Quantum Computing’s Uncertain Timetable

Published on October 1, 2026

The deadline for quantum security isn’t the arrival of the quantum computer, says Tim Hudson, President, OpenSSL Corporation.

Ask when organisations should prepare for post-quantum cryptography, and the temptation is to respond with another question: when will a quantum computer become powerful enough to break the cryptography we rely on today?

I think that overlooks the point.

Nobody can offer businesses a dependable date for the arrival of a cryptographically relevant quantum computer. We do know, however, that replacing cryptography embedded throughout modern technology takes time.

That makes a different question more useful: if your cryptography needed to change, how long would it take?

For many organisations, the answer makes uncomfortable reading. Some may not yet have enough information to answer at all.

Cryptography is everywhere. It safeguards connections between systems, protects data and authenticates users. It is built into applications, infrastructure, devices and software provided by other organisations. Much of it operates so reliably that organisations seldom have to think about it.

Until something needs to change.

The challenge is that a decision to migrate does not make every system ready to migrate. Before organisations can plan a transition, they need to understand what they are changing, who controls it and what else depends on it. None of that requires a prediction about when a quantum computer will arrive.

You can’t replace what you haven’t found

Preparing for post-quantum cryptography begins with understanding what is already in place, rather than selecting a new algorithm.

Where is cryptography used? Which algorithms are deployed? What information do they protect, and how long must it stay confidential? Which systems depend on them? What can you control yourself, and where are you dependent on suppliers?

In a small technology environment, finding those answers may be fairly straightforward. Within a large enterprise, with years of accumulated infrastructure and software dependencies, the task can be much more demanding.

An organisation may be able to update one application directly while relying on a supplier to change another. Even where the technology is understood, responsibility for updating it may sit across several teams. A useful inventory therefore needs to do more than list algorithms. It should help people identify who can act and what needs to happen first.

That discovery process is worthwhile regardless of when quantum computing reaches the threshold that concerns cryptographers. Organisations that understand their cryptographic dependencies are better equipped to respond to changing standards, the retirement of algorithms or newly discovered vulnerabilities.

Post-quantum cryptography is revealing a wider issue of resilience: organisations must get better at changing their cryptography.

Standards are only part of the story

An important milestone is already behind us. Post-quantum algorithms have progressed from academic research to published standards and working implementations.

OpenSSL Library 3.5, for instance, added support for the NIST-standardised ML-KEM, ML-DSA and SLH-DSA algorithms.

That represents significant progress, but publishing standards and implementing them does not complete the transition.

Post-quantum cryptography uses different mathematics from established methods such as RSA and elliptic curve cryptography. Those differences bring practical engineering challenges.

Consider signature sizes. An algorithm may provide the security properties cryptographers want, yet substantially increase the volume of data passing through an existing protocol. That has consequences.

Performance is another consideration, alongside interoperability with systems that will migrate at different times. An organisation needs to understand how a new approach behaves within its own environment, including where it interacts with older systems.

That is why implementation and deployment are separate milestones. Having an algorithm available gives teams something to evaluate. Testing establishes what adopting it will mean for the services they operate.

Security must do more than work on paper. Cryptography needs to function within the infrastructure that people use every day.

Debate belongs in the process

The cryptographic community still disagrees on aspects of the post-quantum transition. I don’t believe that should surprise organisations.

Challenging assumptions is part of a cryptographer’s work. They scrutinise standards and search for weaknesses. When a technology could eventually safeguard vast quantities of sensitive information, that scrutiny is healthy.

For those making investment decisions, disagreement can be unsettling. It can also make waiting seem attractive. But organisations can begin understanding their dependencies and testing available approaches while technical debate continues.

One practical question is whether organisations should adopt new post-quantum algorithms alone or use them alongside established classical cryptography.

Hybrid approaches make it possible to combine the two. During the transition, that may appeal to organisations seeking the protection of a new post-quantum approach without depending on it exclusively.

Different organisations will reach different conclusions. At OpenSSL, our approach is not to favour one published national or international standard over another. We implement standards so users have a choice.

Organisations can then assess their own circumstances instead of being directed towards a single answer.

Don’t wait for a countdown

There is a further reason why some organisations may need to consider migration earlier than others.

Encrypting sensitive information today does not mean it will cease to be valuable tomorrow.

An attacker can capture encrypted information now and keep it. If technology later becomes capable of breaking the cryptography used to protect it, information that remains valuable could be exposed.

How much that matters depends on the information itself. Data that loses its relevance within hours presents a different situation from government, healthcare or commercial information that must remain confidential for decades.

The question is therefore about more than the security of today’s connection. It also concerns the lifetime of the information passing through it. How long would disclosure cause harm? Would that information still matter after the systems that originally handled it had been replaced?

These questions help organisations decide where to focus their attention. They also explain why a single migration deadline has limited value. Organisations need to assess their own information, infrastructure and exposure to risk.

Cryptographic agility is the real objective

If there is one lesson I hope organisations take from post-quantum migration, it is that changing cryptography should become a routine capability.

Algorithms will change in the future, and the technologies we depend on today will eventually give way to others. Organisations therefore need to locate their cryptography and replace it without repeatedly rebuilding large parts of their infrastructure.

This is cryptographic agility. It could prove to be among the most valuable results of the post-quantum transition.

In practice, that ambition should influence the questions organisations ask during migration. How difficult will the next change be? Will the knowledge gained during this transition remain available to the people maintaining these systems? Will future teams understand the dependencies and decisions being created now?

Completing an upgrade matters. So does leaving the organisation better prepared for the upgrade after it.

The organisations best equipped for the quantum era will not necessarily be those that deployed a particular algorithm ahead of everyone else. They will be those that mapped their dependencies, carefully tested new approaches and developed systems able to adapt as the technology evolves.

A discussion that needs to happen now

The post-quantum transition is at an interesting stage. Standards have been published and implementations are available, while many of the harder questions now relate to deployment.

How do these algorithms perform within existing infrastructure? Where is hybrid cryptography appropriate? How should organisations set their migration priorities? And how can we prevent one form of technical debt from simply replacing another?

Answering those questions takes more than cryptographic expertise. Developers and security leaders need to speak to each other. Researchers need to hear from those putting their work into practice. Organisations must understand what the standards mean for the systems they run.

These are among the discussions we’ll be having at OpenSSL Conference 2026, taking place in Prague from October 13 to 15. The event brings together people approaching these challenges from different perspectives.

At this point in the post-quantum transition, sharing practical experience is valuable. What teams learn from evaluating algorithms, working through dependencies and testing interoperability can help turn a broad ambition into a workable migration plan.

For organisations wondering where to begin, the first questions are already available: what cryptography do we use, what does it protect, and how would we change it?

Quantum computing’s timetable remains uncertain. The work needed to prepare is tangible, and organisations can begin it now.

https://cafeadobro.ro/

https://www.stagebox.uk/wp-includes/depo10-bonus10/

depo 25 bonus 25

https://parfumschristianblanc.com/

https://www.barplate.com/wp-includes/js/qris/

https://hotmusic507.org/

Enjoyed this video?
"No Thanks. Please Close This Box!"