The quantum computing revolution is no longer a distant abstraction confined to physics labs — it is actively reshaping how the world thinks about cybersecurity. Right now, chip designers, server manufacturers, smartphone OEMs, and cloud hyperscalers are quietly baking quantum-resistant algorithms into the very silicon your organisation depends on. If you lead IT, security, or infrastructure, this wave of hardware change has enormous implications for your roadmap. Here's everything you need to know about why the shift is accelerating and exactly what you should be doing about it.
What Is Post-Quantum Cryptography — and Why Does It Matter?
Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to withstand attacks from both classical and quantum computers. As quantum computers become more powerful, traditional public-key cryptosystems such as RSA and ECC are at risk of being rendered obsolete.
The underlying mathematics of today's encryption — the foundations of everything from your VPN to your banking app — rely on problems that are hard for classical computers to solve.
Shor's algorithm, running on a fault-tolerant quantum computer with thousands of logical qubits, could factor large numbers and compute discrete logarithms exponentially faster than classical computers, undermining the mathematical hardness assumptions that protect these cryptographic systems.
For business leaders navigating the noise, the signal should be clear: post-quantum cryptography is a manageable evolution, not a crisis.
But manageable doesn't mean optional — and it certainly doesn't mean there's time to wait.
The Ticking Clock: Q-Day Is Closer Than You Think
One of the most common miscalculations IT leaders make is assuming the quantum threat is decades away. The evidence increasingly contradicts that view.
Google has warned that "Q-Day" — the point where a quantum computer is powerful enough to crack current encryption techniques — could come as soon as 2029. The new timeline comes in light of progress in quantum computing hardware development, quantum error correction, and quantum factoring resource estimates.
The Global Risk Institute's Quantum Threat Timeline Report suggested a full-scale, cryptographically relevant quantum computer was "quite possible" within the next 10 years, and "likely" in the next 15.
The report noted it is particularly hard to evaluate quantum risk to cybersecurity because "under the radar" research efforts — by secret state-backed labs, companies operating in stealth or malicious private actors — could mean that advances in quantum computing are hidden from view. "Since covert successes would remain invisible for some time, it is safer to assume that the true threat could be closer than what can be inferred from open publications alone."
Even more pressing than Q-Day itself is the "harvest now, decrypt later" (HNDL) threat.
The most immediate driver to address quantum security today is this threat model: adversaries can capture encrypted data today and store it until a sufficiently capable quantum computer enables decryption in the future. As a result, organisations may already be exposed where sensitive information has long-term value, including intellectual property, financial records, government communications, and healthcare data — even in the absence of any visible breach.
The Standards Are Set: What NIST Has Established
Regulators and standards bodies have responded decisively.
In August 2024, NIST finalised three post-quantum cryptography standards: FIPS 203 (ML-KEM for key encapsulation), FIPS 204 (ML-DSA for digital signatures), and FIPS 205 (SLH-DSA for hash-based signatures).
Following NIST's finalisation of PQC standards in August 2024 and the selection of HQC as an additional algorithm in March 2025, organisations across every sector are now working to migrate their cryptographic infrastructure.
Organisations should not wait for additional new signatures to be finished; the advice is to start deploying the already standardised algorithms now, and swap in any new ones later only if needed.
Governments are acting in lockstep with these standards.
In response to the June 6, 2025 Executive Order 14306, "Sustaining Select Efforts to Strengthen the Nation's Cybersecurity," CISA is providing and regularly updating lists to aid in post-quantum cryptography adoption.
Because PQC-capable products are widely available in the listed categories, organisations should acquire only PQC-capable products when planning acquisitions.
Globally,
the EU framework from the NIS Cooperation Group sets out three key milestones: 31 December 2026 for initial national transition roadmaps and identification steps; 31 December 2030 for high-risk use cases and pilots with PQC-by-default; and 31 December 2035 for full transition.
Why Hardware Makers Are Moving Right Now
The silicon industry is not waiting for enterprises to catch up. Chipmakers and device manufacturers are treating PQC as an immediate engineering priority.
Chip makers are baking post-quantum cryptography acceleration into hardware as the threat of quantum systems breaking current encryption rises.
Intel is among the most vocal leaders on this front.
Intel has started providing "PQC capable support" in Xeon 6 server hardware
,
and expects a multi-year journey to transition all of its chips to be PQC-compliant, with the new algorithms coexisting with other encryption such as AES to handle both quantum and standard web traffic.
On the mobile and consumer device side, movement is equally significant.
STMicroelectronics has introduced the ST54M chip, which combines a PQC hardware accelerator with NFC, an embedded secure element, and embedded SIM capabilities. The company stated that this integration provides device makers with a secure path to prepare next-generation mobile experiences. The chip supports PQC algorithms including ML-KEM and ML-DSA, and its hardware engine is designed to address emerging PQC requirements while helping protect against side-channel and fault-injection attacks.
