Enterprise risk
Quantum computing is an imminent threat to assumed data privacy and operational security.
Organisations must start planning now to assess and mitigate the risks related to post-quantum cryptography (PQC).
Australia sets the local planning baseline.
Data, standards, government, suppliers and internal migration run at different speeds. ASD recommends organisations should have a refined plan by end-2026, should have commenced transition by end-2028 and should have completed it by end-2030.
Name the sponsor. Test the 2026 plan now.
Define scope, ownership, priority data and the migration approach.
Named sponsor, approved scope, inventory method, funding path and critical dependencies.
Accountable input: Data owners and risk owners
Dates differ. The work converges.
Canada, the EU, France, the UK and the US use different dates, audiences and legal effects. Together, they reinforce inventory, prioritisation, crypto-agility, procurement and supplier engagement.
Project implication: prepare for supplier and market pressure across jurisdictions.
Australia
- Audience
- Businesses, infrastructure and government; ISM controls only where applicable
- Legal effect
- Broad dates are advisory recommendations. ISM outcomes depend on system scope and lawful applicability.
- Australian enterprise implication
- Use 2026, 2028 and 2030 as the local planning baseline, then test which controls apply.
Standards and readiness
Standards are available. Readiness still needs proof.
Final standards support controlled discovery and testing. NIST states the new algorithms will likely not be drop-in replacements; performance, interoperability and supplier implementation still need validation.
Fund trials. Require product-specific evidence from suppliers.
NIST FIPS 203, 204 and 205 are final.
Select candidate functions for controlled design and testing.
Publication does not prove product readiness and does not set an enterprise deadline.
Evidence needed before production
These are checks, not controls. Each requires organisation-specific evidence.
- Inventory
Know where public-key cryptography supports priority data and services.
- Product support
Confirm supported implementations, roadmaps and deprecation paths.
- Interoperability
Test clients, services, suppliers and trust chains together.
- Performance
Measure service, network, device and operational impact.
- Rollback
Prove a safe return path before production cutover.
- Governance
Record approval, ownership, exceptions and residual risk.
Set direction before the transition sets it for you.
The board does not need to select algorithms. It needs clear ownership, scope, supplier commitments, testing, lifecycle funding and managed exceptions.
Require a staged readiness plan with decisions, evidence and owners.
Questions management should answer before the board sets direction.
- Accountability
Who owns the enterprise transition, and which decisions need board oversight?
Name an executive sponsor, risk owner and reporting cadence.
- Scope
Which services, data, trust functions and assets are material enough to enter the first migration waves?
Fund a risk-led cryptographic inventory and dependency map.
- Suppliers
Which suppliers can provide product- and version-specific support, roadmap and deprecation commitments?
Use procurement and renewal decisions to close the critical gaps.
- Testing
Which changes require interoperability, capacity, rollback and operational testing before production?
Run controlled trials before broad deployment or legacy retirement.
- Asset lifecycle
Which assets cannot accept change through normal support and maintenance cycles?
Align replacement, isolation or surrounding-architecture options with capital plans.
- Exceptions
Which residual risks need an owner, expiry date, compensating control and funded closure path?
Require clear risk acceptance and closure reporting.
Manage the transition or inherit it.
The alternative is delayed discovery, compressed replacement and inherited supplier decisions. Ownership, inventory, procurement conditions and staged testing create options before disruption becomes urgent.
Approve sponsorship, scope, funding, reporting and escalation now.
Name an executive sponsor, a risk owner and clear decision rights for the transition.
- Accountable lead
- Executive sponsor with CIO, CISO and business risk owners
- Bring back to the board
- Programme charter, scope, governance cadence and unresolved ownership gaps
- Escalation trigger
- No accountable owner, disputed scope or unmanaged cross-business dependency





