Post-Quantum Cryptography is already a business risk

August 4, 2026 | Andrew Wheeler, SVP, Deputy CTO and Director of HPE Labs
Two men are engaged in a discussion while a woman works on a laptop in the background, with multiple screens displaying data in a modern office environment

Preparing for a quantum-safe future is no longer a theoretical exercise. It's an infrastructure planning challenge organizations need to address today

In this article
  • Post-quantum cryptography is becoming a business planning priority, not a future concern
  • Preparing for a quantum-safe future requires infrastructure-wide modernization and governance
  • HPE is building quantum-safe capabilities across infrastructure to help customers protect digital trust and prepare for the future
  • Building crypto-agility today can help protect digital trust and reduce long-term risk

Post-quantum cryptography has entered the planning phase

Most organizations believe they still have time to think about post-quantum cryptography. In reality, the bigger risk isn't predicting when a cryptographically relevant quantum computer will arrive. It's ensuring your organization has enough time to prepare. Quantum timelines remain uncertain, but the work required to modernize cryptography across enterprise environments is significant. Because cryptography underpins everything from secure communications and software integrity to device identity and regulatory compliance, planning can no longer wait.

Most organizations believe they still have time to think about post-quantum cryptography. In reality, the bigger risk isn't predicting when a cryptographically relevant quantum computer will arrive. It's ensuring your organization has enough time to prepare.

There are four reasons why many organizations are beginning to plan now. First, harvest-now/decrypt-later risk means adversaries can capture encrypted data today and decrypt it later when quantum capability matures, putting long-lived information at risk before “Q-Day” arrives. Second, NIST finalized the first comprehensive PQC standards in 2024, giving organizations a practical foundation for planning. Third, government and regulated-industry guidance is emerging, increasing pressure to understand exposure, prove readiness, and align procurement decisions. Fourth, migration will take years because cryptography is embedded throughout enterprise environments, from certificates and code signing to device identity, networking, applications, and third-party systems.

A multi-year migration challenge

HPE views PQC readiness as an infrastructure transformation challenge, not simply a single security upgrade. Success will require visibility into where cryptography is used, a risk-based approach to modernization, and the flexibility to adapt as standards and requirements continue to evolve. The safest path is phased, standards-aligned, and crypto-agile: discover where vulnerable algorithms are used, prioritize data and systems with long protection horizons, modernize the hardest-to-change trust anchors first, and build the ability to update cryptography as standards, protocols, certifications, and customer requirements evolve.

HPE is already incorporating PQC-readiness capabilities across key infrastructure domains, including compute, networking, management platforms and cryptographic tooling. Recent advances include PQC-enabled platform security, updated cryptographic libraries aligned with emerging standards and expanded support for quantum-resistant protocols.

The business implications of waiting

For business leaders, the issue is timing. PQC migration will take longer than many organizations expect because cryptography is deeply distributed and often poorly inventoried. Core migration can take 24 to 36 months, while broader infrastructure transition can take 24 to 48 months or more depending on scale, legacy dependencies, vendor readiness, validation cycles, and operational complexity. Waiting until a cryptographically relevant quantum computer exists may leave organizations with too little time to complete the transition responsibly. The organizations that start now will have more control over cost, sequencing, interoperability, and risk; those that wait may be forced into rushed transitions under regulatory, customer, or incident-driven pressure.

The implications extend well beyond cybersecurity teams. Harvest-now/decrypt-later attacks put long-lived sensitive data at risk, while future vulnerabilities in digital signatures could affect software authenticity, firmware integrity and device trust. Certificate and PKI dependencies could create hidden fragility across applications, networks, and management systems. Regulated industries may also face pressure to demonstrate migration planning, supplier readiness, and risk-based prioritization before formal deadlines arrive. PQC readiness therefore belongs in enterprise risk management, cybersecurity planning, infrastructure refresh, compliance strategy, and vendor governance.

Three steps toward quantum readiness
 

1.       The starting point is understanding where cryptography exists across the environment.  Many organizations lack a complete inventory of the cryptographic algorithms used across infrastructure, applications, platforms, certificates, code signing, device identity, management interfaces, and third-party services. They should prioritize data and systems with long confidentiality horizons, especially regulated, mission-critical, high-value, and operationally sensitive information. They should also identify the hardest-to-change areas early, including hardware-rooted identity, secure boot, firmware signing, infrastructure control planes, long-lived certificates, and internal PKI.

2.       Establish governance early.Vendor discussions should focus on standards alignment, migration roadmaps, certification plans, performance tradeoffs, and long-term support commitments. They should also build PQC requirements into procurement for infrastructure expected to remain in service for many years. A narrow claim of “PQC-ready” is not enough. Production readiness requires interoperability, validation, operational support, and the ability to adapt as guidance from organizations such as NIST and other standards bodies continues to evolve.

3.       The final step is building crypto-agility into the organization.  Companies need the ability to introduce, test, replace, and validate cryptographic algorithms without redesigning the environment each time standards, threat models, or compliance expectations change. Hybrid approaches will be important during transition, especially where interoperability with existing systems must be preserved. Infrastructure refresh cycles should be aligned to PQC requirements so that new investments reduce future migration debt rather than extend it.

At HPE, we’re helping customers prepare now.

The question is no longer whether organizations will need to prepare for post-quantum cryptography. The question is whether they will begin preparation on their own terms or wait until external pressures force action. Organizations that start now will be better positioned to protect digital trust, manage risk, and adapt to the next generation of computing.

HPE helps companies take this practical path: discover exposure, prioritize risk, modernize cryptographic management, align infrastructure investments, and move toward crypto-agile operations across the full technology stack. HPE Services is expanding readiness and advisory capabilities to support assessment, cryptographic posture management, PKI and key management modernization, and infrastructure transformation while helping customers maintain compliance, sovereignty, resilience, and operational continuity.

The executive message is simple: do not panic, but do not wait. PQC readiness is a business continuity and digital trust imperative. Organizations that start now can make measured, standards-aligned decisions, protect the data that matters longest, modernize the trust anchors that are hardest to change, and avoid expensive last-minute remediation. HPE’s strength is its ability to connect silicon-anchored trust, lifecycle-managed infrastructure, networking expertise, services guidance, and standards-based execution that helps enterprises turn quantum uncertainty into a credible path toward quantum-safe operations.

Explore how HPE is helping customers prepare:

Share this article