- Quick Answer: Why Does the G7's PQC Warning Matter to Enterprises?
- The Two G7 Documents: What Each One Says
- Why This Guidance Changes the Conversation
- The Uncomfortable Math: Why Migration Takes Longer Than the Threat Allows
- Enterprise Decision Table: How to Prioritize Your PQC Program
- Migration Is an Operational Program, Not an Algorithm Swap
- Hybrid Cryptography and the Transition Period
- What the G7 Guidance Does Not Do
- How Encryption Consulting Can Help
- Conclusion
- Frequently Asked Questions
In January and May 2026, G7 financial authorities published two landmark documents on post-quantum cryptography (PQC) risk. Both name Harvest Now, Decrypt Later as an active, ongoing threat and set a 2030-2035 migration window that aligns with NIST IR 8547’s deprecation timeline. If your organization encrypts sensitive data today with RSA, ECDSA, or ECDH, that data may already be at risk. Start with a cryptographic inventory.
When central banks speak, enterprises listen. When G7 financial authorities issued coordinated guidance on quantum technologies and their implications for the financial system in 2026, it marked a turning point. Post-quantum cryptography (PQC) is no longer a topic confined to cryptographers and standards bodies. It is now a documented concern of the institutions that underpin global finance, and that shift carries weight far beyond banking.
Quick Answer: Why Does the G7’s PQC Warning Matter to Enterprises?
The G7’s 2026 guidance matters to enterprises because it converts PQC migration from a theoretical future concern into a current operational priority backed by institutional consensus. The G7 Cyber Expert Group (CEG) Roadmap published in January 2026 set a coordinated 2030-2035 migration window for the financial sector. The G7 Quantum Technologies Working Group (QTWG) Report published in May 2026 extended the analysis to cover both confidentiality threats (Harvest Now, Decrypt Later) and integrity threats (Trust Now, Forge Later). For any enterprise holding sensitive long-lived data, these documents signal that the regulatory direction is set, the algorithmic deprecation timeline is confirmed (NIST IR 8547: RSA and ECC deprecated after 2030, disallowed after 2035), and delay is no longer a neutral option.
The Two G7 Documents: What Each One Says
Two distinct G7 documents are now in play, and understanding what each one does helps clarify why they matter together.
The G7 Cyber Expert Group (CEG) Roadmap, published January 13, 2026 and co-chaired by the U.S. Treasury and the Bank of England, is the operational document. It advises G7 Finance Ministers and Central Bank Governors on cybersecurity matters and sets a coordinated multi-phase roadmap for migrating to quantum-resistant cryptography across the financial sector. The CEG is explicit that the document does not set regulatory expectations but is intended to inform migration activities. That said, guidance from this body has a well-established pattern of preceding examination criteria. The roadmap identifies the 2030-2035 window as the target for financial sector transition, matching the NIST IR 8547 timeline.
The G7 Quantum Technologies Working Group (QTWG) Report, published May 2026 and co-chaired by the Banque de France and the Bank of Canada, takes a wider analytical lens. It covers quantum computing applications in finance, quantum sensing, and cryptographic security, and examines the system-level dependencies that quantum adoption could introduce. Where the CEG roadmap focuses on how to migrate, the QTWG report explains the full scope of why. Together, they give senior leadership both the strategic rationale and the operational framework.
Why This Guidance Changes the Conversation
For years, the quantum threat lived in an awkward space. It was real and serious, and critically, perceived as years away, which made deferral easy to justify. What the G7 documents do is remove that comfort. When the institutions overseeing trillions in assets reach a shared conclusion about quantum risk, the conversation moves from theoretical to operational.
Both documents explicitly name Harvest Now, Decrypt Later (HNDL) as an active threat. HNDL is the adversarial strategy of collecting encrypted data today, before a cryptographically relevant quantum computer (CRQC) exists, and storing it until a CRQC becomes available to decrypt it. The data being collected now, encrypted with RSA-2048 or ECDH, becomes the target. Any organization whose sensitive data must remain confidential for a decade or more is already inside the HNDL exposure window.
The QTWG report also surfaces a second, underappreciated threat: Trust Now, Forge Later (TNFL). Where HNDL targets confidentiality, TNFL targets integrity. A quantum computer could retroactively derive a private key from today’s public digital signatures, enabling backdated forgery of financial transactions, signed contracts, or software updates. The QTWG report notes TNFL may prove more disruptive than HNDL for financial infrastructure, where non-repudiation is foundational. Enterprise security programs that focus exclusively on encryption and ignore signing key exposure are planning for only half the threat.
