Skip to main content
KPMG Adaptability Pulse Survey

Learn how companies drive bold action at scale

Access the survey results
KPMG Adaptability Pulse Survey

Learn how companies drive bold action at scale

Access the survey results

Quantum risk isn't tomorrow's problem, it's today's cybersecurity preparation gap

Quantum cybersecurity risk is already here. Yet most CISOs haven't started post-quantum cryptography planning, creating a widening gap between today's security posture and tomorrow's resilience.

The decisions organizations make today about how they encrypt data, design systems, and manage third-party dependencies directly determine their exposure to quantum-enabled threats. Yet most security programs are not structured to act on risks that won't produce visible consequences for years. That gap between acknowledging emerging risks — such as those associated with quantum computing — and being prepared to address them is where the real danger lies.

Why post-quantum cryptography is a timing problem most security programs aren't structured to solve

Most cybersecurity risks follow a familiar pattern. A vulnerability becomes visible, attackers begin to exploit it, and organizations respond by patching, containing, or mitigating the issue. Even when that response is imperfect, the sequence is clear: visibility creates urgency, and urgency drives action.

Quantum risk does not follow that pattern. It introduces a category of exposure where the impact is delayed, but the decisions that determine that impact are being made now. Data is being generated, transmitted, and stored today under cryptographic assumptions that will not hold indefinitely. Systems are being built and integrated in ways that will be difficult to unwind later. Dependencies are forming across environments that are not yet fully visible.

That is where quantum risk is different. It is not defined by when the threat becomes operationally disruptive. It is defined by how early an organization begins to prepare for it. Many security programs are not yet aligned with this dynamic.

The quantum threat model is fundamentally different from traditional cybersecurity risk

The challenge with quantum computing is not simply that it will eventually break current encryption standards. That outcome is widely understood. The more important issue is how it changes the relationship between time and exposure. In most areas of cybersecurity exposure exists when a vulnerability can be exploited in the present. Quantum risk extends that timeline.

Data that is secure today may not remain secure in the future, even if it is never compromised in the traditional sense. This is the basis of what is often referred to as "harvest now, decrypt later" (HNDL), a strategy through which adversaries collect and retain encrypted data now, with the expectation that future quantum capabilities will allow them to decrypt it. For organizations with long-lived data (intellectual property, regulated information, sensitive communications) this threat is not theoretical.

NIST's finalized post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, and FIPS 205 SLH-DSA, all published in August 2024) have set the technical baseline for migration. The US government's CNSA 2.0 framework translates that baseline into hard deadlines: new national security system procurements must support CNSA 2.0 by January 1, 2027, network equipment must exclusively use quantum-resistant algorithms by 2030, and full NSS migration is targeted by 2035.1 The Cloud Security Alliance estimates that Q-Day — the point at which a quantum computer can break existing public-key cryptography — could arrive as early as 2030.2 With discovery and planning alone taking one to two years, the preparation window is not wide.

This tension is reflected in how organizations are responding. While 41% of organizations say they are concerned they are falling behind in preparing for quantum-driven security threats,3 only a minority have begun implementing post-quantum cryptography, and fewer than half consider themselves well prepared. This does not suggest a lack of awareness it reflects a gap between recognizing the risk and having a model capable of addressing it.

Why quantum readiness exposes a structural limitation in cybersecurity operating models

The difficulty of quantum readiness is not purely technical; there is also an operational component. Most cybersecurity programs are designed to respond to risks that are:

Visible in the present

Localized within specific systems

Resolved through precise, contained action

Quantum risk doesn’t fit that profile. It requires organizations to act in advance of visible impact, coordinate across multiple domains, and plan for changes that will unfold over several years. It is less like responding to a vulnerability and more like managing a long-horizon transformation across a distributed system.

This is where the strain appears. In many organizations, encryption decisions are embedded across:

  • Application layers
  • Infrastructure components
  • Identity and authentication systems
  • Third-party services and vendor platforms
  • Legacy hardware that may not have the memory or processing power to handle the much larger keys required by PQC algorithms
  • Operational technology and IoT environments, where patching cycles are measured in years and cryptographic modernization is especially constrained

In these instances, ownership is often fragmented, and visibility is incomplete, and dependencies are not always fully understood. As a result, quantum readiness is not a single initiative. It is a network of interdependent changes, each of which must be sequenced, prioritized, and validated over time. Security programs optimized for reactive precision are not always well equipped for this kind of coordination. The gap is not in technical capability; it is in how the work is organized and executed.

The risk of waiting is not urgency, it's loss of flexibility

Clearly, quantum risk is frequently deferred because it does not create immediate operational pressure. Without a triggering event, it is easy for other priorities to take precedence. However, delay can affect the range of available options.

When preparation begins early, organizations have flexibility. They can:

Inventory systems gradually

Align cryptographic changes with existing upgrade cycles

Coordinate across teams without forcing trade-offs

Test and validate approaches before scaling them

When preparation is delayed, that flexibility narrows. Dependencies become harder to unwind, migration timelines compress, and decisions are made under greater pressure, with less downstream visibility.

What practical quantum readiness looks like in a large enterprise environment

The starting point is not technology. It is understanding. For CISOs, the most effective way to approach quantum readiness is not as a single large initiative, but as a series of structured, coordinated steps that build over time.

1 | Conduct a quantum risk assessment and build a cryptographic inventory

CISOs need to identify where long-lived sensitive data exists, determine how it moves through the environment, and create a "cryptographic bill of materials" (CBOM).

2 | Establish ownership and build alliances

CISOs should find allies in risk, regulatory compliance, and internal audit to elevate PQC to board-level visibility.

3 | Update procurement and third-party risk management

CISOs must begin updating procurement standards to prevent the introduction of new systems incapable of transitioning to PQC.

