Instant Response
24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…
ViewDefensive Services
The data you encrypt today is not at risk only once capable quantum computers exist. It is at risk now — if somebody records the traffic and stores it until they can decrypt it. For anything that must still be confidential in ten years, the deadline has already passed.
The threat
The attack is called “harvest now, decrypt later” and needs no quantum computer, only storage. Encrypted traffic is intercepted and set aside. Decryption follows once the technology is there. Anyone who treats this as a distant concern is confusing the moment of the attack with the moment of the damage.
Whether it affects you comes down to a simple calculation: how long must your data stay confidential, and how long will it take to replace your encryption? If the two together exceed the time until a capable quantum computer, you are already late — regardless of when exactly that computer arrives.
For design data, patient records, contracts, board correspondence and anything under long statutory retention, that calculation already comes out badly today. For access to the pool car logbook it does not. Telling the two apart is the actual work.

The distinction
The term “quantum cryptography” covers two very different things, and confusing them costs money. We will tell you in the first conversation which of the two applies to you — as a rule it is the second.
Quantum key distribution distributes keys over a physical channel on which any eavesdropping is detectable. That is impressive and right for a few cases: your own fibre between two data centres, manageable distance, very high protection requirement. It needs dedicated hardware and dedicated links — it does not work across the public internet. For most organisations it is the expensive answer to a question they do not have.
Post-quantum cryptography means mathematical algorithms that run on today's hardware and, by current understanding, are not broken by quantum computers either. NIST published the first of them as standards in 2024 — ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures. They replace RSA and elliptic curves exactly where those sit today: in TLS, VPN, code signing, email.
Migration happens not by replacement but by combination: the existing algorithm and the new one run side by side, and the key is derived from both. If one breaks, the other holds. The German BSI explicitly recommends this route in its technical guideline BSI TR-02102, and it is the only one that does not require advance trust in a young algorithm.
You cannot migrate what you do not know about.
The process
Migration is not a project with an end date but a sequence. We work through it with you — starting where the damage would be greatest.
Cryptographic inventory — where in the organisation is encryption actually used? In practice at considerably more places than are documented: in applications, in libraries, in devices, in contracts with providers. Without this list, any plan is guesswork.
Assessment by lifetime — for each body of data, how long must it stay confidential? Urgency follows from that, not from the technology.
Prioritisation — what comes first? Usually the external links carrying long-lived data: site-to-site connections, backups, exchange with partners.
Migration plan — per link the algorithm, the timing, the dependency on vendors. Much of it hinges on versions that do not exist yet; that belongs in the plan, not in a footnote.
Hybrid migration — step by step, one link at a time, each with a fallback. No cut-over date on which everything changes at once.
Cryptographic agility — and finally the real point: the ability to switch faster next time. Anyone who has hard-wired their algorithms will be back at the start in ten years.
Regulation
The migration is not yet tied to a fixed date anywhere, but it stopped being voluntary some time ago. The European Commission has called on member states to produce roadmaps for the transition; the German BSI lists quantum-safe algorithms in its technical guidelines.
More relevant in practice is the route through existing obligations: NIS2 and DORA require risk management that reflects the state of the art. A documented cryptographic inventory with assessment by data lifetime is exactly that — and it is the evidence an auditor wants to see, long before any date appears anywhere.
If you want to place the result in an overall position, you will find it again in Sightadel under the data domain.
The assessment
If your longest confidentiality requirement is two years and your systems are replaced at short intervals anyway, you do not need a migration project today. It is then enough to require cryptographic agility at your next procurement — and that costs nothing but a sentence in the specification.
And if you are drawn to QKD without owning fibre between your sites: it does not add up. We would rather say so in the initial conversation than in the final invoice.
In closing
Replacing cryptography has never taken two years; it has always taken closer to ten — the retirement of SHA-1 is the most recent example. That is precisely why the work does not start when the first quantum computer announces that it has broken RSA, but now: with a list of what you actually use.
Talk to us about scope and urgency. The initial conversation costs nothing and, for roughly one organisation in three, ends with the recommendation to do nothing for now beyond taking stock.
FAQ
Nobody knows, and anyone naming a year is guessing. It also does not matter for your decision: what counts is how long your data must stay confidential and how long your migration takes. If the sum exceeds the plausible horizon, act now — regardless of the exact date.
By current understanding they are, and they went through a multi-year public selection process. That is not a guarantee — it never was for RSA either. Which is exactly why migration is hybrid: as long as both algorithms run side by side, the other one holds if one falls.
That is the normal case and the most common reason migrations stall. We put the dependency in the plan rather than skirting it: which version is needed, when it is announced, what the interim solution is. In some cases the answer is to change supplier.
For quantum-safe algorithms, as a rule no — they run on existing systems. Only QKD needs dedicated devices and dedicated links, and that applies to very few organisations. Where accelerator cards are involved, we check their support as part of the work.
Yes, and that is the usual route. Most begin with the external connections carrying long-lived data. The inventory should be complete, though — otherwise you are planning around the places you do not know about.
Defensive Services
24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…
ViewSignatures catch what is known. NeoI catches what deviates from your normal state — including attackers who use nothing…
ViewFirewall, segmentation and intrusion detection as one architecture — planned, implemented, operated. With Valar as a ha…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.