AI News Feed
Market watch
Cybersecurity

Quantum readiness enters build phase as 2029 deadlines and 2030 rules converge

DigiCert's World Quantum Readiness Day highlighted a shift from post-quantum planning to execution, with 2029 and 2030 deadlines driving cryptographic inventories, PKI modernization, regulatory alignment and live hybrid-key pilots.

DigiCert CEO Amit Sinha described the work as a foundational rebuild. "It is a once in a 30-year upgrade to the core trust foundations of the internet," Sinha told theCUBE's John Furrier. He compared the migration to constructing a skyscraper: "You don't need to build a skyscraper in one shot. You don't need the full final blueprint. You need to start with the foundations, build the next floor and then stack up floors on top."

Sinha said the main obstacle is scope, with underfunded PKI teams facing what he called a Y2K-like times 10 event. "You don't need a perfect inventory, you need a good enough inventory. Identify crown jewels in your application suite that you want to attack first," he said. That inventory of machines, software and libraries becomes the basis for cryptographic posture, which DigiCert surfaces through Quantum Central, launched in July. Shrinking certificate lifetimes are pushing the same automation agenda, Sinha added, because the 47-day mandate and post-quantum migration both have 2029 deadlines. He said PKI modernization and encryption migration should be treated as one program rather than two. "Prioritize the migration to quantum safety," Sinha said. "PKI modernization is long overdue. And the deadline to do that is 2029. If you don't start today, you're already out of time."

Regulatory deadlines are also converging, but not on a single scope. Naomi Wynn, CEO of National Energy Public Key Infrastructure, and Jostein Stokkan, product manager of service offerings at Atea Norge AS, told DigiCert's Dean Coclin that Australia is pursuing complete migration, while Scandinavian and Baltic countries generally follow European Union timelines for roadmaps and high-risk systems. In the United States, Executive Order 14412 requires federal agencies to name post-quantum cryptography migration leads and to transition high-value assets and high-impact systems to PQC for key establishment by Dec. 31, 2030. Wynn said the Australian Signals Directorate and the Australian Cyber Security Centre have requested full PQC compliance and complete migration by 2030.

Different national standards add complexity for multinational organizations, Stokkan said. "I think [different standards] will affect [PQC]. But if we can help organizations to become more crypto agile, to be able to adapt to different types of encryption as they become important or just change, I think everything will be smoother and easier for all parties," he said. Wynn said implementation questions remain unresolved. "There is no one-size-fits-all; there is no template," she said, adding that she hoped for improved guidance in the next year on expectations, what is good enough and what will meet requirements.

At LGT Financial Services AG, quantum safety entered formal risk discussions in 2022, when the topic was raised at the firm's annual risk and cyber risk management meeting. The company later created a Quantum Safe Competence Center to connect security operations, architecture, PKI, application owners, vendors and risk stakeholders, according to Christian Pfister, team leader of IT security operations and lead for the center. "Quantum safety is a resilience and risk management issue," Pfister told DigiCert's Shane Kelly. He said leadership's key question was which information must remain confidential long enough that it may be exposed to a future cryptographic break, and that waiting for a cryptographically relevant quantum computer would leave too little time to identify dependencies, upgrade products, coordinate suppliers and migrate safely.

LGT's competence center provides security direction, while individual teams and service owners remain responsible for implementation. Pfister said that approach allowed targeted work to begin while the company continued developing its cryptographic inventory. "If you try to inventory, replace and validate every cryptographic use case at once, it makes the program unmanageable, and you can't measure the outcome," he said. "The [post-quantum cryptography] migration is not one project and one algorithm change; it's a series of migration waves." Supplier engagement became another workstream involving vendor management and procurement. LGT began asking vendors about product roadmaps, supported algorithms, timelines and compatibility constraints in 2023 or 2024, Pfister said, and it also coordinated with experts, including connections to DigiCert.

On the technical side, LGT modernized its Transport Layer Security baseline and tested hybrid key exchange in controlled environments, combining X25519 with the NIST-standardized Module-Lattice-Based Key-Encapsulation Mechanism. Pfister said the pilot is now live, with the company's online banking system using hybrid key exchange and no customer disruption. "This principle we are going to follow in all areas," he said. Testing exposed interoperability problems across the full connection path, including load balancers and content delivery networks; some connections failed or returned to the previous configuration. Pfister said most issues look familiar to anyone who has delivered major security changes, including legacy hardware, unsupported firmware and unmanaged libraries. The pilot exposes technical debt that already exists, he said, and that is not a reason to wait but precisely why starting early matters.