4 | Define a phased migration strategy based on cryptographic agility

CISOs should focus on cryptographic agility — the ability to swap out algorithms without rewriting applications or rebuilding infrastructure — to make a phased PQC migration feasible at enterprise scale.

5 | Upskill teams and educate stakeholders

CISOs are encouraged to lead educational and training campaigns for stakeholders across the organization, from the board to development teams.

Why regulation is accelerating the timeline and what it means for governance

The emerging imperative around quantum risk is not isolated. It reflects a broader shift in how regulators and international bodies are formalizing security expectations.

In the US, the Quantum Computing Cybersecurity Preparedness Act mandates federal agencies to mitigate quantum threats, and CNSA 2.0's procurement gate in January 2027 acknowledges defense contractors and national security system suppliers are facing compliance pressure today. Globally, the G7 Cyber Expert Group has urged financial institutions to adopt PQC, and the European Commission has released its own PQC transition roadmap alongside legislation (NIS2 and DORA) that requires demonstrable cryptographic resilience.

As environments grow more complex, cybersecurity is less about responding to discrete events and more about managing systems over time. Where AI-driven threats have exposed how difficult it is to operate at speed, quantum risk exposes to the challenge of operating across extended timelines.

In this context, regulators are not framing quantum readiness as an optional best practice. They are framing it as a matter of defensible governance.4 Organizations that can demonstrate a cryptographic inventory, a migration roadmap, and clear ownership of quantum-related risk are not just better prepared, they are better positioned for the evolving regulatory environment.

Quantum readiness: The new differentiator for cybersecurity leadership

The significance of quantum risk extends beyond encryption. It highlights a broader evolution in what modern cybersecurity leadership requires. The role is shifting from managing immediate threats to orchestrating resilience across time, systems, and dependencies. In this model, the ability to act before a crisis becomes a significant differentiator is crucial and quantum readiness is the ultimate test case.

This reality has prompted government cybersecurity authorities to warn that PQC migration will happen on a global scale. The consensus is that it is essentially impossible to avoid, making early preparation and planning essential for a secure and orderly transition.5

This is a challenge that cannot be addressed through reactive action. It demands planning and foresight, rewarding early movement in a way few other risks do. Indeed, estimates suggest that only around 35,000 businesses are actively deploying PQC algorithms in 2026, a figure expected to grow to over 100 million by 2035.6 Organizations that move early will have the capability, visibility, and internal coordination that makes that transition orderly rather than urgent.

Proactive cybersecurity to help you guard against tomorrow’s threats today

As cyber threats grow in sophistication, CISOs must navigate an increasingly complex landscape of risks and vulnerabilities. With expanding regulatory requirements and the continuous evolution of attack methods, maintaining a robust cybersecurity posture is more critical than ever. 

At KPMG, we understand these challenges and provide targeted solutions to address them effectively. Today's CISOs need strategies that are both adaptable and multifaceted to stay ahead of ever-evolving threats. KPMG combines cutting-edge technology, actionable insights, and unparalleled expertise to help you prioritize and address your most critical cyber and tech risk challenges.

Our team leverages the latest in AI-driven analytics and industry best practices to deliver proactive, tailored solutions that fortify your security posture. Our cybersecurity and tech risk solutions are designed to enable your organization to anticipate threats, respond swiftly, and emerge stronger. From predictive threat intelligence to rapid incident response, KPMG is your partner in navigating cyber risk with confidence and agility.

 

KPMG Cyber and Tech Risk Services >

 

KPMG Cyber Managed Services >

 

Get in touch >

Advanced Threat Detection

Stay ahead of sophisticated cyber adversaries with AI and machine learning that detect and mitigate threats before they can impact your operations. Our solutions offer real-time threat intelligence and automated response mechanisms to keep your defenses strong and adaptive.

Enhanced Access Management

Effective identity and access management (IAM) is critical for controlling access to your systems and data. Automating IAM processes improves security and operational efficiency, ensuring only authorized users have access based on stringent, dynamic policies.

Regulatory Compliance

Stay compliant with evolving regulations and standards such as GDPR, CCPA, and industry-specific mandates. Our compliance services minimize regulatory risks and potential fines while streamlining audit and reporting processes.

Data Protection and Privacy

Ensure the integrity and privacy of data wherever it resides – on-premises, in the cloud, or in hybrid environments. Our strategies encompass robust encryption, DLP solutions, and strict access controls to protect against breaches and unauthorized access.

Footnotes

1 PQC Information.com, “CNSA 2.0 Compliance Deadlines by System Type, April 11, 2026.

2 Forrester, “Practical Quantum Computing By 2030 Is Likely — And So Is Q-Day,” March 11, 2026.

3 KPMG Global Tech Report 2026.

4 KPMG Cyber Considerations 2026, "Transitioning to post-quantum cryptography."

5 UK National Cyber Security Centre, "Next steps in preparing for post-quantum cryptography," 2024.

6 Juniper Research, “27% of Businesses Globally to Deploy PQC by 2035, Driven by Crypto-agility.” April 21, 2026.

Meet our team

Our KPMG Cyber and Tech Risk team offers clients unparalleled expertise and access to cutting-edge technology, ensuring robust protection against evolving cyber threats. By leveraging a unique blend of functional, industry, and technological experience, our professionals help organizations navigate the complex landscape of cybersecurity with confidence. Our specialists are skilled in areas such as AI-driven threat detection, cloud security, identity and access management, and advanced data privacy. We empower your organization to embrace technological advancements safely and confidently, transforming your cybersecurity posture from reactive to proactive.

Image of Dr. Lekshmy Sankar
Dr. Lekshmy Sankar
Head of Quantum Security, KPMG

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.
All fields with an asterisk (*) are required.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline