Skip to main content


      Quantum computing could unlock significant advances across science, technology and industry. At the same time, sufficiently capable quantum computers would undermine many of the public-key cryptographic methods that organizations rely on to secure communications, authenticate users and systems, and verify the authenticity of software.

      The challenge for organizations is no longer only when cryptographically relevant quantum computers will arrive. It is whether the systems, data and technology investments they rely on today can remain secure throughout a multi-year transition.

      That transition has already begun. Post-quantum standards are available, the EU has established milestones for a coordinated migration, and Traficom guidance emphasizes early, risk-based preparation. For many organizations, the immediate task is not to replace every cryptographic mechanism. It is to identify where vulnerable cryptography is used, understand which critical use cases depend on it, determine what must be protected first and avoid creating new cryptographic legacy.

      Cryptography is a hidden business dependency

      Public-key cryptography is an invisible foundation of the digital economy. Methods such as RSA and elliptic-curve cryptography support secure web traffic, virtual private networks, digital certificates, user and machine authentication, email security, electronic signatures and software updates.

      If these methods become vulnerable, the impact will extend beyond data confidentiality. Organizations could face risks to digital identities, the authenticity of digitally signed information and the mechanisms used to establish trust between systems. One significant concern is the integrity of software and firmware updates. If an attacker can forge a trusted publisher’s digital signature, the update process itself may become an avenue for compromise.

      The risk also begins before sufficiently capable quantum computers become available. Under the “harvest now, decrypt later” scenario, threat actors may collect encrypted information today with the intention of decrypting it when the necessary technology becomes available.

      This is especially relevant to organizations holding information that must remain confidential for many years, including intellectual property, healthcare information, financial records, sensitive public-sector information and critical-infrastructure data.

      For example, if information must remain confidential for ten years and migrating the systems that protect it will take five years, the organization may need to act well before the expected arrival of a quantum computer capable of breaking current cryptography.


      Why the migration is more than an algorithm upgrade

      Replacing vulnerable cryptography will not be comparable to installing a routine software update. Cryptographic methods are embedded across applications, infrastructure, identity platforms, network devices, cloud services, operational technology and third-party products. Migration must therefore address several interconnected challenges.


      Many organizations lack a complete picture of where cryptography is used. Algorithms, certificates, keys and libraries may be embedded in applications, distributed across teams or hidden within external services.

      A cryptographic inventory, which may include Cryptographic Bills of Materials (CBOMs), can help identify these dependencies. However, discovery alone is not enough. Cryptographic dependencies must be connected to the information they protect, the business services they support, their owners and the required protection period. This context determines what should be migrated first.

      Not every system will be capable of supporting PQC through a straightforward software update. Readiness depends on product support across hardware, software, cryptographic libraries and protocols.

      Some systems may be upgradeable, while others may require component replacement, architectural changes, compensating controls, risk acceptance or retirement. These constraints can be particularly significant in operational technology, IoT and other environments with limited resources or long replacement cycles. PQC may also introduce larger keys, signatures and messages, making performance and compatibility testing important for many use cases.

      PQC migration covers both internally developed systems and commercial off-the-shelf products. Organizations may depend on cloud providers, software vendors, managed services and equipment manufacturers to introduce support for new algorithms and protocols. Vendor roadmaps, contractual commitments and product lifecycles should therefore be considered from the outset.


      Crypto-agility as the long-term capability

      Addressing these challenges requires more than selecting new algorithms. Organizations need the ability to understand, govern and change cryptography as technologies, standards and risks evolve.

      This capability is commonly described as crypto-agility: the organizational and technical ability to discover, govern and replace cryptographic algorithms, keys, certificates, libraries and protocols without unacceptable disruption to business operations.

      In practice, crypto-agility has four dimensions:

      Visibility

      Do we know where quantum-vulnerable cryptography is used and what it protects?

      Governance

      Are ownership, approved standards and migration decisions clearly defined?

      Technical flexibility

      Can cryptographic components be changed without extensive application redevelopment or architectural change?

      Operational capability

      Can changes be tested, deployed, monitored and rolled back safely?


      Building these capabilities as part of the PQC migration can make future cryptographic changes faster, safer and less disruptive.

      A phased path towards post-quantum readiness

      PQC migration should be managed as a risk-based, multi-year transformation rather than a purely technical project. Priorities should reflect data longevity, business criticality, exposure, migration complexity and reliance on external providers.

      Assign accountable owners and identify where quantum-vulnerable cryptography is used, what it protects and which business services depend on it. The resulting inventory should be maintained throughout the migration and used to prioritize long-lived data and high-risk systems.

      Define migration principles, engage critical vendors and incorporate PQC readiness into procurement and architecture requirements so that new investments do not create additional cryptographic legacy. Identify systems that cannot be upgraded early enough to plan for replacement, redesign, compensating controls or risk acceptance.

      Test appropriate PQC and hybrid implementations for security, interoperability, performance and operational impact. Begin with high-risk use cases, such as long-term confidential information and software-signing mechanisms, before extending migration according to business risk and technology-renewal cycles.


      How we can help

      PQC migration requires coordination across cybersecurity, architecture, technology teams, procurement, data owners and third-party risk management. KPMG can support organizations in areas such as:

      PQC readiness assessment

      High-level assessment of exposure to quantum-vulnerable cryptography, organizational readiness and priority actions for beginning the transition.

      Cryptographic discovery and risk prioritization

      Identification of cryptographic dependencies and critical use cases, followed by prioritization based on data longevity, business impact, exposure, migration complexity and technology lifecycles.

      Migration strategy and architecture advisory

      Development of risk-based roadmaps, governance models and architecture principles for phased migration and long-term crypto-agility.

      Vendor and procurement readiness

      Assessment of critical supplier and product roadmaps and development of PQC, crypto-agility and lifecycle-support requirements for procurement and contracting.

       

      Organizations do not need to migrate every system immediately. They do need to establish ownership, understand their most important cryptographic dependencies and determine where action is required first. Organizations that begin building visibility, setting priorities and developing crypto-agility today will be better positioned to manage the transition to post-quantum cryptography in line with business risk and technology renewal cycles.

      Contact us

      Elmeri Hulkko
      Elmeri Huikko

      Cyber Advisory

      KPMG in Finland

      Related content

      Cyber Security

      Our cyber experts can help you to protect your future.
      Blue swirl