started · updated
G7 urges organizations to begin post-quantum cryptography migration
The G7 Cybersecurity Working Group has urged both public and private sector organizations to begin migrating to post-quantum cryptography (PQC). This call to action addresses the “harvest now, decrypt later” threat, where adversaries collect encrypted data today to decrypt it once sufficiently powerful quantum computers are developed.
Experts emphasize that successful migration requires prioritizing a comprehensive cryptography inventory over the immediate selection of new algorithms. Understanding where cryptography is currently deployed within an organization is considered a foundational step for navigating the transition.
While NIST has finalized its first three PQC standards—ML-KEM, ML-DSA, and SLH-DSA—the migration process is expected to take years. It involves complex updates to applications, certificates, hardware, and protocols. Although some financial sector roadmaps point toward 2035 as a target, the G7 stresses that organizations protecting long-term sensitive data cannot afford to delay.