The timeline for quantum computing to break current encryption standards has accelerated significantly, with multiple laboratories demonstrating stable 10,000-qubit systems. Security experts are warning organizations about "harvest now, decrypt later" attacks, where threat actors collect encrypted data today with the expectation of decrypting it once quantum computers become capable.
Intelligence agencies worldwide are believed to be already stockpiling vast amounts of encrypted communications, according to declassified documents and expert testimony before the Senate Intelligence Committee. The volume of data being collected has increased exponentially with the proliferation of encrypted messaging and cloud services.
NIST has reiterated its urgent call for organizations to begin crypto-agility planning, emphasizing that migration to post-quantum cryptography (PQC) is not a future concern but a present necessity. The recently published FIPS 207 standard provides the cryptographic algorithms needed for the transition.
Financial institutions are leading the migration effort, with JPMorgan Chase and Goldman Sachs announcing they expect to complete PQC deployment by early 2027. However, small and medium enterprises lag significantly, with fewer than 15% having even initiated crypto-inventories. The expected cost of global PQC migration is estimated at $7 billion over the next five years.