Quantum safe compliance: why your organisation cannot afford to wait

18th August 2026BlogAJ Thompson

Are you ready to get in touch?

Request a Call back

Quantum-safe compliance is the process of migrating your organisation’s cryptography to standards that quantum computers cannot break. For IT directors, risk teams, and security leads in regulated industries, this is no longer a future concern. Adversaries are already collecting your encrypted data today. Their intention is to decrypt it once quantum computers mature — a tactic known as “harvest now, decrypt later.” NIST published the first post-quantum cryptography (PQC) standards in August 2024. The NSA’s CNSA 2.0 framework sets a hard deadline of January 2027 for new National Security Systems.

In this article, AJ Thompson explains what quantum-safe compliance requires, why the regulatory timeline is already pressing, and the three actions your organisation should take now.

Let me be direct about something too many boardrooms are still treating as a future problem. IBM’s announcement that it is working alongside DEKRA— the world’s leading safety certification and assurance body— to promote Quantum Safe Assurance is not a signal that risk is approaching. It is a signal that the industry has moved into the response phase. Quantum safe compliance is no longer optional. The threat is live, the regulatory deadlines are fixed, and the organisations that begin migrating now are the ones that will control their own timeline.

The harvest now, decrypt later threat

Adversaries are already deploying what security teams call “harvest now, decrypt later” strategies.
In practice, this means intercepting and storing encrypted data today, with the intention of decrypting it once quantum technology matures. Your financial records, intellectual property, and customer data are all in the crosshairs. If that information has been transmitted in the last few years, there is every chance it has already been harvested. The only question is whether it will be readable when Q-Day arrives.

IBM’s partnership with DEKRA matters precisely because of what DEKRA represents. This organisation is trusted globally to certify safety and compliance across critical industries. When DEKRA aligns with IBM’s Quantum Safe programme, it sends a clear message to regulators and risk teams alike. Quantum readiness is no longer a technology conversation. It is a certification and governance conversation — and that distinction matters.

The clock is already ticking: the threat is live today, and the compliance deadlines are fixed. Share on X

The regulatory timeline for quantum safe compliance

The deadlines are set, and the runway is shrinking. The National Institute of Standards and Technology published the first post-quantum cryptography (PQC) standards in August 2024. The NSA’s CNSA 2.0 framework follows with hard timelines: all new National Security Systems must be quantum-safe by January 2027, with full mandatory compliance by 2033.

For organisations operating across European markets, NIS2 and DORA create parallel obligations. As a result, quantum-vulnerable cryptography is increasingly classified as falling below the standard of “state-of-the-art” security required by both directives.

Organisations that begin their migration in 2027 or 2028 will find themselves in a race they cannot win. They will be competing against regulatory deadlines, vendor migration backlogs, and adversaries who have already been collecting their data for years. In short, the time to start is now — not when the pressure becomes unavoidable.

Three actions your organisation must take now

Conduct a full cryptographic audit. You cannot protect what you cannot see. Map every algorithm, digital certificate, and cryptographic key across your estate. Then run a posture analysis to understand each asset’s protection relevance and the mitigation effort required. However, most organisations find they have far more cryptographic exposure than they expected — which is why starting early matters.

Prioritise by data longevity, not data volume. Intellectual property, long-term financial records, and sensitive personal data all have lifespans that extend well beyond the point at which cryptographically relevant quantum computers will exist. Therefore, these assets migrate first. A multi-year roadmap is essential — waiting until 2027 or beyond leaves no runway.

Build a phased migration roadmap now. Create a detailed plan outlining the steps, timelines, and resources required to transition to quantum-resistant encryption. In addition, adapt existing policies and governance frameworks to incorporate quantum risk. Quantum safe compliance is not just a technical change — it is a governance change — and that takes time to build properly.

At Northdoor, we already work with clients across regulated industries to assess quantum exposure and build practical, prioritised migration plans. These are aligned to the IBM and DEKRA Quantum Safe Assurance framework, which provides an internationally recognised benchmark that regulators and auditors will increasingly expect organisations to demonstrate against.

The IBM and DEKRA framework gives you a benchmark

The organisations beginning this work today will control their quantum safe compliance timeline. Those that delay will find themselves scrambling to meet it. The IBM and DEKRA framework sets a certifiable standard — not just a best-practice guide. Northdoor has the expertise to help you get there.

For a deeper look at what migration involves, read our step-by-step guide to IBM Quantum Safe migration. Or contact Northdoor for a Quantum Safe readiness assessment — before your window closes.

1

Our Awards & Accreditations