G7 Urges Organizations to Prepare for Quantum Cyber Threats
G7 and CISA advisory urges organizations to start migrating to post-quantum cryptography now, citing 'harvest now, decrypt later' risks and a 2035 UK roadmap for completion.

Executive Summary
The G7 Cyber Security Working Group, alongside the U.S. Cybersecurity and Infrastructure Security Agency (CISA), issued a joint advisory on Thursday urging governments and private-sector organizations to begin transitioning to post-quantum cryptography (PQC) immediately. The advisory warns that adversaries may already be stealing encrypted data with the intent to decrypt it once sufficiently powerful quantum computers emerge—a tactic known as "harvest now, decrypt later." Organizations handling data that must remain confidential for decades, such as government records, personal information, and trade secrets, face exposure today, not in some distant future.
Technical Analysis
The advisory, released September 3, 2026, emphasizes that while the exact timeline for quantum computers capable of breaking RSA and ECC is uncertain, recent advances suggest their development is accelerating. Post-quantum cryptography, which is designed to resist both classical and quantum attacks, is the recommended defense. The G7 and CISA advise organizations to identify systems holding their most sensitive information and prioritize them for migration to PQC. Rather than replacing entire infrastructures at once, they recommend integrating quantum-resistant algorithms into routine upgrades to reduce cost and disruption.
The advisory also highlights business risks beyond security: companies that delay adoption may lose competitive advantage or be excluded from government contracts that require quantum-resistant technology. This follows a broader trend of governmental guidance. In 2025, the U.K.'s National Cyber Security Centre published a roadmap urging organizations to complete PQC migration by 2035, with early adoption expected in banking, finance, and telecommunications. In June 2026, President Trump signed two executive orders to accelerate U.S. quantum development and protect federal systems from quantum threats. The G7 had previously warned finance ministries and central banks in 2024 about "impending threats" from quantum computing.
Mitigations & Recommendations
Defenders should treat the advisory as a call to action for cryptographic agility. Start by inventorying all cryptographic assets and data flows, identifying those that protect long-lived secrets. Prioritize migration for systems that handle data requiring confidentiality beyond 10 years. Adopt a phased approach: implement PQC alongside existing algorithms in hybrid mode to ensure interoperability, and update procurement requirements to mandate quantum-resistant solutions. Monitor NIST's finalized PQC standards and vendor roadmaps for implementation timelines. For organizations in regulated sectors, align with national guidance, such as the U.K.'s 2035 deadline, to avoid future contract exclusions.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
