NordVPN Promotion

Home / News

G7 Cyber Agencies Urge Immediate Post-Quantum Migration Planning

Cybersecurity agencies from the Group of Seven are urging governments and businesses to begin preparing now for the migration away from public-key cryptography vulnerable to future quantum computers, warning that the transition will require years of coordinated work across digital infrastructure.

The G7 Cybersecurity Working Group’s September 3 call to action says organizations should treat the quantum threat as a near-term security problem rather than wait for a cryptographically relevant quantum computer to emerge. The group includes national cybersecurity authorities from the G7 countries, with participation from the European Commission and support from ENISA.

The immediate risk includes data being collected today for decryption later. The agencies highlight “harvest now, decrypt later” attacks, in which adversaries retain encrypted information until sufficiently capable quantum computers become available. They also warn that quantum attacks on public-key cryptography could undermine authentication, allowing attackers to impersonate trusted parties or forge digitally signed information.

The group recommends a phased, risk-based migration. Organizations should inventory where cryptography is used, identify critical systems and long-lived sensitive data, map dependencies, establish governance and budgets, and build cryptographic agility so algorithms can be replaced without redesigning entire systems. The September appeal builds on more detailed G7 migration guidance published earlier this year.

For Internet infrastructure, the problem extends well beyond encrypted web traffic. Public-key cryptography underpins authentication and signatures across TLS and certificate infrastructures as well as DNSSEC and the Resource Public Key Infrastructure used in routing security. The IETF’s RFC 9958, published in June, says protocols and infrastructure using today’s public-key algorithms will need to transition to post-quantum alternatives.

That transition is already reaching Internet standards work. An active DNSSEC proposal is examining how to accommodate post-quantum signatures without imposing their substantially larger sizes throughout signed DNS zones. Separate RPKI experiments are testing post-quantum and composite signatures and measuring their effects on certificates, route-origin authorizations, repositories and distribution mechanisms. Both remain works in progress rather than deployed standards.

TLS migration has moved further ahead. In August, the IETF published RFC 10024, defining three hybrid post-quantum/traditional key-agreement mechanisms for TLS 1.3 that combine ML-KEM with conventional elliptic-curve exchanges. Work on post-quantum certificate authentication continues separately.

The G7 agencies do not specify when a quantum computer capable of defeating today’s public-key systems will arrive. Their argument is instead that uncertainty about that date does not remove the migration deadline: cryptographic inventories, standards, software upgrades and interdependent infrastructure transitions have to be completed before such a machine becomes operational.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By CircleID Reporter

CircleID’s internal staff reporting on news tips and developing stories. Do you have information the professional Internet community should be aware of? Contact us.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Brand Protection

Sponsored byCSC

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

Cybersecurity

Sponsored byVerisign

DNS Security

Sponsored byWhoisXML API

IPv4 Markets

Sponsored byIPv4.Global

Domain Names

Sponsored byVerisign

NordVPN Promotion