Quantum computing is often presented as a technology of the future. For many organizations, it may still appear too distant to become a current governance, risk, and compliance concern. However, its possible impact on cryptography makes the question more urgent than it first seems.
Today, organizations depend on cryptographic mechanisms to protect sensitive data, secure online communications, authenticate users, and verify digital signatures. However, the development of quantum computing over recent years is revealing the future limitations of some widely used public-key cryptographic mechanisms, especially RSA and elliptic-curve cryptography (ECC). A powerful quantum computer could solve the mathematical problems on which the security of these mechanisms depends.
Organizations have an interest in considering quantum risk today. Information encrypted now may still be sensitive when quantum capabilities become available. Furthermore, replacing cryptographic mechanisms across complex information systems may require several years. Waiting for the threat to become operational could therefore leave organizations with insufficient time to respond. This situation creates a difficult question for organizations: how can they prepare for a risk when the threat is not yet operational and its timeline remains uncertain? The response will require the involvement of different actors, from cybersecurity and IT teams to risk managers, business owners and suppliers. GRC can provide the structure needed to understand the exposure, assess the risk, and coordinate the transition.
This article examines how quantum computing may affect current cryptographic mechanisms, why organizations should prepare today, the challenges it creates for governance, risk, and compliance, and the main steps toward quantum readiness.
What Quantum Computing Changes in Cryptography
The main objective of encryption is to transform readable information into an unreadable form in order to prevent unauthorized access. And the information can be recovered only by using the appropriate cryptographic key. In today’s computing environment, organizations mainly rely on two types of cryptographic mechanisms: symmetric and asymmetric cryptography. Symmetric encryption uses the same secret key to encrypt and decrypt information, with AES being a common example. Asymmetric cryptography uses two mathematically linked keys: a public key that can be shared and a private key that must remain secret. RSA and ECC are widely used asymmetric mechanism.
These mechanisms are considered secure against classical computers when they are correctly implemented and use appropriate key sizes. Their security depends on mathematical problems that are easy to perform in one direction but extremely difficult to reverse. For example, RSA relies on the difficulty of finding the original prime numbers used to produce a very large number. When an appropriate key size is used, even a powerful classical computer would need an extremely long time to find these numbers. This mathematical difficulty is what makes RSA secure today.
However, progress in quantum computing could change this situation. Quantum computers process information differently from classical computers. A classical computer uses bits, and each bit has one value at a time, either 0 or 1. A quantum computer uses quantum bits, called qubits. Before it is measured, a qubit can exist in a combination of the two reference states, called a superposition. Quantum algorithms manipulate these states and use interference to reduce incorrect possibilities and increase the probability of obtaining a useful result. This does not make quantum computers faster for every task, but it can give them an important advantage when solving some specific mathematical problems.
The main cryptographic concern comes from Shor’s algorithm. A sufficiently powerful quantum computer could use it to solve the mathematical problems protecting RSA and ECC. This could compromise key establishment and digital signatures, affecting confidentiality, integrity, and authenticity. However, quantum computing does not affect every cryptographic mechanism in the same way. AES, which is a symmetric encryption algorithm, is not broken by Shor’s algorithm. The main concern is the future vulnerability of public-key cryptography on which many digital systems currently depend.
Why Organizations Should Prepare Today?
As mentioned above, a powerful quantum computer capable of breaking current public-key cryptography is not available today, and no one can predict exactly when it will become operational. However, this uncertainty does not mean that organizations should wait before assessing the risk. The need to prepare is mainly justified by the lifetime of sensitive information and the time required to change cryptographic systems.
The first concern is known as HNDL, or “Harvest Now, Decrypt Later.” It means that an attacker can collect encrypted information today and store it for several years, until sufficiently quantum capabilities become available and allow the attacker to decrypt it. The level of risk depends largely on the lifetime of sensitive information and how long it must remain confidential. This may concern government information, personal data, research, intellectual property, or strategic business information. The important question is not only how information is protected today, but also how long it needs to remain confidential.
A second concern relates to digital signatures. RSA and ECC are used not only to establish secure communications, but also to verify the identity of a signer and confirm that information has not been modified. If these mechanisms become vulnerable, attackers could potentially forge signatures, impersonate trusted parties, or distribute malicious software as a legitimate update. This creates risks to integrity and authenticity.
Finally, changing cryptographic mechanisms is not as similar as installing a simple software update. Cryptography is present in applications, certificates, protocols, devices, and services provided by external suppliers. Some old systems may not support new algorithms, and suppliers may not all be ready at the same time. Organizations must first identify these dependencies, assess their importance, test new solutions, and manage compatibility. This process can require several years. That is why organizations should start preparing today. This does not mean that every system must be replaced immediately. It simply means giving the organization enough time to understand the risk, define its priorities and manage the transition step by step.