For regulated industries, these documents are leading indicators. Financial sector guidance from G7 bodies has a consistent history of shaping examination criteria across jurisdictions. Organizations in finance, insurance, and critical infrastructure should expect quantum readiness questions in future audits. But the lesson applies equally to every enterprise that depends on cryptography to protect sensitive data or verify the integrity of signed operations.
The Uncomfortable Math: Why Migration Takes Longer Than the Threat Allows
Post-quantum migration is not a patch. For a large enterprise, a realistic end-to-end transition can take well over a decade. Cryptographic discovery alone, which must precede everything else, often takes two to three years. Application migration across legacy systems and embedded cryptography can stretch to eight to ten years. Most organizations that begin this process find significantly more cryptographic surface area than they expected.
This risk is captured precisely by Mosca’s Inequality, formulated by cryptographer Dr. Michele Mosca. If the length of time your data must stay confidential (X) plus your migration timeline (Y) exceeds the years until a CRQC arrives (Z), you already have a problem. X + Y greater than Z means migration should have started already. The G7 QTWG report reinforces the urgency, noting a non-negligible probability that a CRQC could emerge within the next decade. If that probability is even partially correct and your sensitive data has a ten-year confidentiality horizon, the inequality may already be breached.
Regulatory deadlines compress the window further. NIST IR 8547 (Initial Public Draft, November 2024) proposes deprecating quantum-vulnerable algorithms, including RSA, ECDSA, and ECDH, after 2030 and disallowing them entirely after 2035. Executive Order 14412 (June 2026) effectively treats the 2030 deprecation date as a compliance deadline for federal high-value assets and high-impact systems. For defense-adjacent or national security system contractors, NSA’s CNSA 2.0 is tighter still: new software and firmware signing acquisitions must support quantum-resistant cryptography exclusively from January 1, 2027.
An organization beginning its program in 2026 has a reasonable runway. One that waits until 2028 faces a high-risk scramble against hard regulatory deadlines. The time advantage belongs entirely to those who start now.
Enterprise Decision Table: How to Prioritize Your PQC Program
Not every system faces the same urgency. Use this table to triage where to start based on actual risk exposure rather than treating all cryptographic assets as equally urgent.
| Asset or system type | Primary threat | Confidentiality horizon | Priority | Recommended first step |
|---|---|---|---|---|
| Long-lived sensitive data (patient records, financial archives, IP) | HNDL (active now) | 10+ years | Critical: act now | Classify data by lifespan; encrypt at-rest copies with hybrid PQC schemes |
| Long-lived signing keys (CA root keys, code signing keys, firmware signing) | TNFL (integrity forgery) | Lifetimes of 10-20+ years | Critical: act now | Inventory all signing keys; plan key ceremony for ML-DSA replacements |
| TLS and certificate infrastructure (external services) | HNDL, compliance deadline | Short (cert lifetimes) | High: before 2030 | Audit CA hierarchy; test ML-KEM and hybrid TLS in staging |
| VPNs and network encryption | HNDL | Medium | High: before 2030 | Request vendor PQC roadmaps; prioritize devices on NSA CNSA 2.0 scope |
| Application cryptographic libraries | HNDL, TNFL | Varies | Medium: 2026-2029 | Run CBOM Secure scan to find all library-level RSA/ECC usage |
| Legacy and embedded systems (OT, IoT) | HNDL | Long (device lifetimes) | Medium: begin assessment now | Assess hardware constraints; plan for hybrid or protocol-level protections |
| Third-party software and supply chain | HNDL, TNFL (through vendors) | Varies | Medium: start due diligence now | Include PQC roadmap requirements in vendor contracts and RFPs |
Migration Is an Operational Program, Not an Algorithm Swap
The deepest insight in the G7’s framing is that post-quantum readiness is fundamentally an operational capability, not a cryptographic one. Swapping RSA for ML-KEM (FIPS 203, key encapsulation) or ECDSA for ML-DSA (FIPS 204, digital signatures) is conceptually simple. Doing it across an entire enterprise without breaking systems, missing hidden dependencies, or violating interoperability with partners that have not yet transitioned is an enormous coordination challenge.
