PQC migration isn’t a cryptography problem

作者 | Sep 21, 2026

Saying that post-quantum cryptography (PQC) migration isn’t really a cryptography problem might sound like an odd statement from someone who spends a lot of time talking to organisations about post-quantum cryptography.

But it’s a point I kept coming back to during a recent webinar led by Graham Peters from Arqit, PQC Migration: Strategies to Address the Board-Level Issue That Won’t Wait, alongside Lucy Potter from Frazer-Nash Consultancy and Daryl Flack from Avella Security.

When people hear ‘PQC migration’, they naturally focus on the cryptography element. Which algorithms will replace today’s standards? When will quantum computers arrive? How quickly do we need to migrate?

These are important questions, but in reality, they aren’t the hardest ones to answer.

The bigger challenge is for boards and senior leaders to fully understand how deeply cryptography is embedded across modern organisations. Far more than a technology upgrade, PQC migration touches systems, supply chains, governance, risk and long-term business resilience. This makes understanding both where cryptography is today and what it will take to change it crucial.

This is maybe the most important takeaway from our discussion – that if organisations treat PQC migration as a technical exercise alone, they’ll miss the scale of the challenge entirely.

When a cyber security challenge becomes a business transformation challenge

The challenge is no longer theoretical. Governments, regulators and major technology providers are establishing timelines and expectations. Organisations are increasingly being asked not whether they should prepare, but how.

Part of the urgency comes from what’s commonly known as ‘harvest now, decrypt later’ (HNDL). Sensitive data encrypted today can be captured and stored in the hope that future quantum computers will eventually be able to decrypt it. For organisations responsible for long-lived confidential information, from defence and critical infrastructure to financial and healthcare data, that’s a risk that needs to be factored into decisions being made today.

But what makes this different from previous cyber security challenges is its reach. PQC migration doesn’t sit neatly within a single team or function, demanding coordination across technology, operations, procurement, risk and leadership teams.

Procurement is a good example of why. If you haven’t stemmed the flow of classical cryptography into your ecosystem, you’re in danger of playing whack-a-mole as new systems that need migrating appear halfway through your programme. Once you’ve started moving away from older cryptography, you need to make sure you’re not continuing to buy more of it. That means working with procurement teams to favour quantum-safe or easily updatable cryptography wherever possible – and where that isn’t available, suppliers should have a clear roadmap in place that aligns with your organisation’s risk profile.

That’s why PQC migration is a business transformation challenge. Getting it right depends on policy, procurement, governance and organisational change just as much as it depends on technology, taking it all the way up to board level.

Visibility before migration

What’s interesting is that many leaders instinctively jump straight to migration. They start asking which algorithms they need, what technologies they should deploy or what their future architecture might look like.

But during the webinar, a different theme emerged: visibility. If you don’t know what you have, then you can’t risk assess against it. You can’t manage it, you can’t see it and you can’t plan for it. It’s a simple observation, but an important one.

In my experience, many organisations are looking for a migration strategy before they’ve established a clear view of their cryptographic estate. Yet understanding that landscape is often where the most valuable conversations begin. That doesn’t mean waiting until you’ve completed a full discovery of your estate before you start migrating. If you wait until that exercise is finished, you’ll never start. The important thing is knowing where your cryptographic assets are and building visibility of the systems that matter most. From there, cryptographic discovery should evolve into an ongoing monitoring and compliance activity, because your estate is constantly changing. In parallel, organisations should already be starting migration, or else they risk spending years discovering the problem without ever reducing the risk.

At CC, that’s where we’re helping organisations focus first: building visibility across complex estates, identifying cryptographic dependencies, understanding the implications of quantum risk, and developing practical migration roadmaps that align with broader business and technology objectives.

The organisations moving first

We also explored why some sectors appear to be moving faster than others. Financial services often receive attention for its early activity, but in my view, telecoms, energy and other critical infrastructure sectors are also making significant progress. What they tend to have in common is an understanding that trust, resilience and secure communications sit at the heart of their business models.

Another theme that emerged was the importance of collaboration. Whether it’s supply chains, standards bodies, government guidance or cross-functional leadership teams, no organisation can navigate this challenge in isolation. PQC migration touches procurement, governance, operations, risk, compliance and technology strategy in equal measure.

The organisations making the strongest progress are recognising this early and building the structures, governance, visibility and policies needed to support long-term change.

Watch the full discussion

When it comes to PQC, the organisations that succeed won’t necessarily be the ones with the most advanced technology but the ones that see PQC migration as a vital long-term business transformation programme that demands visibility, coordination and leadership across the organisation.

In PQC Migration: Strategies to Address the Board-Level Issue That Won’t Wait, I join Graham Peters (Arqit), Lucy Potter (Frazer-Nash Consultancy) and Daryl Flack (Avella Security) to discuss:

  • Why quantum risk has become a board-level concern
  • The implications of harvest now, decrypt later attacks
  • Why visibility is emerging as a critical first step
  • Lessons from sectors already moving ahead
  • The role of governance, regulation and organisational change

Watch the webinar to hear the full discussion and explore how CC can help your organisation understand its cryptographic landscape, build migration strategies and develop the capabilities needed to navigate PQC migration with confidence.

専門家

Bob Oates
Bob Oates
Associate Director at ケンブリッジコンサルタンツ | プロフィールを見る

Bob is the technical lead for Cambridge Consultants' PQC offerings and a specialist in the interaction between safety and security for operational technology, critical infrastructure, and IoT devices.

関連するインサイト

ディープテック

新規なテクノロジーや、そのテクノロジーを通じた長期的に持続可能な価値の創出について、ご関心をお持ちでしょうか。

当社はビジネスとテクノロジーが交差する場所での創造性に主眼を置き、お客様の事業を再定義するようなソリューションを創出します。

産業分野

お客様が目指す産業分野に関する深い見識を備え、ブレークスルーをもたらすディープテックを活用できて、価値を創出する活動で確かな実績を持つパートナーが必要です。

お客様の事業分野における当社の実績や、どのような事業上の優位性をお届けできるかについて、ご確認ください。

インサイト

ケンブリッジコンサルタンツの最新のインサイト、アイデア、視点をご確認ください。

ビジネスと社会の将来を形成するディープテックの動向を、最前線の事例を通じてお伝えします。

キャリア

ご自身の能力が評価され、真の差異を産み出せるような仕事に興味はありませんか。

これからキャリアをスタートする方でも、経験豊富な方でも、ぜひご連絡をお待ちしています。