Skip to main content
CybersecurityVulnerability Management

G7 Urges Industry to Accelerate Post-Quantum Encryption Defenses

Researchers work at a modern lab with a laptop and scientific instruments.

"The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence," the G7 cybersecurity working group wrote in a June report prepared at the G7 Summit in France.

G7 working group: accelerate migration to post‑quantum cryptography

The working group warned that organizations “can no longer afford to postpone” transitioning critical systems and data to post‑quantum cryptography (PQC). Its report framed the quantum risk not as an abstract mathematical problem but as an economic and business risk that requires coordinated action across public and private sectors. The authors urged early engagement, coordinated planning and informed decision making, saying the transition “is not a problem for individual organizations to solve in isolation.”

Specific technical and operational risks the report highlights

The report acknowledged uncertain timelines for when quantum computers capable of breaking public‑key encryption might arrive, but it identified concrete present‑day threats. It warned about the practice of harvesting sensitive encrypted data today to decrypt it later, and it flagged risks to authentication and assurance mechanisms — including the possibility that quantum capabilities could forge trusted data or steal confirmations, jeopardizing secure communications and legal contracts.

NIST, NSA, crypto‑agility and the limits of certainty

The report reiterated that the PQC algorithms slated for adoption were originally designed by independent cryptographers and vetted by the National Institute for Standards and Technology (NIST) and the National Security Agency (NSA). It also noted why multiple algorithms and the concept of “crypto‑agility” are necessary: designing protections against a capability that does not yet exist requires estimation, and those estimates can be wrong or overlook parts of the cryptographic attack surface. The working group observed that some NIST‑selected algorithms have already been broken with traditional computers or AI, reinforcing the need to support multiple approaches and the ability to switch rapidly between them.

U.S. policy moves and shifting industry timelines

The report placed those technical points alongside recent policy and industry shifts. It recorded that the Trump administration issued an executive order directing agencies to boost the domestic quantum industry and to accelerate internal timelines for migrating to PQC from 2035 to 2030. It also noted that Google and other companies “have opted to move their own migration timelines to 2029.” At the same time, the working group observed uneven progress: federal agencies and the highly regulated financial sector have proceeded on schedule in some areas, while other industries lag because owners and operators feel they have more immediate concerns than quantum computers.

Signed endorsement and collective responsibility

The G7 report was signed by seven national cyber agencies: the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.K.’s National Cyber Security Centre (NCSC), The French Cybersecurity Agency (ANSSI), Germany’s Federal Office of Information Security (BSI), Canada’s Communications Security Establishment (CSE), Japan’s National Cybersecurity Office (NCO) and Italy’s National Cybersecurity Agency (ACN). The coordinated endorsement underscores the report’s central message: transitioning to PQC is a collective task that requires public‑private coordination, prioritized inventories of critical systems, and planning to shift to vetted PQC algorithms.

What this means for federal agencies, financial firms, and other industries

  • Federal agencies: The report reinforces current U.S. policy direction to accelerate migration timelines and to treat PQC as an urgent operational priority rather than a distant research problem.
  • Financial firms: As a sector already proceeding on schedule in some areas, financial institutions face pressure to complete inventories and migration plans to meet both regulatory expectations and the collective risk profile described by the G7 working group.
  • Other industries: Owners and operators outside highly regulated sectors, which the report identifies as lagging, will need to reframe the quantum threat as a near‑term business risk and allocate resources to inventory, prioritize, and begin migrations — or risk harvested data and compromised authentication in the future.

The G7 working group leaves the practical challenge plainly stated: governments and major cyber agencies have endorsed specific PQC paths and accelerated timelines, yet the report documents uneven readiness and the real possibility that present‑day encrypted data could be exposed to future quantum decryption. The next steps are concrete — inventory critical systems, prioritize migration to vetted PQC algorithms, and build crypto‑agility — but whether organizations across sectors will marshal the resources and coordination the working group demands remains the open question.

Original story: https://cyberscoop.com/g7-quantum-computing-encryption-warning/