# What happened Agency (CISA) and the G7 Cyber Security Working Group are calling on governments and organizations to start transitioning to post-quantum cryptography (PQC). The group says quantum computing presents a real threat to public-key cryptography and could endanger the security of public and private digital infrastructure.
# Why it matters Public-key cryptography underpins online security for communications, authentication, and many critical systems. Quantum computers, if they reach sufficient capability, could break widely used algorithms. Because encrypted data can be captured now and decrypted later when quantum computers are powerful enough, organizations that handle sensitive or long-lived data face exposure unless they act.
# What the G7 recommends The working group—composed of CISA, Canada's Communications Security Establishment, France's ANSSI, Germany's BSI, Italy's national cybersecurity agency, Japan's NISC, the UK's National Cyber Security Centre and Department for Science, Innovation and Technology, and EU institutions—laid out five concrete priorities:
- Raise awareness of quantum risks across government and industry.
- Develop national strategies that support adoption and integration of PQC.
- Advance research and development for quantum-safe technologies.
- Foster public-private partnerships to share resources and experience.
- Integrate PQC into cybersecurity requirements and procurement processes.
# Immediate practical steps for organizations Start with planning and discovery rather than immediate wholesale replacement. Practical initial steps include:
- Inventory cryptographic assets and identify where public-key algorithms protect sensitive or long-retention data.
- Prioritize systems for transition by sensitivity, lifetime of data, and difficulty of retrofit.
- Engage procurement and legal teams to include PQC requirements in contracts and acquisitions.
- Build relationships with vendors and peers through public-private partnerships to share migration experience and tools.
- Monitor R&D and standards efforts to choose vetted PQC algorithms and implementation guidance.
# What to watch next
# Bottom line The G7 call to action reframes quantum risk as a present concern that requires planning now. Organizations that handle confidential or long-lived data should inventory cryptographic exposure, prioritize systems for migration, and align procurement and vendor discussions around PQC readiness.