Threats

Australia publishes new guidance on the transition to post-quantum cryptography

July 17, 2026
12 min read

Key Insights:

  • The fabled 'Q-Day' is coming, timing unknown, and there's a fear it may break the internet
  • Future quantum computing capabilities pose a significant threat to the digital infrastructure of critical utility operators
  • Government cyber agencies including the UK's National Cyber Security Centre and Australia's Signals Directorate have published timelines on migrating to post-quantum cryptography
  • ASD recommends organisations should have a plan to transition by the end of 2026 and has published new guidance
  • Australia's financial services regulator APRA will soon verify that companies are starting to map where cryptography is relied upon across their systems, data, and third-party providers

New PQC guidance released as deadline approaches

If you've been lucky enough to see a "quantum chandelier" in person, you'll be familiar with the poetic beauty of a these massive, tiered cooling systems designed to enable super fast quantum computing through cryogenic cooling.

It's more than thirty years since Professor Peter Shor devised Shor's algorithm, a way of finding the prime factors of large numbers exponentially faster than classical computers and theoretically threatening existing cryptography such as RSA.

He continues to offer in depth knowledge on Quantum Computation and once penned a poem on the challenge the cyber security industry now faces:

If computers that you build are quantum,
Then spies of all factions will want 'em.
Our codes will all fail,
And they'll read our email,
Till we've crypto that's quantum, and daunt 'em.

Overcyte previously explored the key quantum security risks for OT operators and the need for business to begin planning NOW for the transition.

How do I start tackling PQC?

Critical infrastructure owners and operators must ensure they are keeping up with quantum developments. In the UK, NCSC published its timeline for PQC migration with no hurry to draft an initial migration plan before 2028:

In Australia, the ASD's PQC planning guide has an earlier deadline where organisations should "have a refined plan for their transition to PQC" by the end of 2026, just five months away:

The Aussies favour a PQC migration plan being in place by the end of 2026

Ensuring financial firms are moving ahead on PQC risks

Supporting these timelines, APRA, the Australian Prudential Regulation Authority and overseer of the financial sector addressed the recent 2026 AFIA Risk Summit and stated that:

APRA wants to see our regulated entities at least starting to map where cryptography is relied upon across their systems, data, and third-party providers, including long-lived data and critical infrastructure. Over the coming year, we intend to step up our supervisory engagement on this issue too - commensurate with the threat.  We will want to see evidence that boards understand the risk, recognise their obligation to act and are advancing plans to meet the ASD’s recommended timeline.

Google targets completing its own post-quantum migration by 2029 when it's predicted that RSA will be susceptible to new quantum computing capabilities.

This leaves just 900 days for firms to safely progress and complete their plans.

Updating procurement practices and seeking vendor assurance

The ASD believes that "vendor readiness may be one of the biggest factors influencing an organisation’s ability to transition to post-quantum cryptography (PQC) within recommended timeframes."

As a result, this week they have published Post-quantum questions to ask your vendors, a checklist and guide to help organisations assess the PQC readiness of their third-party suppliers of products or services.

Through a structured set of questions, organisations can identify supply chain dependencies on cryptography and assess quantum-related risks to meet their own proposed migration timeline.

The advice is to incorporate key PQC considerations into procurement, contract renewal and vendor assurance activities as the timeline ticks down.

Using the LATICE framework, the questions provide a practical approach to tier vendors and quantify possible risks to operational and cyber security:

  • Locate and inventory cryptographic dependencies (8 questions)
  • Assess risk to individual systems (6 questions)
  • Triage and prioritise systems for transition (5 questions)
  • Implement post-quantum cryptographic algorithms (6 questions)
  • Communicate with vendors and educate relevant stakeholders (6 questions)

Overcyte believes these 31 questions can be leveraged by any firm now seeking to embed PQC security practices into day to day operations.

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo