CISA and G7 Sound the Alarm on Quantum Computing's Threat to Encryption
A joint call to action urges governments and businesses to start swapping out today's cryptography before quantum computers make it useless.

Key points
- CISA and the G7 Cyber Security Working Group jointly published "Preparing for the Post-Quantum Era: A Call to Action" urging a global move to post-quantum cryptography.
- The guidance lists five priorities, including national strategies, research funding, and building quantum-safe requirements into government purchasing.
- Sensitive data stolen today can be decrypted later once quantum computers mature, a tactic known as "harvest now, decrypt later."
- The U.S. National Institute of Standards and Technology finalised its first post-quantum encryption standards in August 2024, giving organisations concrete algorithms to adopt.
The U.S. Cybersecurity and Infrastructure Security Agency has teamed up with the G7 Cyber Security Working Group to tell the world, politely but firmly, that it is time to start replacing the maths that protects almost every login, bank transfer, and government secret online.
Their joint paper, published this week through CISA Cybersecurity Advisories, is called "Preparing for the Post-Quantum Era: A Call to Action." It is aimed at governments, regulators, and any business that relies on encryption. Which is all of them.
What is the actual problem?
Today's encryption relies on maths problems that ordinary computers cannot solve in any reasonable time. A sufficiently powerful quantum computer, a new kind of machine that works on the strange rules of quantum physics, could crack a lot of that maths in hours.
That matters for two reasons. First, once quantum machines arrive, anything still protected by today's algorithms is readable. Second, criminals and hostile states are already grabbing encrypted traffic now and stashing it, betting they can decrypt it later. Researchers call this "harvest now, decrypt later."
Banking sessions, medical records, diplomatic cables, and the digital signatures that prove a software update is genuine all sit on the same shaky foundation.
What are CISA and the G7 actually asking for?
They are asking organisations to plan the switch to post-quantum cryptography, or PQC, which is a new family of encryption algorithms designed to resist quantum attacks. The paper sets out five priorities.
| Priority | What it means in plain terms |
|---|---|
| Awareness | Make leaders understand the quantum risk exists now, not in 2040 |
| National strategies | Governments write formal roadmaps for PQC adoption |
| Research and development | Fund work on quantum-safe tools and testing |
| Public-private partnerships | Vendors, banks, and agencies share what they learn |
| Procurement rules | Bake PQC into what governments and regulators buy |
The procurement point is the sharpest one. When a government refuses to buy software that cannot do post-quantum key exchange, vendors move fast.
Is any of this real yet, or still theory?
The algorithms are real. In August 2024 the U.S. National Institute of Standards and Technology published its first three finalised post-quantum standards, including ML-KEM for key exchange and ML-DSA for digital signatures. Big cloud providers, browser makers, and messaging apps have started rolling them out in hybrid mode, meaning they run the old and new algorithms side by side.
What is missing is the boring middle work: inventorying every certificate, every VPN, every hard-coded library across an organisation, then swapping them out without breaking anything. That takes years.
On the authentication side, this is not a story about multi-factor authentication saving the day. MFA proves who you are at login. PQC protects the cryptographic channel your login travels through, and the signatures on the tokens your identity provider issues. Both matter, and both need to be quantum-safe in time.
What should ordinary people do?
Honestly, almost nothing directly. This is an infrastructure job for vendors, banks, hospitals, and governments. Keep your software updated so you receive PQC support when your providers ship it. If you run a small business, ask your key suppliers, especially your VPN and identity vendors, what their post-quantum roadmap looks like. A vague answer is itself an answer.
The quantum computer capable of breaking today's encryption may be a decade away, or it may not. The data being stolen and stored today is already at risk. That is the whole point of the CISA and G7 message.



