nisttrade-pressNewsThe Broadside3 min read

G7 warns PQC migration lag puts encryption at risk

The working group's call to action lands alongside a Trump executive order that moved the federal migration deadline from 2035 to 2030, but most private-sector sectors outside finance and tech haven't started.


TL;DR

The G7 Cyber Security Working Group released a report urging governments and organizations to accelerate migration to post-quantum cryptography, warning that the quantum threat "remains off the radar for many organizations." The report, signed by CISA and its G7 counterparts, outlines five priorities: awareness, national strategies, R&D, public-private partnerships, and integrating PQC into procurement requirements. The Trump administration separately moved the federal civilian-network migration deadline from 2035 to 2030 via executive order. The gap between the accelerating federal timeline and lagging private-sector adoption outside finance and tech is widening, creating a two-speed migration that leaves supply chains exposed.

G7 warns PQC migration lag puts encryption at risk
Editorial illustration · drawn by The Broadside

The G7 Cyber Security Working Group's new report, "Preparing for the Post-Quantum Era: A Call to Action," lands at a moment when the federal government is sprinting on PQC migration and much of industry hasn't laced up.

The report, released September 3, 2026, and signed by CISA alongside cybersecurity agencies from the UK, France, Germany, Canada, Japan, and Italy, frames the quantum threat as a near-term economic and business risk, not a distant cryptographic puzzle. "The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence," the working group wrote. It calls on leaders to "reframe the quantum threat from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure."

The report's five priorities (raising awareness, developing national PQC strategies, advancing R&D, fostering public-private partnerships, and integrating PQC into procurement) are not new. CISA, NSA, and NIST have been urging early planning since at least 2023, when they jointly published a quantum-readiness factsheet warning of "harvest now, decrypt later" operations. What's new is the widening gap between the federal side and everyone else.

The accelerating federal clock

The Trump administration has now pulled the federal civilian-network migration deadline from 2035 to 2030, per an executive order signed in June 2025. CISA followed with a product-categories list in January 2026 identifying hardware and software categories (cloud services, web software, networking hardware, endpoint security) where PQC-capable products are "widely available" and agencies should procure only PQC-capable options.

But security professionals pushed back immediately. As CyberScoop reported in January, experts cautioned that most products and backend internet protocols have yet to be updated. The categories list is a procurement signal, not a certification that the listed products are actually quantum-safe in deployment.

The private-sector gap

Google and some other large tech firms have moved their own migration timelines to 2029. The financial sector, heavily regulated and accustomed to cryptographic transitions, is moving. But outside those pockets, adoption has lagged. The G7 report acknowledges this explicitly: "a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk."

The working group also noted that the transition "is not a problem for individual organizations to solve in isolation, but rather a collective transition." That framing matters for contractors. A prime that has completed its cryptographic inventory and begun migration may still depend on subcontractors or MSPs that haven't. The federal 2030 deadline creates a compliance clock; the absence of one in the broader private sector creates a supply-chain asymmetry.

What's still open

The executive order moved the deadline for federal civilian networks. It did not specify whether the 2030 target applies uniformly across all federal contractors and subcontractors, or whether phased timelines by system criticality and classification level are expected. No implementing guidance has clarified that question. CISA's product-categories list offers a procurement lens but not a compliance roadmap. The G7 report urges integration of PQC into procurement requirements, a principle that, if adopted by individual member nations, could eventually close that gap.

The G7 report is a call to action, not a mandate. The federal 2030 deadline is a mandate, but its reach beyond civilian agency networks remains undefined. The gap between the two is where contractors will spend the next several years.


Published ·Deep Fathom