Quantum Computing Risk as a GRC Challenge
The different concerns discussed above show that the risks quantum computing creates for current cryptographic mechanisms are not limited to technical issues for IT and cybersecurity teams. They also represent a challenge for governance, risk, and compliance.
From a governance perspective, organizations need to define who is responsible for monitoring this risk and preparing the response. The subject can involve different functions, including information security, IT, risk management, legal, procurement, and business departments. Without clear responsibilities and coordination, each function may consider that the subject belongs to another department. Management should, therefore, ensure that quantum risk is considered in future security and technology decisions.
The level of risk is not the same for every organization. It depends on the type of information, how long it must remain protected, the cryptographic mechanisms used and the time needed to change them. For example, information that must remain confidential for 15 years is more exposed than information that loses its value after a short period. Each organization should, therefore, assess its own situation and give priority to sensitive information and critical systems.
Quantum risk may also create compliance concerns. Organizations have legal, regulatory, or contractual obligations to protect personal, financial, or strategic information. If the cryptographic protection used today may become vulnerable while the information still needs to remain confidential, this risk should be considered as part of compliance management.
Another important concern relates to external suppliers. Organizations depend on cloud services, software, certificates, equipment, and other services provided by third parties. Their ability to change cryptographic mechanisms will also depend on the preparation and migration plans of these suppliers. For this reason, supplier monitoring and future contractual requirements should be included in the preparation.
Organizations do not need to create a completely new risk-management framework to manage this subject. ISO/IEC 27005 can help them identify, analyze, and evaluate scenarios related to long-term confidentiality, digital signatures, and migration difficulties. ISO/IEC 27001 can support the governance, treatment, and monitoring of these risks through the existing information security management system.
The objective is not to predict the exact date when a powerful quantum computer will become available. It is to understand the organization’s exposure and start making the necessary decisions before the situation becomes urgent.
From Awareness to Quantum Readiness
Understanding the risk is a first step, but it does not mean that an organization is ready. Quantum readiness does not require the immediate replacement of all existing cryptographic mechanisms. It means that the organization knows its exposure, defines its priorities, and prepares a controlled transition.
The first action is to identify the information that needs to remain confidential for a long period. Organizations should determine where this information is stored, how it is exchanged and which cryptographic mechanisms protect it. This assessment should begin with sensitive information and critical systems instead of trying to analyze everything at the same time.
Organizations also need to identify where RSA and ECC are used. These mechanisms may be present in applications, digital certificates, communication protocols, digital signatures, devices and services provided by external suppliers. Building this inventory may be difficult because some cryptographic mechanisms are hidden inside applications or are not clearly documented.
One of the main solutions to this risk is Post-Quantum Cryptography, known as PQC. It refers to cryptographic algorithms designed to resist attacks from both classical and quantum computers. These algorithms can run on current computers, so organizations do not need to have a quantum computer to use them.
In 2024, NIST published its first three final PQC standards. ML-KEM is mainly used to establish shared secrets, while ML-DSA and SLH-DSA are used for digital signatures. These standards give organizations an important direction for preparing their future migration.
Nevertheless, adopting PQC is not the only action required. Organizations still need to identify their cryptographic dependencies, assess the related risks, test the new solutions and manage their compatibility with existing systems. New algorithms may also have different requirements in terms of performance, key sizes, and signatures.
External suppliers are also an important part of the preparation. An organization may be ready to change its own systems but still depend on software, cloud services, or equipment that does not yet support post-quantum solutions. Organizations should, therefore, ask their critical suppliers about their migration plans, timelines, and future compatibility.
Another important element is crypto-agility. It means the ability to replace cryptographic algorithms, keys, or certificates without rebuilding the entire system or causing serious disruption. This is important because technologies, standards, and threats may continue to change even after the first migration.
Finally, organizations should prepare a gradual migration plan that defines priorities, responsibilities, budgets, and testing needs. A quantum-ready organization is not one that has already replaced every vulnerable mechanism. It is an organization that understands where the risk exists and prepares its transition step by step.
Conclusion
Quantum computing is still developing, and a computer capable of breaking current public-key cryptography is not available today. However, this does not mean that quantum risk should be ignored until such a computer becomes operational. Information collected today may still be sensitive in the future, while changing cryptographic systems can require several years.
Organizations should begin by understanding their exposure, identifying their priorities, and preparing a controlled migration. Existing risk-management frameworks can support this preparation, while PQC standards provide an important direction for the transition. Existing risk-management frameworks can support this preparation, while PQC standards provide an important direction for the future migration.
Are organizations ready? For many of them, the answer is probably not yet. Cryptographic dependencies are not always known, supplier plans may remain unclear, and quantum risk may still be considered a distant technical subject. However, becoming ready is a gradual process. It starts by recognizing the risk, assigning responsibilities and preparing the transition step by step.
The future of quantum computing remains uncertain, but preparing for its risks is already a shared responsibility across the organization.







