Preparing for the Post-Quantum Era: What Companies Must Do Now
Thales PQC Palooza held during RSA Conference 2026 brought together a raft of distinguished guests who collaborate within the Thales PQC…
Preparing for the Post-Quantum Era: What Companies Must Do Now

Thales PQC Palooza held during RSA Conference 2026 brought together a raft of distinguished guests who collaborate within the Thales PQC ecosystem to share their approaches to living in the post-quantum era.
For decades, modern cybersecurity has relied on cryptographic algorithms that are effectively unbreakable with today’s computing power. But quantum computing changes that equation. Once sufficiently advanced quantum machines become available, they will be able to break widely used public key algorithms such as RSA and ECC in a matter of hours or minutes. This isn’t a distant, theoretical concern. Nation-states and sophisticated adversaries are already harvesting encrypted data today with the intention of decrypting it later, a strategy known as “harvest now, decrypt later.”
This is why PQC has become one of the most urgent technology transitions of the next decade, and a key topic of discussion at RSAC. The U.S. National Institute of Standards and Technology (NIST) has already selected the first PQC algorithms for standardization, and global regulators are beginning to push organizations toward readiness. But the real challenge isn’t the algorithms themselves, but the migration. To be prepared for this, companies need a clear, structured approach to understanding their cryptographic posture and planning a safe transition. That begins with five foundational steps.
1. Build a Cryptographic Inventory
You can’t protect what you can’t see. Most organizations have cryptography embedded in hundreds of places, including applications, APIs, databases, network devices, cloud workloads, certificates, IoT devices, and vendor products. In many cases, cryptography is buried deep in legacy code or inherited systems that no one has touched in years. Building a cryptographic inventory is the process of cataloguing:
- What cryptographic algorithms are in use
- Where they are used
- How they are implemented
- Which systems depend on them
- Who owns those systems
This inventory becomes the foundation for every PQC decision that follows, and without it, migration just becomes guesswork.
2. Conduct Cryptographic Discovery at Scale
Manual inventorying is impossible for large enterprises. Automated cryptographic discovery tools, which are sometimes built into modern security platforms, can scan codebases, binaries, network traffic, certificates, and configuration files to identify cryptographic usage patterns. Effective discovery should reveal:
- Hard-coded keys
- Deprecated algorithms
- Weak key lengths
- Non-standard or homegrown cryptography
- Shadow IT systems using outdated libraries
Discovery must remain an ongoing capability, since new code is deployed every day. Organizations that treat it as such will be far better positioned for PQC migration.
3. Establish Cryptographic Posture Management
Cryptographic posture management (CPM) is emerging as a new discipline, one similar to cloud posture management or identity governance. It provides a centralized, real-time view of an organization’s cryptographic health. A strong CPM program includes:
- Policies defining approved algorithms and key lengths
- Automated monitoring for violations
- Lifecycle management for certificates and keys
- Reporting for compliance and audit teams
- Integration with DevOps pipelines to prevent insecure cryptography from being deployed
In the post-quantum era, CPM will be essential. It ensures that once PQC algorithms are introduced, they remain consistently and correctly implemented across the organization.
4. Identify Where Vulnerable Cryptography Lives
Not all cryptography is equally urgent to replace. Some systems are highrisk because they protect longlived data like financial records, personal information, intellectual property, or governmentregulated data. Other systems may be lower risk because the data they protect has a short useful lifespan. Organizations should classify cryptographic assets based on:
- Sensitivity of the data
- Longevity of the data
- Exposure to external networks
- Regulatory requirements
- Business impact if compromised
This prioritization helps companies focus their PQC efforts where they matter most.
5. Plan and Execute a PQC Migration Strategy
PQC migration is not a simple “drop-in replacement.” New algorithms have different performance characteristics, larger key sizes, and new operational requirements. Migration will require:
- Updating applications and libraries
- Replacing certificates and key infrastructure
- Coordinating with vendors and supply chain partners
- Testing for performance and compatibility
- Ensuring hybrid modes (classical + PQC) where needed
The organizations that succeed will treat PQC migration as a multi-year transformation program, not a technical patch.
The bottom-line message from the guests at PQC Palooza was that the time to act is now, that the window of opportunity is shrinking, and as one guest put it, it is “Y2K without a date.” Quantum-capable adversaries may seem years away, but with techniques like “harvest now, decrypt later” already known, the threat is here. Regulators are watching, customers are asking questions and boards are beginning to demand answers. Companies that start building their cryptographic inventory, discovery capabilities, and posture management programs now will be ready for a smooth PQC transition, but those that wait will face a rushed, expensive, and potentially risky scramble.
To learn more about what we learned at PQC Palooza, check out the special edition of the Thales Security Sessions podcast ‘Inside the Race to a Quantum Safe Future: PQC Palooza Live 2026 at RSAC’ or search Thales Security Sessions with your podcast provider of choice.
메타데이터
- post_id
- 2bdb5aab4fcc
- slug
- preparing-for-the-post-quantum-era-what-companies-must-do-now-2bdb5aab4fcc
- url
- https://medium.com/thales-cybersecurity-products/preparing-for-the-post-quantum-era-what-companies-must-do-now-2bdb5aab4fcc
- canonical_url
- https://medium.com/thales-cybersecurity-products/preparing-for-the-post-quantum-era-what-companies-must-do-now-2bdb5aab4fcc
- author_url
- https://medium.com/@steve_prentice
- status
- ok
- fetched_at
- 2026-06-15 20:49:13