This is why crypto-agility matters so much. An organization that has hardcoded cryptographic algorithms into its systems will experience every future transition as a crisis. One that treats cryptography as a managed, swappable, policy-governed layer can absorb change as routine. The same discovery, automation, and policy-enforcement capabilities needed for managing certificate lifespans today are precisely those needed for quantum migration tomorrow.
The G7 CEG Roadmap’s multi-phase structure reflects this operational reality. A credible enterprise program must coordinate across several distinct workstreams simultaneously:
- Cryptographic discovery and inventory: Before any migration decision can be made, an organization must know what cryptographic assets exist, where they are, and which algorithms they use. This is the prerequisite gate that everything else depends on. Without a Cryptographic Bill of Materials (CBOM), migration planning is guesswork.
- Certificates and PKI: Every certificate and the PKI hierarchy that issues it must be inventoried, assessed for quantum vulnerability, and prepared for reissuance with ML-DSA or hybrid algorithms. Certificate infrastructure is typically the largest single category of cryptographic assets and often the most visible when it fails.
- Applications and libraries: Software with cryptography embedded in its code, libraries, and dependencies must be identified and remediated. This is frequently the longest workstream because of legacy systems and third-party software where the organization does not control the source code.
- Network infrastructure: Protocols, VPNs, load balancers, and the cryptographic configurations across network devices all need to migrate, typically while maintaining interoperability with systems that have not yet transitioned. Hybrid cryptography, combining a classical algorithm with a post-quantum one, is the mechanism that makes this interoperability period manageable.
- Data protection: Long-lived sensitive data must be prioritized early against both HNDL and TNFL, including data already at rest and long-lived signing keys. HNDL means that already-collected encrypted data is at risk; waiting for migration to be complete before addressing this category is not safe.
- Vendors and supply chain: The G7 CEG Roadmap explicitly flags smaller firms reliant on third-party technology providers as particularly at risk, because weaknesses in shared cloud platforms or software libraries ripple across the ecosystem. PQC roadmap requirements should become part of vendor due diligence and contract language now.
- Governance: Executive sponsorship, a cross-functional working group, a quantum risk entry on the enterprise risk register, and sustained multi-year funding are essential. Without governance, programs stall when organizational priorities shift. The G7’s emphasis on senior leadership engagement is not incidental; it reflects the practical reality that PQC migration cannot be sustained as a purely technical program.
Hybrid Cryptography and the Transition Period
The transition to post-quantum algorithms will not happen overnight across an enterprise estate or an industry ecosystem. For an extended period, classical and post-quantum algorithms must coexist. Hybrid cryptography, combining a classical algorithm such as ECDH with a post-quantum algorithm such as ML-KEM, so the connection remains secure as long as either holds, is the leading strategy for this period.
NIST IR 8547 explicitly supports hybrid modes during the transition. The 2035 disallowance of quantum-vulnerable classical algorithms is not intended to prohibit hybrid schemes that incorporate an approved post-quantum algorithm alongside a classical one. This provides organizations a compliant path to deploy post-quantum protection immediately while retaining backward compatibility with partners and systems still operating on classical algorithms.
A worked example: a financial institution running TLS 1.3 today can configure its servers to offer X25519Kyber768 (a hybrid key exchange combining X25519 and ML-KEM-768) alongside standard X25519. Clients that support the hybrid mode use it and gain post-quantum protection. Clients that do not support it fall back to standard X25519. No service disruption occurs, and the institution begins accumulating post-quantum protection for new sessions immediately, reducing the HNDL exposure window for current traffic even before the full migration is complete.
Cryptographic discovery and inventory must be treated as an effectively permanent program, not a project with an end date. The G7 CEG Roadmap explicitly notes that the post-quantum transition will certainly not be the last cryptographic migration required. Crypto-agility, the ability to discover, swap, and govern cryptographic algorithms as a managed operational layer, is the enduring capability that makes future transitions survivable.
What the G7 Guidance Does Not Do
Understanding the limits of these documents is as important as understanding their weight.
- Neither document sets binding regulation: The G7 CEG Roadmap explicitly states it does not set guidance or regulatory expectations. The QTWG report is non-prescriptive. Their significance is institutional signaling and the vocabulary they give to supervisors, boards, and counterparties, not direct legal obligation.
