IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
Charting a secure course to a post-quantum world

Charting a secure course to a post-quantum world

Wed, 7th Oct 2026 (Today)
Dr Susanne Kränk
DR SUSANNE KRÄNK Giesecke+Devrient

Quantum computing occupies a unique position in technology policy. It is simultaneously a promise and a threat, and both aspects are taken seriously by leading institutions. On one side sits the prospect of efficiently solving optimization problems or modelling the behaviour of complex systems that remain out of reach for classical computing. On the other sits a specific, well-understood risk: a sufficiently powerful quantum computer could break the public-key cryptography that secures our digital infrastructure today.

Traditional public-key cryptography relies on the assumption that certain mathematical problems are hard for computers to solve. RSA cryptography depends on the difficulty of factoring large numbers while elliptic-curve cryptography is based on the hardness of solving discrete logarithm problems. Shor's algorithm is expected to efficiently solve both problems once sufficiently powerful fault-tolerant quantum computers become available.

Nobody knows exactly when that will happen but many experts estimate it could occur between 2030 and 2040. Recent advances in quantum computing technology indicate that this milestone could be reached rather sooner.

Waiting for certainty is not an option for three reasons. First, organizations already face the "harvest now, decrypt later" threat. Encrypted data captured today can simply be stored until a quantum computer becomes available to break it. Anything with a long confidentiality requirement, financial records, health data, government communications, is already exposed to this risk, regardless of when the technology matures.

Secondly, products with long life cycles that are deployed today may still be in use when powerful quantum computers arrive. And finally, migrating to new cryptographic algorithms capable of withstanding quantum attacks will also take years to complete.

Institutional timelines reinforce the urgency: the European Union's roadmap calls for migration of high-risk use cases by 2030, and a recent U.S. executive order sets 2030 and 2031 deadlines for key establishment and digital signatures on high-value assets, respectively.

Path to a post-quantum security

Fortunately, the first quantum-safe algorithms are already available. After an eight-year transparent and open evaluation process, the U.S. National Institute of Standards and Technology (NIST) finalized its first three post-quantum algorithms in mid-2024: ML-KEM for key encapsulation and ML-DSA and SLH-DSA for digital signatures.

Cryptography only works when all parties use the same protocols, much like sharing a common language. If different "languages" are used, interoperability breaks down and secure communication becomes impossible. International standardization bodies – such as 3GPP and GSMA for connectivity, ICAO for international travel documents, and IETF for general internet communication – are now incorporating the new PQC algorithms into the respective protocols.

This process is more complex than it might seem: integrating PQC is not a simple plug-and-play replacement. PQC algorithms differ from traditional public-key encryption schemes in their design (e.g. KEM) and in key size and data transmission requirements. While the IETF has published first RFCs, such as RFC 10024 for TLS, the standardization of PQC protocols is still an ongoing process.

Driving standardization for secure ID in the quantum age

While work on protocol standards continues, pilot projects play a crucial role in advancing standardization and exploring the feasibility of migrating complex ecosystems. The identity ecosystem, in particular, is highly complex.

The German federal technology company Bundesdruckerei and SecurityTech company Giesecke+Devrient have established a unique technical foundation by prototyping one of the world's first implementations of a quantum-safe identity card. This initiative was carried out jointly with the German Federal Office for Information Security (BSI) and implemented on specialized chips from the semiconductor manufacturer Infineon.

PQC: No Longer Just Theory– Now in Practise

With the first internet standards published, PQC deployment is already a reality. By late 2025, Cloudflare reported that more than half of human-initiated internet traffic on their global network was already secured with post-quantum encryption.

The messenger service Signal announced a PQC upgrade of its secure messaging protocols to protect against "harvest now, decrypt later" attacks - just to mention early examples.

For most organizations the work is just beginning. Migrating cryptographic infrastructure across an organization, let alone a country, is a multi-year undertaking involving the identification of cryptographic assets, prioritization, and creating risk-based migration roadmaps.

First technical building blocks already exist. Otherwise, organizations are encouraged to conduct feasibility studies, such as the German eID demonstrator, to test and validate new approaches together with various ecosystem partners.

Addressing these challenges now makes PQC migration a manageable task, enabling organizations to embrace quantum computing as a future, prosperous technology.