“Q-Day”—the day when a quantum computer that can break conventional cryptography becomes available—is not far away. No one can say for certain when it will happen, but most experts place the timeframe within the next 5-10 years.
There are good reasons for the low end of the range. Huge investments are being made in quantum computing. Last year, quantum computing companies generated over a $1 billion dollars in revenue, and investments keep pouring in. And great progress is being made. According to IBM’s roadmap, the company is targeting 2029 when large-scale, fault-tolerant machines will be available.
These advancements (and others) are one reason for two key changes we are seeing in the industry: post-quantum cryptography (PQC) and a reduction in public-key certificate lifetimes.
PQC - New encryption algorithms for the quantum era
Today’s digital communications are secured using either RSA or Elliptic Curve Cryptography (ECC) encryption.
RSA encryption is based on factoring two very large prime numbers (each number hundreds of digits long multiplied together to produce an enormous value) using a process known as integer factorization.
ECC is more efficient than RSA in that it requires smaller bit sizes for the same level of protection. It is built on the elliptic curve discrete logarithm problem (ECDLP), which is based on determining how many times a point on a curve was added to itself, knowing only the result from which to start.
Because of their mathematical complexity, conventional computers are unable to break these algorithms. But neither RSA nor ECC can stand up to a large, error-corrected quantum computer running Shor’s algorithm.
Post-quantum cryptography is a new set of algorithms specifically designed to withstand encryption-breaking attempts by quantum machines. The National Institute of Standards and Technology (NIST) has published the following PQC standards:
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)
- FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA)
- FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA)
To prepare for the quantum era, organizations need to begin now. The United States government, in fact, just issued an Executive Order in June, directing the Department of Commerce to complete a pilot project for PQC migration by December 31, 2027, with the overall goal of transitioning high value assets for certain use cases within key agencies to PQC by as early as 2030.
Migrating from RSA and ECC to PQC is a complex, multi-year effort. Starting sooner rather than later has several advantages. First, it ensures your organization is prepared before adversaries can get their hands on quantum machines. Second, it protects you against those who are following a “harvest now, decrypt later” strategy, where data is stolen and stored with the expectation that it can be decrypted years from now when quantum machines are available.
PQC, PKI, and CLM
PQC migration is a complex endeavor. Before starting, it’s critical to understand the relationship between PQC, public-key infrastructure (PKI), and certificate lifecycle management (CLM).
- PQC is simply the mathematical algorithms used when certificates, keys, and trust chains are created.
- PKI is the framework—the certificate authorities (CAs), registration authorities (RAs), policies, protocols, etc.—that adopts PQC and uses the algorithms to create certificates, much like it uses RSA or ECC today.
- CLM is the operational layer. It provides the management functions to discover, issue, renew, rotate, and revoke certificates.
Most experts agree that all three components are needed to protect data in the quantum era: PQC provides new quantum-resistant algorithms; PKI issues certificates using the new algorithms; and CLM provides the operational capability—the visibility, policy enforcement, and automation functions that are needed to manage all certificates.
Certificate Lifecycle Management
While PQC migration will take time, other changes in effect now require every organization to take action.
The CA/Browser Forum released a phased schedule in April 2025 that reduces the maximum lifetime of public SSL/TLS certificates from the previous maximum of 398 days—the first phase of which took effect on March 15, 2026, reducing the lifetime from 398 to 200 days.
This means for any certificates issued on or after March 15 of this year, you can’t wait until next year to renew them.
The schedule changes continue. Beginning March 15, 2027, the maximum lifetime moves to 100 days. And on March 15, 2029, it drops to only 47 days, which means certificates will need to be renewed about eight times a year.
PQC migration may be a longer-term project, but certificate lifecycle management is one every organization needs to address now to avoid potential outages or embarrassing “this site is not secure” messages on their company website.
- Take inventory – make sure you know about all the certificates your organization currently uses.
- Automate the process – managing certificates using a spreadsheet will no longer be feasible as the lifetime maximum continues to drop. The best approach is to adopt a CLM solution that will enable you to automate the entire process of lifecycle management.
- Test quantum-safe algorithms – begin the process of testing PQC in your environment. Make sure your systems are compatible and work with your vendors to help you integrate quantum-safe solutions.
- Monitor continuously – set up an early warning system to make sure you stay on top of the process and avoid potential disruptions.
Moving forward
Quantum computing may not be on your radar right now. After all, not every use case is suitable for quantum machines. But from a cybersecurity perspective, every organization is vulnerable to what quantum machines will be able to do in the wrong hands.
As CISOs prepare for post-quantum cryptography (PQC) readiness, it is essential to consider hardware investments as part of a long-term infrastructure strategy. Hardware deployments often remain in service for five years or more, making it critical to select vendors that have PQC algorithms and capabilities on their product roadmaps. Doing so helps organizations safeguard their infrastructure investments, reduce future upgrade costs, and strengthen their resilience against emerging quantum computing threats.
To learn more about how ePlus can help you with your Cybersecurity journey, please visit https://www.eplus.com/what-we-do/secure-it-all or contact an ePlus Security specialist today.