What Boards Need to Understand About Post-Quantum Cryptography
Post-quantum cryptography, or PQC, refers to the next generation of encryption algorithms designed to remain secure even after quantum computers capable of breaking today's encryption exist. The US National Institute of Standards and Technology published three new cryptographic standards in August 2024: FIPS 203, 204, and 205. These are not theoretical proposals. They are the migration targets. Regulatory frameworks in the US, UK, and EU are all pointing to them. Organisations that have not begun planning since August 2024 are already behind the regulatory baseline.
The term Q-Day refers to the point at which a Cryptographically Relevant Quantum Computer, a CRQC, becomes capable of breaking the public-key cryptography that secures most digital communications today. The Global Risk Institute surveyed 37 quantum computing and security experts in 2024 and estimated a 14-34% probability that a CRQC capable of breaking RSA-2048 will exist by 2033-2035. That probability is not zero, and it is not 100%. For a board overseeing an organisation that will take two to four years to complete a migration programme, a 14-34% chance within a 10-year window is a material risk requiring a decision, not a deferral.
The third element that boards need to understand is Harvest Now, Decrypt Later, or HNDL. This describes the adversary strategy of recording encrypted communications and stored data today, with the intention of decrypting it once a CRQC exists. The data collection is happening now. For organisations holding data with a sensitivity horizon extending past 2033, financial records, personal data with long retention periods, health records, legal communications, and intellectual property, HNDL is a present operational risk. Q-Day does not need to arrive for the breach to occur. The exfiltration is occurring now; the exploitation is deferred.
Three obligations follow from this picture. First, this is a compliance matter: NIST published standards in August 2024 and the deprecation clock is running. Second, migration takes longer than most organisations expect, at minimum 18 to 36 months from programme start to completion for a large organisation, which means decisions made in 2027 produce outcomes in 2030-2031 at the earliest. Third, the board has an oversight role: if the organisation's CISO cannot answer the five questions at the end of this article, that is information the board needs.
What PQC Is and What It Is Not
Post-quantum cryptography is a software migration, not a hardware procurement. The new algorithms standardised by NIST run on today's classical computers. An organisation does not need quantum hardware to implement them. This distinction matters for boards because it removes the most common reason for deferral: "we'll wait until the technology is ready." The technology is ready. NIST published the standards in August 2024. What remains is the migration programme, and migration programmes take time.
PQC is also distinct from quantum cryptography. Quantum cryptography, of which Quantum Key Distribution is the main example, uses the properties of quantum particles to establish encryption keys. It requires specialised optical hardware and infrastructure. PQC requires neither. Confusing the two leads boards to assume the solution is expensive and infrastructure-intensive when it is not. The migration from RSA and elliptic curve cryptography to ML-KEM (FIPS 203) for key exchange and ML-DSA (FIPS 204) for digital signatures is principally a programme management and engineering challenge, not a capital procurement.
NIST's three August 2024 standards serve distinct functions. FIPS 203, the Module-Lattice-based Key Encapsulation Mechanism, replaces RSA and elliptic curve Diffie-Hellman in establishing shared secrets for encrypted communications. FIPS 204, the Module-Lattice-based Digital Signature Algorithm, replaces RSA and ECDSA for signing software, certificates, and authenticated communications. FIPS 205, the Stateless Hash-based Digital Signature standard, provides an alternative signing scheme with different mathematical foundations. Together they cover the two primary functions of public-key cryptography: key exchange and digital signatures.
Q-Day: The Right Framing for the Boardroom
Quantum computing timelines are genuinely uncertain. Gidney and Ekerå (2021), arXiv:1905.09749, estimated that breaking RSA-2048 with a CRQC would require approximately 20 million physical qubits with optimistic assumptions about qubit error rates. Leading quantum processors in 2026 operate in the thousands of physical qubits. The gap between current capability and the requirements for a CRQC is measurable and significant.
The GRI 2024 probability range of 14-34% by 2033-2035 reflects that gap: it is a material probability, not a certainty, and not an imminence claim. The framing that matters for board planning is this: a 14-34% probability within a window that coincides with your migration programme timeline requires action now, not action when the probability increases. Boards that wait for higher certainty before authorising migration planning are not being prudent. They are accepting that they may not finish before the event they are planning to avoid.
The phrase "quantum computers are not powerful enough yet" is accurate today. It becomes the wrong argument for the wrong timeline if treated as a reason to defer planning. Planning must complete before Q-Day. Migration programmes typically take 18-36 months, a QSECDEF estimate based on industry programme experience, not a figure stated by NIST or NCSC. Boards should understand this estimate as a programme delivery benchmark, not a regulatory commitment.
The Regulatory Starting Gun: NIST August 2024 and the National Frameworks
NIST's August 2024 publication of FIPS 203, 204, and 205 is the regulatory starting gun. The US National Security Memorandum NSM-10, signed 4 May 2022, directed US federal agencies to prioritise migration to quantum-resistant cryptography. NIST IR 8547, an Initial Public Draft published November 2024, sets the deprecation timeline for classical algorithms: when RSA, ECDSA, ECDH, DH, and DSA transition from restricted legacy use to outright prohibition.