Samsung also displayed its S3SSE2A security chip at CES 2026.
Google's upcoming Android 17 operating system will be equipped with PQC digital signature protection using ML-DSA in alignment with NIST.
Apple has also moved publicly on this front:
with its latest release of corecrypto source code in May 2026, Apple shared meaningful advances in applied formal verification with the global cryptographic community, released openly to encourage wider adoption and support critical review.
The broader market reflects this urgency.
The global post-quantum-secure hardware market is estimated at USD 0.7 billion in 2025 and projected to reach USD 20.0 billion by 2035, registering a CAGR of 39.8%.
The Enterprise Reality: Most Organisations Are Dangerously Behind
Despite the hardware momentum, enterprise adoption of PQC remains alarmingly slow.
The Ponemon Institute's 2026 Global State of Post-Quantum and Cryptographic Security Trends study, based on more than 4,000 IT and security practitioners worldwide, found that 68% of organisations describe managing their cryptographic assets as extremely or very difficult, and only 38% report they are actively transitioning to post-quantum cryptography — a figure that declined year over year.
The root challenge is operational, not attitudinal.
Cryptographic algorithms are not cleanly isolated components in modern enterprise infrastructure; they are embedded throughout applications, middleware, network devices, cloud services, hardware security modules, certificate authorities, identity providers, and endpoint agents.
Google announced in March 2026 a 2029 deadline for completing its post-quantum cryptography migration, citing faster-than-expected progress in quantum hardware development, error correction, and factoring resource estimates as the drivers for accelerating.
Cloudflare followed within weeks, announcing it is matching Google's 2029 target for full post-quantum security — including post-quantum authentication, which is significantly harder to migrate than encryption.
The message from industry leaders is clear: if the largest technology companies are treating 2029 as a hard deadline, your organisation needs to treat that as a planning constraint, not a distant concern.
Practical Tips: What IT Leaders Should Do Right Now
You don't need to overhaul everything overnight. What you do need is a structured, prioritised approach that starts today.
1. Conduct a Cryptographic Inventory
CISOs and risk leaders should initiate a cryptographic inventory programme in 2026 if one is not already underway. No meaningful migration planning is possible without knowing what needs to be migrated. This inventory must span the entire enterprise ecosystem including cloud services, supply chain dependencies, and hardware-constrained systems.
2. Prioritise Long-Lived Data First
Prioritise systems with long-lived sensitive data and long replacement cycles.
If your data needs to remain confidential for more than five years, it is already at risk from HNDL attacks today.
3. Build in Crypto-Agility
Security architects should adopt crypto-agility as a mandatory architectural standard for all new systems and modernisation projects beginning immediately. The cost of building in algorithm agility during initial development is far lower than retrofitting it during migration.
4. Only Buy PQC-Ready Hardware Going Forward
Because PQC-capable products are widely available, organisations should acquire only PQC-capable products when planning acquisitions and procuring products in applicable categories.
Ask every hardware vendor — from server suppliers to networking equipment providers — for their PQC roadmap before signing any new contracts.
5. Demand Vendor Transparency
Ask vendors for standards support, validation status, hybrid transition options, upgrade paths, and rollback capabilities.
Vendors who cannot answer these questions clearly should be treated as a risk factor.
6. Run Hybrid Pilots Before Full Migration
Practice deploying a hybrid configuration, measuring impact, rotating keys and certificates, handling failure scenarios, and rolling back safely. Capture results in reusable patterns and runbooks that can be repeated across your estate.
7. Align With Regulatory Timelines — But Don't Stop There
Regulatory deadlines form the bottom line. They are the bare minimum expectations, not the goal post.
Microsoft has also said that by 2033 it aims to make its products post-quantum safe
— use these corporate and regulatory signals to build your own board-level case for urgency.
Conclusion: The Window for Comfortable Migration Is Closing
The hardware industry has made its decision. Intel, Apple, Samsung, STMicroelectronics, Google, and Cloudflare are not hedging — they are building quantum-resistant security into their products and platforms right now. The cryptographic standards are finalised. The government mandates are in motion. The only variable left is how quickly your organisation decides to act.
Quantum computing will reshape encryption, but not overnight, and a disciplined, phased approach lets organisations modernise cryptographic foundations without disruption while strengthening security today.
The risk isn't chaos — it's complacency. Every month you delay is another month of encrypted data sitting in an adversary's archive, waiting for a quantum computer to unlock it.
Ready to take the first step? Start with a cryptographic inventory this quarter, identify your highest-risk data assets, and put PQC-readiness on your next board agenda. The organisations that begin structured migration planning today will be the ones that face Q-Day with confidence — not crisis.


