Shor’s algorithm: a circuit representation of why PQC exists

Start with asking the right questions

You may have read that “quantum computers will break today’s encryption“, and that it’s not a question of if quantum computers will become powerful enough to do so but when. This is the space of Post-Quantum Cryptography (PQC), also going by Quantum-Safe Security. Within PQC, you have Harvest Now, Decrypt Later – “adversaries are harvesting your encrypted data now, to decrypt later [on said quantum computer]”. If you are responsible for data or security at your organisation, a question like “how do we protect our data from quantum computers?” has probably crossed your desk already, or is crossing it right now.

But the urgency thrown around in this market does not mean every system you run needs to migrate to PQC today, or even before that quantum computer arrives. From research, our own scans and reports, and the way we have built Kaysec’s services, we sharpen that urgency onto what actually matters. On time, cost and effort, the job is to migrate only the systems and data that warrant it, in the right order. That starts with asking the right questions, set out below. It is also the first of three steps, a readiness snapshot of where your organisation stands today on cryptographic posture and agility.

1. What do you need to start protecting?

Mosca’s Theorem helps answer this by filtering out what systems and data warrant starting migration now, and those that don’t. If X + Y > Z then you should start preparation now. That’s basic maths which reads as:

X – Which data, and how long do you need it to be kept secret?

The first step in any PQC preparation is to take stock of which data you need to protect and for how long, with shelf-lives running from months to years, and what that data is worth.

Y – How long would it take to migrate the systems that protect X data to be PQC ready?

Y cannot be answered until you know X. Once you know what must stay secret and for how long, you can identify the systems protecting it and scope the migration: what will be complex and slow, and what is close to flipping a switch to turn PQC on.

Z – When will quantum computers be able to break the encryption?

This is the million dollar question that the industry does not yet have an accurate answer but the trend from many signals from the research of hardware and algorithms, to the policies being set, are all narrowing and focusing on a nearer future within several years rather than several decades away.

2. Are there compliance or regulatory mandates for your industry?

Some countries have already stipulated that some organisations, like critical infrastructure operators, military and government agencies, must have PQC migration completed by the end of the decade or soon into the next. More countries, and more industries, will be following suit.

Five Eyes nations are already setting hard migration deadlines. The US (CNSA 2.0) targets full migration by 2035. Australia’s ASD sets the most aggressive general-purpose timeline: a refined transition plan by end of 2026, and full transition by end of 2030. The UK’s NCSC targets 2035. The EU sets 2030 for high-risk systems.

New Zealand’s own NZISM Section 2.4 mandates that agencies monitor PQC developments, inventory their cryptographic systems, and develop migration plans, but yet no PQC algorithms have been approved for NZISM use, and no migration deadline has been set.

3. What is this PQC threat and how does it work?

If you already have a general idea of what PQC is, the first two questions are enough to get you under way. But others in your organisation will need to understand what does and does not need doing, when, and why.

The advent of quantum computing poses a potential threat to digital security systems in all walks of life: health records, financial transactions, banking and cryptocurrency systems, critical infrastructure controls, government secrets, private messages and communications, just to name a few.

Quantum computers are not yet able to break the cryptography that secures all these systems, but adversaries are already executing HNDL (“harvest now, decrypt later”) attacks: capturing encrypted data today with the expectation of being able to decrypt it once that day arrives. It applies to data in transit and at rest.

Shor’s algorithm enables quantum computers to efficiently factor large integers and compute discrete logarithms, breaking RSA and ECC cryptographic algorithms. These are the mathematical foundations of today’s data protection methods.

4. What’s the take away?

The takeaway is not that everything must change tomorrow. Transitioning to PQC is not instantaneous: it takes assessment, planning, system upgrades and new standards, and for some systems that is a multi-year programme. The task is to work out which data and systems actually warrant it, and in what order, then start there. That is what the three questions above are for, and where a readiness snapshot begins.

Our Value Proposition – Our Quantum-Safe Services & Solutions

Kaysec, the post-quantum security division of Spinsphere, delivers quantum-safe security solutions to organisations in New Zealand and worldwide. NIST finalised its first PQC standards in August 2024: ML-KEM (FIPS 203, formerly CRYSTALS-Kyber) for key encapsulation, ML-DSA (FIPS 204, formerly CRYSTALS-Dilithium) for digital signatures, and SLH-DSA (FIPS 205, formerly SPHINCS+) for hash-based signatures. With our expertise in these standards and understanding of regulatory frameworks and policies, we provide the following services:

  • Assessment: Comprehensive PQC readiness audits — identifying quantum-vulnerable systems, mapping cryptographic dependencies, and benchmarking against NZISM Section 2.4 and international frameworks.
  • Inventory: Catalogue sensitive datasets with long confidentiality requirements and map their cryptographic dependencies.
  • Prioritise: Rank systems for migration based on asset value, data sensitivity, operational dependencies, and data longevity.
  • Strategy: Develop a concrete migration roadmap with timelines, resource requirements, and hybrid transition strategies, all aligned to your regulatory environment, whether NZISM, CNSA 2.0, NCSC, or ASD guidance.
  • Implementation: Deployment of NIST/regulatory body approved PQC algorithms (ML-KEM, ML-DSA, SLH-DSA etc.) into your existing infrastructure with hybrid migration strategies.
  • Advisory & Support: Ongoing guidance on compliance, emerging standards (including FN-DSA / FIPS 206), and cryptographic agility best practices.

By partnering with Kaysec, you position your organisation at the forefront of cybersecurity, ready to face the challenges of the quantum future.