Key Findings
Entrust has released a detailed guide for organizations to plan and execute their migration to Post-Quantum Cryptography (PQC). The guide underscores the critical need for prompt action, citing the U.S. National Institute of Standards and Technology’s (NIST) deadlines for the deprecation of current public-key cryptographic algorithms (RSA and ECC) by 2030 and their disallowance by 2035.
Technical/Clinical Details
- NIST Timelines: NIST has provided a clear roadmap, indicating that by 2030, the use of existing public-key cryptography will be deprecated, and by 2035, it will be disallowed. These deadlines are paramount for organizations in sectors such as finance, healthcare, and government, which require long-term protection for sensitive data.
- “Harvest Now, Decrypt Later” Threat: There is a growing threat where adversaries collect (harvest) currently encrypted data, intending to decrypt it later (decrypt later) once sufficiently powerful quantum computers become available. This makes the protection of long-lived sensitive data an immediate and pressing concern.
- Cryptographic Inventory and Risk Assessment: The initial step in the migration process involves creating a comprehensive cryptographic inventory to identify all encrypted assets and dependencies within an organization. Based on this, a risk assessment should be performed to pinpoint areas most vulnerable to quantum attacks.
- Prioritizing Key Establishment Protocols: The guide recommends prioritizing the migration of key establishment protocols, especially for data requiring long-term confidentiality. This includes critical infrastructure elements like TLS/SSL certificates, VPNs, and digital signatures.
- Adopting Crypto-Agility: PQC migration is not a one-time event. The importance of embedding “crypto-agility” into organizational systems is highlighted, allowing for flexible adaptation to the future evolution of cryptographic technologies and potential new quantum-resistant algorithms.
Background & Context
The advancement of quantum computing poses a significant threat to the foundations of modern digital security, particularly public-key cryptographic systems. Governments and industry bodies worldwide are accelerating PQC standardization and migration strategy development to prepare for this “quantum threat.” Entrust’s guide provides a practical framework to help enterprises navigate this complex transition effectively.
Strategic Significance & Outlook
PQC migration will be one of the most critical IT challenges for enterprises in the coming years. Entrust advises organizations to adopt a phased approach, customizing their migration plans to their specific needs and risk profiles. This strategic preparation is expected to ensure the integrity and confidentiality of data in the quantum era, thereby maintaining business continuity and trust.
Get our weekly technology intelligence — free
Receive an infographic that lets you judge at a glance whether each field’s analysis report is worth reading.
Subscribe Free — Weekly Tech Intelligence
By subscribing, you’ll receive Troy-Technical’s weekly technology intelligence newsletter.
- Your email and selected fields are used only to deliver the newsletter.
- We never share your information with third parties.
- You can unsubscribe anytime via the link in each email.
See our Privacy Policy for details.
Takes about a minute · Unsubscribe anytime

Comments