G7 warns that quantum readiness cannot wait
G7 cybersecurity authorities are calling for early preparations to replace vulnerable public-key cryptography, pointing to the time needed to upgrade systems and address risks to Internet infrastructure.
The transition to post-quantum cryptography needs to begin before quantum computers capable of breaking current public-key systems become available, according to cybersecurity authorities from the Group of Seven.
In a 3 September call to action, the G7 Cybersecurity Working Group urged governments and businesses to start preparing for the change rather than wait for a cryptographically relevant quantum computer to emerge. The group includes cybersecurity authorities from the G7 countries, alongside the European Commission, with support from ENISA.
A key concern is that encrypted data can already be collected and stored for future decryption. The agencies also warn that sufficiently capable quantum attacks could compromise public-key cryptography used for authentication and digital signatures, potentially allowing attackers to impersonate trusted parties or forge signed information.
The G7 recommends that organisations begin by establishing where and how cryptography is used across their systems. They should identify critical infrastructure and information that needs protection over long periods, map dependencies between systems, establish responsibilities and budgets, and ensure that cryptographic algorithms can be replaced without rebuilding entire systems.
Internet infrastructure presents a particular challenge because public-key cryptography is embedded in several essential systems. TLS and certificate infrastructures, DNSSEC and the Resource Public Key Infrastructure (RPKI) all rely on cryptographic mechanisms that will need to evolve as post-quantum alternatives become available.
Standards development is already addressing some of these issues. Work on DNSSEC is examining how post-quantum signatures could be introduced without imposing their much larger sizes across signed DNS zones. RPKI experiments are testing post-quantum and composite signatures and assessing their impact on certificates, route-origin authorisations, repositories and distribution mechanisms.
TLS has advanced further, with the IETF publishing RFC 10024 in August. The specification defines three hybrid key-agreement mechanisms for TLS 1.3 that combine ML-KEM with existing elliptic-curve exchanges. Separate work is continuing on post-quantum authentication using certificates.
The G7 has not predicted when quantum computers capable of compromising current public-key systems will become available. Instead, its warning is based on the length and complexity of the migration itself: organisations need time to identify dependencies, adapt standards and software, and coordinate changes across interconnected infrastructure.
