Skip to content

Obsolete by 2030? How SMEs can Audit Your Cryptographic Inventory Before the Quantum Break

The Quantum Migration Clock: A Practical Guide for SMEs

Jul 2026
Lim May-Ann

Many people have by now likely heard warnings about quantum computers breaking encryption. The likelihood of this happening sounds distant and theoretical. However you may feel about it, there is a shift towards quantum readiness happening: governments and standard bodies have started to set quantum migration timelines, regulators are turning quantum risk into a compliance requirement, and organisations across Asia Pacific are working on concrete migration planning. Here is what SMEs should know and do starting now.

What Is Quantum Migration and Why Now?

Quantum migration is the transition from existing encryption algorithms that protect data today (RSA and ECC) to quantum-resistant algorithms that will remain secure even if quantum computers emerge. The threat is real and urgent: adversaries may be breaking in now and harvesting encrypted data today to decrypt it later with future quantum computers, a technique called “Harvest Now, Decrypt Later (HNDL).” This means data encrypted today could be vulnerable tomorrow. There is also a analogous “Trust Now, Forge Later (TNFL)” threat that would affect systems that rely on digital signature systems to ensure integrity, where systems we rely today may be forged by malicious parties.

On August 13, 2024, NIST released the first three post-quantum cryptography standards: ML-KEM, ML-DSA, and SLH-DSA, marking the first publicly available quantum-resistant algorithms that organisations can deploy immediately using classical computers.

With the standards in place, NIST guidance has also highlighted that quantum-vulnerable algorithms will be deprecated by 2030, and disallowed by 2035. Governments have started to adjust to this timeline, with some countries mandating that critical government infrastructure must be protected.

  1. The United State’s NSA requires national security systems to adopt quantum-resistant cryptography for new acquisitions starting in 2027;
  2. The European Union has outlined similar timelines, particularly for critical infrastructure;
  3. The UK’s National Cyber Security Centre (NCSC) outlines a three-phase transition timeline for organisations to migrate to post-quantum cryptography (PQC) and complete the transition by the year 2035;
  4. Australian Signals Directorate (ASD) targets complete transition to quantum-resistant cryptography by 2030;
  5. Singapore’s guidance for Critical Information Infrastructure (CII) projects 31 Dec 2031 to complete quantum-safe migration across CII computer and computer systems, i.e. vulnerable cryptography should no longer be used.

Quantum Deadline: Don’t Miss it

Southeast Asia is an early-moving region, with governments and regulators turning post-quantum migration into a deadline-driven requirement.

If your organization contracts with government, supplies critical infrastructure, or operates in regulated industries (finance, energy, healthcare), these deadlines are no longer optional. They are compliance requirements. Starting in 2030 will already be too late, given the asset-by-asset, certificate-by-certificate, protocol-by-protocol enumeration that any credible enterprise migration requires.

Step 1: Understand What You Are Protecting

Before you can migrate, you must know where your encryption is. Most organizations fail at this step: Gartner estimates that through 2027, more than 60% of organizations will fail a compliance audit due to untracked cryptographic assets.

Ask yourself: What sensitive data does my organization encrypt? Which systems handle this data? How is it encrypted? How long must it stay secret?

Data that must remain confidential for decades (intellectual property, financial records, medical information) faces the highest quantum risk. If adversaries are collecting your encrypted data now, quantum computers could decrypt it in the future.

Step 2: Conduct a Cryptographic Inventory Audit

You cannot replace what you have not mapped. This is a critical first step, and it is simpler than you might think.

What you are looking for:

  • Digital certificates using RSA or ECDSA algorithms
  • Websites, VPNs, email systems using these algorithms
  • Long-lived certificates (valid for multiple years—these are particularly risky)
  • Any system where encryption protects data for extended periods

How to find them:

  • Check your TLS certificates. If you have a website, look at the certificate. Is it RSA or ECDSA? If so, it needs replacement by 2035.
  • Document your VPNs, email encryption, and data-storage systems. Ask your vendors: “What encryption algorithm does your system use? Is it RSA or ECC?”
  • Search your network. Ask your IT staff to find all certificates on your network. Use tools that scan for certificate files (ending in .pem, .crt, .key).

This step helps you turn your raw data in a spreadsheet into actionable insights: identifying what algorithm, where it is deployed, who depends on it, when it expires, and what data it protects.

Step 3: Prioritize and Plan

Not everything needs to migrate immediately. Prioritize by risk:

  • High priority (migrate now): Long-lived certificates protecting sensitive data, systems handling government or financial information, systems running past 2030.
  • Medium priority (migrate by 2032): Standard TLS certificates, systems with shorter lifespans, data with medium-term confidentiality requirements.
  • Lower priority (complete by 2035): Non-critical systems, internal-only communications.

Hybrid approaches that combine traditional and quantum-resistant algorithms during transition offer intermediate resilience while you plan full migration.

The SME Reality

You do not need a dedicated cryptography team to start preparing for quantum migration. Start with the inventory in a spreadsheet of your critical systems and their encryption methods. Contact your vendors and ask: “Do you support post-quantum cryptography? What is your migration timeline?” Most major vendors have plans in place. The migration clock is real, but it is not a sprint. Protect your data and your future compliance status today by starting migration planning in 2026. This positions your organisation to meet 2030 and 2035 deadlines without needing a crisis response team.