G7 cybersecurity authorities are urging organizations to treat the threat posed by quantum computing to current encryption methods as an immediate priority. The warning, issued by the G7 Cybersecurity Working Group, emphasizes that migration away from vulnerable public-key cryptography will require years of preparation and should not be delayed until quantum computers capable of breaking encryption become operational. The group includes national cybersecurity agencies from G7 nations, the European Commission, and ENISA, reflecting a coordinated international effort to address the issue before it materializes into a crisis.
The quantum threat to digital infrastructure
The agencies highlight two primary risks: "harvest now, decrypt later" attacks, where adversaries collect encrypted data today to decrypt it once quantum computers become powerful enough, and the potential for quantum attacks to undermine authentication systems. Public-key cryptography, which secures everything from TLS and certificate infrastructures to DNSSEC and routing security protocols like RPKI, could be rendered ineffective. This would enable attackers to impersonate trusted entities or forge digitally signed information, compromising the integrity of critical internet infrastructure.
The G7’s September call to action builds on earlier guidance released this year, which outlined a phased, risk-based approach to migration. Organizations are advised to begin by inventorying their cryptographic systems, identifying critical infrastructure and long-lived sensitive data, and mapping dependencies. Establishing governance structures, securing budgets, and ensuring cryptographic agility—so algorithms can be replaced without overhauling entire systems—are also recommended as foundational steps.
Progress in standards and protocols
Efforts to integrate post-quantum cryptography into internet standards are already underway. The IETF has published RFC 9958, which acknowledges the need to transition protocols using current public-key algorithms to post-quantum alternatives. For DNSSEC, proposals are being developed to accommodate post-quantum signatures without imposing their larger sizes across entire signed DNS zones. Similarly, RPKI experiments are testing post-quantum and composite signatures to assess their impact on certificates, route-origin authorizations, and distribution mechanisms, though these remain experimental rather than deployed standards.
TLS migration has advanced further. In August, the IETF published RFC 10024, which defines three hybrid key-agreement mechanisms for TLS 1.3. These mechanisms combine post-quantum algorithms like ML-KEM with traditional elliptic-curve exchanges, providing a transitional path for securing web traffic. However, work on post-quantum certificate authentication is still ongoing, indicating that the transition will be incremental and complex.
For professionals: Organizations should begin by auditing their cryptographic dependencies, prioritizing systems that handle long-term sensitive data or critical authentication. Early adoption of hybrid cryptographic solutions, such as those outlined in RFC 10024, can provide a bridge to full post-quantum migration while maintaining compatibility with existing infrastructure.
Uncertainty and urgency
The G7 agencies do not specify a timeline for when a quantum computer capable of breaking current encryption will emerge. Instead, they argue that the uncertainty surrounding this date does not negate the urgency of migration. The transition process—spanning cryptographic inventories, standards development, software upgrades, and infrastructure coordination—must be completed before such a machine becomes operational. Delaying action risks leaving digital infrastructure exposed to future attacks, particularly as adversaries continue to collect encrypted data for decryption later.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 8 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story G7 post-quantum migration planning is not covered in recent or pipeline articles.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers G7 post-quantum migration planning.
- Writing the article — Draft created article_id=528 slug=g7-cyber-agencies-push-urgent-post-quantum-migration
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states the G7 call to action was issued in 'September' without specifying the exact date (September 3). While the source confirms the September 3 date, the draft omits it, which could be seen as a minor omission of precision.
- Style compliance: The headline ('G7 cyber agencies push urgent post-quantum migration') slightly exceeds the 90-character limit (91 characters).
- No copied phrasing: The phrase 'harvest now, decrypt later' is directly quoted from the source without blockquote formatting. While this is a technical term, it should either be paraphrased or formatted as a verbatim quote.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #74
- Linking related stories — Linked 5 relations from 460 candidates
- Publishing — Published g7-cyber-agencies-push-urgent-post-quantum-migration
- Mastodon — Posted https://mstdn.social/@hostingpaper/117236457902274789



Discussion · coming soon
Be the first to join the thread when community discussion launches.