G7 Urges Organizations to Replace Vulnerable Encryption Before Quantum Threat Arrives
The G7 is calling on governments and organizations to begin preparing for a cybersecurity threat that does not fully exist yet but could eventually undermine some of the encryption protecting today’s digital infrastructure.
A new G7 cybersecurity call to action urges public and private organizations to start transitioning to post-quantum cryptography (PQC) rather than waiting until sufficiently powerful quantum computers become available. The guidance warns that recent advances in quantum computing make the threat more immediate and that replacing cryptographic systems can take years. The concern centres on public-key encryption, which is widely used to protect communications, digital identities and sensitive information across the internet. A future quantum computer powerful enough to run certain algorithms could break some of the mathematical problems on which those systems depend.
The quantum threat is no longer being treated as distant
Quantum computers are still far from being capable of breaking the encryption used across the internet at scale. The problem for organizations is the amount of time needed to replace the technology protecting their systems. The G7's cybersecurity working group is therefore pushing organizations to begin the transition before the threat becomes technically practical. The group says the exact arrival date of a cryptographically relevant quantum computer remains uncertain, but recent developments make it necessary to prepare now.
There is another concern: information encrypted today can potentially be collected and stored by attackers and decrypted in the future once sufficiently powerful quantum machines become available. This is often described as a “harvest now, decrypt later” threat. That makes long-lived information particularly important. Data that needs to remain confidential for many years could be at risk even if current encryption continues to work for the time being.
What organizations are being asked to do
The G7 is recommending a phased approach rather than an overnight replacement of existing systems. Organizations should first identify where cryptography is being used across their infrastructure and determine which systems and information would face the greatest consequences if current encryption were compromised. That includes mapping dependencies between internal systems, suppliers and external services.
From there, organizations can develop migration plans and begin moving critical systems toward post-quantum algorithms. The approach is intended to make the transition manageable. Replacing encryption can affect software, hardware, authentication systems and communications infrastructure, meaning organizations cannot simply change one setting and consider the problem solved.
Post-quantum cryptography is the next line of defence
Post-quantum cryptography uses mathematical techniques designed to resist attacks from both conventional and quantum computers. The goal is not to build a new form of encryption specifically for one future quantum machine. Instead, the transition involves adopting algorithms that are expected to remain secure against the capabilities of large-scale quantum computers while continuing to work within existing digital systems. This is also why cryptographic agility is becoming important. Organizations need systems that can change algorithms without having to rebuild their entire infrastructure whenever security standards evolve.
Financial systems face particular pressure
The financial sector is one of the areas receiving particular attention because banks, payment networks and other financial institutions rely heavily on public-key cryptography and handle information that can remain valuable for many years. The G7 had already been working on a coordinated post-quantum transition roadmap for financial institutions. The latest call broadens the message, making clear that quantum-related cybersecurity is not only a problem for banks or governments but one that needs attention across the wider economy. For companies operating critical infrastructure, the stakes can be even higher. A successful attack against vulnerable cryptographic systems could affect everything from communications and authentication to industrial and public services.
The transition will take years
The central message from the G7 is therefore about timing. Organizations do not need to wait for a quantum computer capable of breaking today's encryption before acting. By the time such a machine becomes practical, replacing deeply embedded cryptographic systems could already be a major operational challenge. Starting the work now gives companies and governments time to identify vulnerable systems, test new algorithms and make the transition without rushing under the pressure of an active threat. Quantum computing is still developing, and nobody can say exactly when a machine capable of breaking widely used public-key encryption will arrive. But the G7's latest warning makes one point clear: the safest time to begin preparing for that day is before it arrives.
