Post-Quantum Cryptography.
The Path to Quantum Readiness Starts Now.
Post-Quantum Cryptography
Your Path to Becoming Quantum Ready – Why it Needs to Start Now
While quantum computing promises major advances across a wide range of applications, it also presents a significant cyber security risk. A sufficiently powerful quantum computer has the potential to break many of the cryptographic algorithms currently being used to secure networks, applications, digital certificates and data.
While this technology is not yet available, the Australian Signals Directorate (ASD) is advising organisations to begin the transition to post-quantum cryptography now.
Post-Quantum Cryptography (PQC) – Why it Matters
Post-quantum cryptography uses algorithms designed to withstand attacks from both conventional and quantum computers. It will replace traditional algorithms such as RSA, DH, ECDH and ECDSA, which currently secure network devices, VPNs, digital certificates, remote access and encrypted communications. In the future, these could be compromised by a sufficiently powerful quantum computer capable of decryption in a matter of minutes or hours.
ASD-approved post-quantum algorithms include ML-KEM for establishing encryption keys and ML-DSA for digital signatures. These algorithms are intended to provide a practical pathway for protecting systems against future quantum-enabled attacks.
Australian Signals Directorate (ASD) – Recommended Timeline
A cryptographically relevant quantum computer (CRQC), when it becomes available, will threaten the security of systems that rely on traditional asymmetric cryptographic algorithms. ASD is therefore recommending that organisations cease using traditional asymmetric cryptography including RSA, DH, ECDH and ECDSA – by the end of 2030.
ASD’s PQC transition guidance sets three key milestones:
- By the end of 2026: Develop a refined PQC transition plan based on security risks, data sensitivity, technology dependencies and infrastructure lifecycles.
- By the end of 2028: Begin transitioning critical systems and sensitive data.
- By the end of 2030: Complete the transition to ASD-approved post-quantum cryptography.
For organisations required to comply with the Information Security Manual, these milestones should form part of formal compliance planning. For other organisations, particularly those operating critical infrastructure, they provide an important cyber security benchmark.
[Diagram courtesy of Australian Signals Directorate.]
The Network Infrastructure Impact
Cryptography is embedded throughout modern network infrastructure, including:
- Firewalls, routers and switches
- VPN and remote-access platforms
- Wireless and cloud networking
- Load balancers and application delivery platforms
- Identity and certificate services
- Network management systems
- Operational technology environments
Some platforms may support PQC through software or firmware updates. Others may require replacement due to processing, memory, cryptographic or vendor-support limitations.
This makes infrastructure lifecycle planning critical. Network equipment purchased today may remain in service beyond 2030. If it cannot support ASD-approved algorithms, organisations could face an expensive and unplanned replacement program.
Future network procurements should therefore confirm support for ASD-approved algorithms, including ML-KEM-1024, ML-DSA-87, SHA-384, SHA-512 and AES-256. Vendor claims of being “quantum-ready” should be validated against specific products, software versions and delivery dates.
The Importance of Acting Now
ASD highlights the risk of ‘harvest now, decrypt later’. An attacker can download a signed operating system image and extract the public keys used to verify it. While benign for now, this changes in a quantum future.
Once quantum computers can defeat today’s code‑signing cryptography, an attacker could compromise a vendor’s private signing keys and use them to insert backdoors or malware into bootloaders and operating systems that still appear fully trusted.
This is particularly relevant for government, financial, health, intellectual property and critical-infrastructure information that must remain confidential for many years.
Transitioning will also take time. Legacy systems, operational technology, vendor dependencies, interoperability and procurement cycles mean organisations cannot afford to wait until the quantum threat is fully realised.
Network Readiness Assessment & Transition Roadmap
C5 Technology is helping organisations understand their exposure by developing a practical transition roadmap aligned with ASD’s milestones. The PQC Network Readiness Assessment is tailored to the individual needs of the organisation and includes things like:
- Discovery of cryptographic use across network and security infrastructure platforms
- Review of network architecture, VPNs, certificates and secure communications
- Review of vendor PQC capabilities and published roadmaps
- Identification of equipment requiring upgrade or replacement
- Alignment of PQC requirements with planned network refresh programs
- Prioritised transition roadmap through 2026, 2028 and 2030
- Recommendations for procurement standards, testing and governance
Post-quantum cryptography is not simply a future technology issue. It is a current infrastructure, procurement and risk-management priority. Speak to your C5 representative to discuss your network readiness and transition planning roadmap.
Note: Information in this article compiled from various sources including the Australian Signals Directorate and Cisco Quantum Labs.