Start with asking the right questions
You may have read that “quantum computers will break today’s encryption“, and that it’s not a question of if quantum computers will become powerful enough to do so but when. This is the space of Post-Quantum Cryptography (PQC), also going by Quantum-Safe Security. Within PQC, you have Harvest Now, Decrypt Later – “adversaries are harvesting your encrypted data now, to decrypt later [on said quantum computer]”. If you are responsible for data or security at your organisation, a question like “how do we protect our data from quantum computers?” has probably crossed your desk already, or is crossing it right now.
But the urgency thrown around in this market does not mean every system you run needs to migrate to PQC today, or even before that quantum computer arrives. From research, our own scans and reports, and the way we have built Kaysec’s services, we sharpen that urgency onto what actually matters. On time, cost and effort, the job is to migrate only the systems and data that warrant it, in the right order. That starts with asking the right questions, set out below. It is also the first of three steps, a readiness snapshot of where your organisation stands today on cryptographic posture and agility.

1. What do you need to start protecting?
Mosca’s Theorem helps answer this by filtering out what systems and data warrant starting migration now, and those that don’t. If X + Y > Z then you should start preparation now. That’s basic maths which reads as:
X – Which data, and how long do you need it to be kept secret?
The first step in any PQC preparation is to take stock of which data you need to protect and for how long, with shelf-lives running from months to years, and what that data is worth.
Y – How long would it take to migrate the systems that protect X data to be PQC ready?
Y cannot be answered until you know X. Once you know what must stay secret and for how long, you can identify the systems protecting it and scope the migration: what will be complex and slow, and what is close to flipping a switch to turn PQC on.
Z – When will quantum computers be able to break the encryption?
This is the million-dollar question. The industry has no precise answer yet, but the signals, from hardware and algorithm research to the policies being set, are all narrowing on a nearer future: several years away, not several decades.
2. Are there compliance or regulatory mandates for your industry?
Some countries have already stipulated that some organisations, like critical infrastructure operators, military and government agencies, must have PQC migration completed by the end of the decade or soon into the next. More countries, and more industries, will be following suit.
Five Eyes nations are already setting hard migration deadlines. The US (CNSA 2.0) targets full migration by 2035. Australia’s ASD sets the most aggressive general-purpose timeline: a refined transition plan by end of 2026, and full transition by end of 2030. The UK’s NCSC targets 2035. The EU sets 2030 for high-risk systems.
New Zealand’s own NZISM Section 2.4 mandates that agencies monitor PQC developments, inventory their cryptographic systems, and develop migration plans, but yet no PQC algorithms have been approved for NZISM use, and no migration deadline has been set.
3. What is this PQC threat and how does it work?
If you already have a general idea of what PQC is, the first two questions are enough to get you under way. But others in your organisation will need to understand what does and does not need doing, when, and why.
The advent of quantum computing poses a potential threat to digital security systems in all walks of life: health records, financial transactions, banking and cryptocurrency systems, critical infrastructure controls, government secrets, private messages and communications, just to name a few.
Quantum computers are not yet able to break the cryptography that secures all these systems, but adversaries are already executing HNDL (“harvest now, decrypt later”) attacks: capturing encrypted data today with the expectation of being able to decrypt it once that day arrives. It applies to data in transit and at rest.
Shor’s algorithm enables quantum computers to efficiently factor large integers and compute discrete logarithms, breaking RSA and ECC cryptographic algorithms. These are the mathematical foundations of today’s data protection methods.
4. What’s the takeaway?
The takeaway is not that everything must change tomorrow Transitioning to PQC is not instantaneous: it takes assessment, planning, system upgrades and new standards, and for some systems that is a multi-year programme. The task is to work out which data and systems actually warrant it, and in what order, then start there. That is what the three questions above are for, and where a readiness snapshot begins.
What makes working with us different
We discuss, discover and scan, we do not apply generic methods. Kaysec runs an internet-wide post-quantum readiness scanner and publishes its findings openly. Your assessment starts with a meet and greet to discuss your business, data, concerns and questions. From there we work from measured data about your own systems and suppliers, not a generic maturity questionnaire.
We are independent. Kaysec is tied to no vendor and earns nothing from the products you end up choosing, so our recommendations answer to your risk, not to a partner quota. Where we help implement, we do it vendor-neutrally.
We anchor to your country’s frameworks first, then the relevant international ones. For New Zealand that begins with NZISM. Our benchmarking is built on the New Zealand Information Security Manual and the local regulatory picture first, then mapped outward to CNSA 2.0 in the US, ASD in Australia, NCSC and the EU.
We triage, we do not stampede. Migration is a sequencing problem, not a race. We tell you what to move, what to leave, and what to watch, with reasons you can take to a board.
How we work: three steps, at your pace
You can start at step one and stop there, or at any point in the journey.
The cryptographic standards we work to
NIST finalised the first post-quantum standards in 2024: ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures, with FN-DSA (FIPS 206) and more following. We track these and the candidates behind them, so your roadmap is built on finalised standards and informed about what is coming, not on last year’s names.
Read our work first
We publish our analysis openly, including the scans behind our claims and, where the evidence points that way, the case for not acting yet. Read the reports, then judge whether our read is one you want on your side of the table. Public-facing scans are only the tip of the iceberg. The important work begins inside, with the people who know and guard your organisation’s systems and data. That is where the real steps are taken.