Cybersecurity

The global race to quantum-safe cybersecurity has just changed gears. Here's why it matters

The gap between future quantum risk and today’s cybersecurity planning has narrowed considerably over the past year.

Organizations need to recognize that cybersecurity expectations are shifting towards quantum. Image: Zheng Yang/Unsplash

Daniel Akinmade Emejulu
Head, Global Public Policy & Social Impact, Quside
José Ramón Martínez Saavedra
VP Innovation, Quside
Carlos Abellan
Founder and CEO, Quside
This article is part of: Centre for Cybersecurity
  • The gap between future quantum risk and today’s cybersecurity planning has narrowed considerably over the past year.
  • Policy-makers worldwide have already begun to move on quantum-safe cybersecurity and the private sector will follow.
  • Organizations should not wait for legislation and instead look to integrating quantum readiness into cybersecurity now.

The US Treasury in August launched a Quantum-Readiness Task Force for the financial sector, summoning government, financial institutions and technology infrastructure providers together around three workstreams: post-quantum cryptography (PQC) transition, third-party/vendor readiness, and digital assets/emerging technology risk.

The launch came just months after the United States also accelerated the global race for quantum-safe cybersecurity. On June 22, US President Donald Trump signed two executive orders: one to boost advanced quantum computing, and another directing federal agencies to transition to post-quantum cryptography by 2030 to safeguard federal assets, and by 2031 for authentication. Historically, where the public sector moves first, especially in the US, private markets have followed.

The US is not acting alone. In Europe, the European Commission has already published a coordinated roadmap urging EU member states to begin transitioning to PQC by the end of 2026, with critical infrastructure expected to migrate by 2030.

Meanwhile, ANSSI, France’s national cybersecurity agency, has announced that from 2027 it will stop certifying security products that lack quantum-resistant encryption, expecting all government and critical-infrastructure purchases to be quantum-safe by 2030.

Japan is following a similar path. Through its national cryptographic standards programme, CRYPTREC, the Japanese government is incorporating PQC into national standards and laying the groundwork for migration across government and critical infrastructure.

What is 'state-of-the-art' cybersecurity in the quantum era?

An important question arises: what does “state-of-the-art” cybersecurity mean now? While EU laws like Digital Operational Resilience Act (DORA), Network and Information Security Directive 2 (NIS2) and the Cyber Resilience Act (CRA) set cybersecurity standards, none explicitly require post-quantum cryptography. However, they all demand organizations implement “state-of-the-art” measures.

Financial supervisors are clarifying what this “state-of-the-art” standard entails. On 7 July, the European Central Bank told bank CEOs that progress in quantum computing will impact cybersecurity, and post-quantum cryptography adoption must start now with strategic investment, adding that it will address the emerging risk to traditional encryption methods by letter in due course.

Two days later, Switzerland’s FINMA issued guidance requiring a migration plan, risk analysis, cryptographic inventory, protection against harvest-now-decrypt-later attacks, engagement with external providers and crypto-agility transition.

The message is clear. Preparing for the quantum era should be part of today’s cybersecurity planning, and not just a long-term ambition.

Momentum is also growing across Africa, even though most nations have not adopted dedicated post-quantum strategies. Yet across the continent, governments are rapidly expanding areas that will require quantum readiness with digital infrastructure, identity systems and fintech.

Rwanda’s Quantum Leap Africa advances quantum research and education, while the Africa Quantum Consortium's 2026 white paper, Securing Africa's Digital Backbone, discusses post-quantum migration.

Building quantum-resilient security early can prevent costly transitions and boost cyber resilience. Globally, all organizations will also need to meet international cybersecurity standards set by Europe, the US and supply chains in preferred markets.

What is the quantum threat?

Modern encryption protects everything from private messages and online banking to healthcare records, government communications and critical infrastructure – precisely because it would take today’s fastest supercomputers an unimaginably long time to break it.

However, a sufficiently powerful quantum computer could perform the same task in a dramatically fast-tracked timeframe, making many of today’s digital security systems vulnerable.

Current quantum computers are not yet a threat, but recent hardware and algorithm advances suggest the timeline may be shorter. In 2025, Google's research indicated the qubits needed to break RSA encryption could drop by 20-fold, from 20 million to under 1 million, narrowing the gap with real machines.

In March 2026, a follow-up study with Ethereum and Stanford estimated that breaking elliptic-curve cryptography in digital signatures could require fewer than 500,000 qubits – again, about a 20-fold reduction.

Whether that timeline proves accurate or not, one conclusion is becoming increasingly difficult to ignore: akin to the 2020 pandemic, we cannot afford to wait until the “Q-Day” moment arrives to prepare for it.

  • Conduct a cryptographic inventory to identify where encryption is used
  • Develop cryptographic agility to update algorithms without costly redesigns
  • Implement defence-in-depth with multiple protection layers, such as combining classical and post-quantum cryptography

The issue is not awareness but planning: a FINMA survey of 60 Swiss financial institutions found they recognize the cyber risk from quantum computers, but lack clear migration roadmaps or forward-looking plans.

Have you read?
  • Global Cybersecurity Outlook 2026

Why ‘state of the art’ already points in this direction

Innovation converges with regulation in legislation such as DORA, NIS2 and CRA, which are all designed to be technology neutral. They require organizations to adopt “state-of-the-art” cybersecurity measures, allowing flexibility as technology evolves.

Organizations cannot assume compliance just because specific technologies are not named yet, especially as the EU develops post-quantum cryptography standards, shaping the meaning of “state of the art".

This extends beyond the choice of algorithm. Secure cryptography relies on high-quality entropy, the true randomness used to generate keys. Weak randomness can weaken even the best algorithms: if an attacker narrows the key range, they may find the key without breaking mathematics.

Moving to post-quantum algorithms does not eliminate that dependency: post-quantum cryptography keys also depend on the same entropy sources. A quantum-safe algorithm with weak randomness is not truly secure.

The key is verifiable entropy: randomness that can be measured and proven continuously, not just assumed. Verification ensures the actual unpredictability of outputs, making randomness a measurable security trait. Certification bodies stress assessment and evidence; they will scrutinize the difference between claimed and actual entropy. Quantum entropy sources help close that gap, as their unpredictability comes from physical processes that can be quantified and certified. The main point is verifiability, with physics serving that end.

Why quantum readiness needs to be built into cybersecurity

The gap between future quantum risk and today’s cybersecurity planning has narrowed over the past year. Organizations do not need to predict exact arrival times of quantum computers, only recognize that cybersecurity expectations are shifting.

The global trend is clear: the US advances through federal actions, Europe via regulation and standards and Japan through national standards, while Africa can incorporate quantum resilience into new systems.

Governments often set market agendas early, influencing industry adoption. History shows public-sector priorities shape technology at scale. Once governments demand quantum-safe systems in public and critical infrastructure, industry incentives follow.

For organizations, the best approach is not waiting for legislation but integrating quantum readiness, cryptographic agility and verifiable randomness into modern cybersecurity.

Loading...
Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Related topics:
Cybersecurity
Emerging Technologies
Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

For banks, quantum computing is both a threat to security and a chance to build resilience

Roshan Shetty

September 10, 2026

Four ways organizations can collaborate on cyber resilience

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum