Quantum-safe

Quantum computers will break the public-key cryptography that protects today's business. For a GRC officer this is not a research topic. It is a risk-management measure with an EU date on it, and the first steps are well defined, affordable and useful whatever the hardware timeline turns out to be. This page gives you the case, the plan, and an honest account of where the technology really stands.

The clock is regulatory

The EU expects organisations to begin their transition to post-quantum cryptography by the end of 2026. Critical infrastructure must be fully migrated by 2030, remaining systems by 2035, and the European Commission has proposed writing the obligation directly into NIS2. If NIS2 or DORA applies to you, expect the question in your next supervisory contact.

The reason the clock starts now: encrypted data intercepted today can be stored and decrypted once quantum capability matures. Anything that must still be confidential in the 2030s is exposed already.

What it looks like as a GRC measure

In practice, quantum-safe is a control set like any other, and it fits in the management system you already run.

  1. Cryptographic inventory. Which algorithms, key lengths, certificates, protocols and libraries you depend on, in which systems, from which suppliers. This is an asset register question, and in Abacordo it lives next to the CMDB rather than in a separate spreadsheet.
  2. Risk classification. Separate long-lived sensitive data from transient traffic. Data lifetime plus migration time against the expected arrival of a cryptographically relevant quantum computer gives you a priority order.
  3. Roadmap and governance. A phased, costed plan aligned to the EU milestones and the NIST standards (ML-KEM for key establishment, ML-DSA and SLH-DSA for signatures), a named owner, budget logic and a reporting rhythm the board and the supervisor will recognise.
  4. Execution and crypto-agility. Hybrid deployments, vendor and product questions, guidelines so the next algorithm change does not need another programme, and preparation for audits.

How I help

  • Quantum Risk Quick Scan

    Three to four weeks, fixed fee. A first cryptographic inventory of your most critical systems and suppliers, a risk classification, and a short board report with a recommended sequence.

  • Migration roadmap and governance

    Six to ten weeks. Full inventory approach, prioritisation by data lifetime and quantum risk, a costed phased roadmap, and the governance pack.

  • Programme support

    Day-rate support while your teams execute, or the programme owner role on a retainer of one or two days a week, grounded in ISO 27005 risk practice and in what NIS2 supervision will actually ask.

  • Briefings and masterclass

    A 90-minute board briefing, free for a first orientation, and a one-day hands-on masterclass on the NIST standards, inventory methods and hybrid deployments.

Where the technology really stands

This section is for readers who want to know whether the advice rests on real understanding. It does.

  • Shor's algorithm factors integers and solves discrete logarithms efficiently. This is what breaks RSA and elliptic-curve cryptography. It needs a large, fault-tolerant machine with many logical qubits, built from many more physical ones. That is the timeline driving migration.

  • Grover's algorithm gives a quadratic speedup for unstructured search. In practice it halves the effective strength of symmetric keys, which is why the answer is AES-256 rather than panic.

  • Today's devices are noisy and shallow. Error mitigation cleans up results now but does not scale; error correction, encoding one logical qubit across many physical ones, is the path to running Shor at scale. Early logical-qubit demonstrations are encouraging; useful fault-tolerant machines are a multi-year effort.

  • Quantum advantage has been shown on contrived sampling tasks, not yet on a commercially relevant problem. I say so plainly, because over-promising is how quantum projects lose their budget.

Quantum communication (QKD, EuroQCI, with Belgian participation through BeQCI) complements post-quantum cryptography rather than replacing it, and for most enterprises it is a telecom-infrastructure topic today. Quantum sensing is the most mature of the three families and not where I focus.

Two clocks

The security clock is regulatory and has dates. The opportunity clock is technological and has only signals: error rates, logical qubit counts, the first use case where quantum beats classical on a problem that matters. Treat the first as a compliance programme and the second as a watching brief with an annual review. If you want an honest read on whether quantum computing could matter for your sector within five years, I offer an opportunity scan, a feasibility study on one use case, or a contained proof of value on cloud hardware. If the answer is "not yet", that is the answer you will get, with a date to look again.

How I work in it

I build and reason about circuits in Qiskit, prototype variational and search-style algorithms, and read the primary literature rather than the press releases. I am a member of Quantum Circle Belgium. MIT xPro Quantum Computing Fundamentals completed; IBM Qiskit certification in progress. The point is not to run production quantum workloads. It is to give you advice grounded in what the machines and algorithms can and cannot do.

Not sure where you stand? Try the free Key Cracker and Website Check for a first look at your exposure, or book a conversation.