Enterprise risk

Quantum computing is an imminent threat to assumed data privacy and operational security.

Organisations must start planning now to assess and mitigate the risks related to post-quantum cryptography (PQC).

Australia sets the local planning baseline.

Data, standards, government, suppliers and internal migration run at different speeds. ASD recommends organisations should have a refined plan by end-2026, should have commenced transition by end-2028 and should have completed it by end-2030.

Name the sponsor. Test the 2026 plan now.

ASD recommendation

Define scope, ownership, priority data and the migration approach.

Project evidence for the board

Named sponsor, approved scope, inventory method, funding path and critical dependencies.

Data clockWhich information must remain confidential beyond the migration period?

Accountable input: Data owners and risk owners

Dates differ. The work converges.

Canada, the EU, France, the UK and the US use different dates, audiences and legal effects. Together, they reinforce inventory, prioritisation, crypto-agility, procurement and supplier engagement.

Project implication: prepare for supplier and market pressure across jurisdictions.

Show on timeline
ASD and ACSC guidance, with separate ISM controls

Australia

2026Refined transition plan
2028Critical transition commenced
2030Recommended completion
Audience
Businesses, infrastructure and government; ISM controls only where applicable
Legal effect
Broad dates are advisory recommendations. ISM outcomes depend on system scope and lawful applicability.
Australian enterprise implication
Use 2026, 2028 and 2030 as the local planning baseline, then test which controls apply.
Common workInventoryPrioritisationCrypto-agilityProcurementSupplier engagement

Standards and readiness

Standards are available. Readiness still needs proof.

Final standards support controlled discovery and testing. NIST states the new algorithms will likely not be drop-in replacements; performance, interoperability and supplier implementation still need validation.

Fund trials. Require product-specific evidence from suppliers.

Final standards, published 13 August 2024

NIST FIPS 203, 204 and 205 are final.

Use now

Select candidate functions for controlled design and testing.

Boundary

Publication does not prove product readiness and does not set an enterprise deadline.

Evidence needed before production

These are checks, not controls. Each requires organisation-specific evidence.

  • Inventory

    Know where public-key cryptography supports priority data and services.

  • Product support

    Confirm supported implementations, roadmaps and deprecation paths.

  • Interoperability

    Test clients, services, suppliers and trust chains together.

  • Performance

    Measure service, network, device and operational impact.

  • Rollback

    Prove a safe return path before production cutover.

  • Governance

    Record approval, ownership, exceptions and residual risk.

Set direction before the transition sets it for you.

The board does not need to select algorithms. It needs clear ownership, scope, supplier commitments, testing, lifecycle funding and managed exceptions.

Require a staged readiness plan with decisions, evidence and owners.

Enterprise readiness

Questions management should answer before the board sets direction.

  1. Accountability

    Who owns the enterprise transition, and which decisions need board oversight?

    Name an executive sponsor, risk owner and reporting cadence.

  2. Scope

    Which services, data, trust functions and assets are material enough to enter the first migration waves?

    Fund a risk-led cryptographic inventory and dependency map.

  3. Suppliers

    Which suppliers can provide product- and version-specific support, roadmap and deprecation commitments?

    Use procurement and renewal decisions to close the critical gaps.

  4. Testing

    Which changes require interoperability, capacity, rollback and operational testing before production?

    Run controlled trials before broad deployment or legacy retirement.

  5. Asset lifecycle

    Which assets cannot accept change through normal support and maintenance cycles?

    Align replacement, isolation or surrounding-architecture options with capital plans.

  6. Exceptions

    Which residual risks need an owner, expiry date, compensating control and funded closure path?

    Require clear risk acceptance and closure reporting.

Manage the transition or inherit it.

The alternative is delayed discovery, compressed replacement and inherited supplier decisions. Ownership, inventory, procurement conditions and staged testing create options before disruption becomes urgent.

Approve sponsorship, scope, funding, reporting and escalation now.

Decision for approval

Name an executive sponsor, a risk owner and clear decision rights for the transition.

Accountable lead
Executive sponsor with CIO, CISO and business risk owners
Bring back to the board
Programme charter, scope, governance cadence and unresolved ownership gaps
Escalation trigger
No accountable owner, disputed scope or unmanaged cross-business dependency