In the UK, the NCSC published its PQC migration timeline with three milestones: a migration plan in place by 2028, highest-priority systems migrated by 2031, and all systems migrated by 2035. For organisations operating or supplying to critical national infrastructure, the 2031 deadline applies to the majority of their systems, not the 2035 backstop.
EU NIS 2 Article 21(2)(h) requires use of cryptography and encryption as a cybersecurity risk management measure for covered entities. US defence contractors and organisations supplying to US federal agencies have additional obligations derived from NSM-10 and the CNSA 2.0 framework. The regulatory environment across major jurisdictions is converging on the same standards and timelines.
The practical board implication is straightforward: the question is no longer whether to migrate but how to sequence it and ensure the programme is resourced to meet the applicable deadlines.
HNDL: Why the Risk Is Present, Not Future
Most board-level risk discussions about quantum computing frame the threat as a future event: when quantum computers become powerful enough, they will break encryption. That framing is partially correct and importantly incomplete. The decryption capability is a future event. The data collection enabling that decryption is happening now.
For organisations whose data holds sensitivity for more than five to ten years, the implication is direct. An adversary who records an encrypted transmission today, one carrying financial settlement data, genomic records, legal communications, or proprietary research, and stores that ciphertext until a CRQC exists, can then decrypt it retrospectively. The data breach occurred at the point of capture. The attacker simply cannot read it yet.
The HNDL risk is not evenly distributed across an organisation's data estate. Data with short sensitivity horizons, marketing campaign results, quarterly sales figures, most operational logs, does not carry meaningful HNDL exposure. Data that must remain confidential for a decade or more is the priority tier. Boards should ensure their CISO has classified the organisation's data estate against HNDL exposure criteria and that the highest-exposure data is explicitly included in the migration programme's priority tier.
QSECDEF's Q-Day timeline risk calculator helps organisations assess which data categories fall within the HNDL exposure window based on their data sensitivity horizon and the current CRQC probability estimates. The data-at-risk guide provides sector-specific classification guidance.
Three Things Boards Need to Own
The first is compliance. The migration is not optional for organisations operating under NCSC, NIST, NIS 2, or CNSA 2.0 frameworks. The NIST IR 8547 transition timeline sets out exactly when classical algorithms become deprecated and then disallowed. Non-compliance is not a future risk contingent on Q-Day arriving; it is a present obligation with current regulatory consequence as deprecation timelines take effect.
The second is timeline. A migration programme authorised in late 2026 is unlikely to complete before 2029 at the earliest for a large organisation. That puts the completion date uncomfortably close to the NCSC's 2031 milestone for high-priority systems. Boards authorising the programme in 2027 or 2028 are authorising a programme that may not complete in time. The window for comfortable completion is already narrowing.
The third is HNDL data classification. The migration programme's priority tier should be driven by which data has the longest sensitivity horizon, not by which systems are easiest to migrate. A board that approves a migration plan without asking which data is classified as HNDL-priority has delegated a risk classification decision that carries board-level liability implications.
Five Questions for Your CISO
Boards exercising effective oversight of quantum security risk should be able to ask these five questions and receive substantive answers.
First: have we completed a cryptographic inventory? If not, when will we? Without the inventory, there is no migration programme, because the scope of what needs migrating is unknown.
Second: which of our systems are classified as highest-priority under the NCSC's 2031 deadline criteria? The answer should name specific systems, not describe categories in general terms.
Third: what data do we hold that an adversary would want to decrypt post-Q-Day? Has it been classified for HNDL risk with a sensitivity horizon assessment?
Fourth: what is our current migration plan, and what milestone have we reached? A complete answer includes a programme timeline, resource allocation, and a named programme owner.
Fifth: are our key suppliers migrating? How is supplier PQC readiness included in our third-party risk programme?
If a CISO cannot answer these questions, the board has not identified a CISO performance problem. It has identified a governance gap that exists regardless of individual performance. Closing the gap requires the programme to be authorised, resourced, and tracked at board level, not simply delegated downward.
The board quantum risk agenda guide covers how to structure board-level oversight for a PQC programme. The quantum security governance framework provides the structural model for a board-level oversight function. QSECDEF membership provides access to practitioner resources specifically designed to support the CISO-to-board communication layer, including briefing templates and methodology documentation. Details are available at the membership page.
The Closing Position
PQC migration is one of the few technology decisions where waiting for more certainty increases organisational risk rather than reducing it. The migration window is finite, the programme takes years, and the regulatory deadline is fixed. Boards that authorise the programme now have the time to complete it properly. Those that wait will be managing a programme under constraint, against a deadline that does not move because the organisation was not ready.
The cryptographic standards are published. The deprecation timelines are set. The board questions are answerable. What remains is a governance decision.