Quantum risk can feel technical and distant. But the steps that make an organisation ready are familiar ones: ownership, visibility, priorities and suppliers.
What is Q-Day?
“Q-Day” is the informal name for the day a quantum computer becomes powerful enough to break widely used public-key encryption such as RSA and elliptic curves. Nobody knows the date. What we do know is that migration takes years, the new standards are ready, and governments have set deadlines between 2030 and 2035.
Why this is a leadership issue
Post-quantum migration touches almost every system, many suppliers and several budget cycles. It needs an owner, funding and priorities, the same things any multi-year programme needs. Leaving it to individual IT teams usually means nothing happens until it is urgent.
Six steps to start now
- 1Appoint an owner. Give one senior person responsibility for quantum readiness and regular board reporting.
- 2Build an inventory. Find where your organisation uses public-key cryptography, starting with your most sensitive data and critical services.
- 3Prioritise by data lifetime. Protect first the data that must stay secret longest, and the systems that take longest to change.
- 4Engage suppliers. Ask key vendors for their post-quantum roadmaps and make support for NIST standards part of new contracts.
- 5Build crypto-agility. Make sure new systems can change algorithms through configuration, not rewrites.
- 6Pilot and learn. Turn on hybrid post-quantum key exchange where products already support it, and measure the impact.
Questions to ask your team
- ◆Do we know where RSA and elliptic-curve cryptography are used in our organisation?
- ◆Which of our data must stay confidential beyond 2030?
- ◆Which of our critical vendors have a post-quantum roadmap?
- ◆What is our target date for completing migration, and does it meet regulators’ timelines?
Common mistakes to avoid
- ◆Waiting for a date: there may be no public warning before Q-Day.
- ◆Treating it as a one-off patch: it is a multi-year change programme.
- ◆Buying “quantum-proof” products without checking: make sure they use NIST-standard algorithms.
task_altKey takeaways
- check_circleQ-Day’s date is unknown, but government deadlines fall between 2030 and 2035.
- check_circleStart with an owner, an inventory and priorities based on data lifetime.
- check_circleSuppliers and crypto-agility are as important as the algorithms themselves.