Skip to main content contact

Is today’s encryption still an effective safeguard?

Is today’s encryption still an effective safeguard?

Post Quantum Cryptography
02.10.2026
4 min
Team in a security operations center in front of a wall display showing the post-quantum cryptography migration roadmap

Created using ChatGPT

 

written by Anja Schmitz, Partner/Senior Consultant at Projektas GmbH, and Xenia Bogomolec, founder of Quant-X Security & Coding GmbH

 

Among the technical measures that protect sensitive data and systems, encryption is one of the most important security mechanisms. But how effective is this safeguard in the long run, if powerful quantum computers could one day break the encryption methods in use today? This article looks at the risks involved and shows why organizations should engage with post-quantum cryptography now.

 

Data and system security is present at every level of the organization today. On one side, the threat landscape in cyberspace keeps growing. On the other, legal and regulatory requirements for the protection of data continue to rise. One major driver was the General Data Protection Regulation (GDPR), which has applied across the European Union since May 2018. It requires appropriate technical and organizational measures to protect personal data. The revised Swiss Data Protection Act, which came into force in September 2023, follows the same risk based approach.

 

Encryption as a central safeguard

 

Encryption is one of the classic technical safeguards. Data is transformed so that it can only be read with the matching cryptographic key. Encryption contributes substantially to the confidentiality and integrity of information and protects personal data from unauthorized access. Cryptographic methods also play a key role in proving the integrity of the author or owner of data and systems.

 

Harvest Now, Decrypt Later

 

Exactly this protective effect is now being called into question by a phenomenon known as “Harvest Now, Decrypt Later” (HNDL). A further threat scenario is “Trust Now, Forge Later” (TNFL). In both cases, encrypted and digitally signed data is intercepted or stolen today and stored for later decryption or manipulation. The attackers are betting that future quantum computers will be able to break the cryptographic methods in use today. This is particularly problematic for data with long retention or confidentiality periods, such as health, customer or personnel records. It also affects data that was collected many years ago and will remain sensitive for years to come.

 

A new form of cyber threat emerges from this: even if encrypted data cannot be read today, its confidentiality and integrity could be at risk within a few years. Organizations therefore face the challenge of moving their cryptographic methods to quantum resistant alternatives in time, before powerful quantum computers become available.

 

Standards and timelines are set

 

Post-quantum cryptography (PQC) has been researched since the early 2000s. The globally leading National Institute of Standards and Technology (NIST) of the U.S. Department of Commerce has evaluated the first candidates for key exchange and digital signatures since 2017 and published three selected standards in August 2024. Standardization of two further PQC methods is under way. The ISO organization in Geneva and the European Telecommunications Standards Institute (ETSI) have since published additional PQC standards. In parallel, various national and international authorities have published migration strategies.

 

The EU aims to migrate critical systems to PQC by the end of 2030. Systems with medium and low risk are to follow by the end of 2035. NIST takes a technical approach: by 2030, all methods with a security level of 112 bits or less will be considered deprecated. Bit security here does not refer to the key length, but to the complexity of the most efficient attack on the method. The widely used RSA-2048, for example, falls into this category. From 2035, all methods that do not qualify as post-quantum secure will no longer be compliant with NIST requirements. Given the complexity of our digital infrastructures, these are ambitious yet necessary timelines.

 

Start now: hybrid methods as an entry point

 

As early as November 2024, 18 EU member states called for urgent prioritization of PQC migrations in Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography. In response to new developments in quantum computing, Google, for example, has set itself the goal of offering post-quantum secure services by 2029. The recommendation is to start with hybrid methods, which combine PQC and classical cryptography.

 

About the authors

 

Anja Schmitz is a lawyer and Partner/Senior Consultant at Projektas GmbH, based in Zug, Switzerland. She advises on corporate governance, compliance, data protection and project management. Her work focuses on the implementation of compliance projects, legal project management and management consulting.

 

Xenia Bogomolec is a cyber security expert and founder of Quant-X Security & Coding GmbH. She advises critical infrastructure providers with high regulatory requirements on cyber security and leads technology transfer projects in post-quantum security, quantum cryptography and AI in the cyber security context.

 

First published in the trade journal Compliance, September 2026 edition. Published on cyberunity.io with the kind permission of the authors.

 

Do you want to go deeper? Here you find two more articles from our community: Cryptography Specialists: The Key to a Secure Post-Quantum World and Quantum-Proof Random Numbers. For questions on PQC migration and on careers in this field, you reach us at info@cyberunity.io.

download pdf (german)

comment

Feld erforderlich
Feld erforderlich
Feld erforderlich
* mandatory