations are treating quantum computing as an operational planning issue rather than purely theoretical research.
Why post-quantum migration is harder than Y2K
The Y2K remediation effort focused on a relatively well-defined software problem: systems that stored years using two digits rather than four. Post-quantum cryptography is broader because cryptographic controls are embedded throughout modern infrastructure, including:
- Applications and APIs
- Cloud services
- Internet of Things devices
- Operational technology
- Certificates and cipher suites
- Third-party integrations
Many of those controls are invisible to the teams responsible for securing them, and documentation may be incomplete. Organizations therefore cannot simply replace a known component. They first need to discover where encryption is used, which protocols are active, and what dependencies exist between managed and unmanaged systems.
The recommended starting point is a comprehensive inventory of cryptographic assets. That means identifying weak cipher suites, expired certificates, and encryption methods that no longer meet compliance requirements. The article then recommends standardizing on stronger protocols such as Transport Layer Security (TLS) 1.3.
It claims that older versions, including TLS 1.1 and TLS 1.2, will be broken by quantum computers in “hours, minutes, or even seconds.” The piece does not provide a technical basis or benchmark for that specific timeframe, so enterprises should treat it as an assertion rather than a quantified forecast.
Visibility is the first migration requirement
A company cannot replace cryptography it does not know it is using. Ninety-one percent of organizations reportedly consider visibility into encrypted traffic critical to post-quantum readiness, according to the article.
Network-derived telemetry is presented as one way to build that visibility. By examining traffic flows and metadata, security teams can map cryptographic usage across systems that may not appear in internal inventories. This outside-in view can reveal hidden dependencies, including connections to unmanaged assets and third-party services.
That information supports three practical steps: assessing risk more accurately, prioritizing remediation, and checking that a move to quantum-resistant cryptography does not create new weaknesses elsewhere. The migration also requires coordination among security, infrastructure, development, and compliance teams, as well as vendors and strategic partners.
The Y2K lesson is to start before the deadline
Y2K ultimately led to major infrastructure upgrades because organizations treated a known, distributed problem as a program of work rather than waiting for a single crisis. TechRadar draws the same lesson for post-quantum cryptography. By 1995, the New York Stock Exchange had spent more than $30 million remediating its systems, demonstrating how expensive late-stage preparation can become even when the underlying issue is understood.
The difference today is that quantum migration spans a more interconnected technology stack and involves data that adversaries may already be collecting. Organizations that inventory their cryptographic assets, monitor encrypted traffic, and create structured transition plans can control the sequence of their changes. Those that wait will face a shrinking window for a remediation effort with no single finish line.
The deadlines from Google, the NCSC, and the G7 differ by as much as six years. That disagreement does not reduce the urgency; it makes an early inventory more valuable, because discovering the scale of the work is itself likely to take time.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