- The CRQC timeline remains uncertain: Both documents acknowledge uncertainty about when a cryptographically relevant quantum computer will arrive. Mosca’s Inequality shows why this uncertainty does not reduce urgency, but organizations should calibrate their data classification to actual confidentiality horizons rather than assuming worst-case timelines for all data.
- The financial sector focus does not mean the guidance does not apply elsewhere: The CEG Roadmap addresses the financial sector specifically. However, NIST IR 8547’s deprecation timeline (2030-2035) applies to all organizations using NIST-endorsed algorithms, and HNDL and TNFL threats are not sector-specific.
- Algorithm selection is the smallest part of the problem: NIST has finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). The algorithm question is settled. The hard work is discovery, migration coordination, vendor management, and sustained governance across a timeline measured in years, not the choice of which algorithm to adopt.
How Encryption Consulting Can Help
The G7 documents make the destination clear. The practical challenge is building the path to get there across an organization’s full cryptographic estate, not just the visible parts.
- CBOM Secure: The first gate is visibility. CBOM Secure scans your environment to identify every cryptographic asset including certificates, keys, algorithms, and protocols, flags those using quantum-vulnerable algorithms (RSA, ECDSA, ECDH), and produces the Cryptographic Bill of Materials that all migration planning depends on. Explore CBOM Secure.
- PQC Advisory Services: Encryption Consulting’s nine-phase PQC Advisory program addresses governance, risk-based roadmaps, data classification by confidentiality lifespan, HNDL and TNFL exposure assessment, and hybrid implementation design. This is the program structure that turns a daunting multi-year mandate into a managed workstream.
- CertSecure Manager: CertSecure Manager delivers the certificate lifecycle automation that makes large-scale PKI migration possible, covering discovery, issuance, renewal, and policy enforcement across the full certificate estate.
- PKI as a Service: PKI as a Service provides a modern, crypto-agile certificate authority without vendor lock-in, designed to support algorithm transitions as ML-DSA and hybrid certificate profiles become standard.
- HSM as a Service: HSM as a Service ensures keys are protected with high-assurance, FIPS 140-3 validated hardware isolation as algorithms transition, providing the root of trust the migration depends on.
Whether you are responding to regulatory signals, briefing your board on quantum risk, or ready to begin cryptographic discovery, contact Encryption Consulting to start building your quantum migration program.
Conclusion
The G7’s 2026 publications are significant not because they reveal a new threat, but because of who is sounding the alarm and how clearly. When central banks and finance ministries document quantum risk as an operational priority, flag both HNDL and TNFL as active concerns, and set a coordinated 2030-2035 migration window that aligns with NIST IR 8547, the era of treating post-quantum migration as a distant technical curiosity is over.
The math is unforgiving. Mosca’s Inequality shows that an organization whose data has a ten-year confidentiality horizon and whose migration will take seven years needs to have started already, regardless of when a CRQC arrives. HNDL means the data being encrypted today is already being collected. The regulatory windows are closing: deprecated after 2030, disallowed after 2035, and NSA-mandated for national security system software signing from 2027.
The path forward is well understood: gain visibility into your cryptographic landscape through a CBOM, build governance and a risk-based roadmap, deploy crypto-agility through automation, and address both confidentiality and integrity threats in parallel. The only decision left is whether to begin now, while time is still an asset, or later, when it has become a liability.
Frequently Asked Questions
What are the two G7 PQC documents published in 2026?
The G7 Cyber Expert Group (CEG) Roadmap (January 13, 2026, co-chaired by U.S. Treasury and Bank of England) provides a coordinated migration framework for the financial sector with a 2030-2035 window. The G7 Quantum Technologies Working Group (QTWG) Report (May 2026, co-chaired by Banque de France and Bank of Canada) takes a wider view covering quantum computing applications, quantum sensing, and cryptographic security together. Neither sets binding regulation, but together they establish PQC migration as a systemic risk management issue.
What is Harvest Now, Decrypt Later (HNDL) and why does the G7 flag it?
HNDL is the adversarial strategy of collecting encrypted data today and decrypting it once a quantum computer is available. Both G7 documents name it as an active threat already underway. Any sensitive data encrypted today with RSA, ECDSA, or ECDH that must stay confidential for more than five to ten years is at risk from HNDL regardless of when a CRQC arrives.
What is Trust Now, Forge Later (TNFL)?
TNFL is the integrity counterpart to HNDL. A quantum computer could derive a private key from today’s public digital signatures, enabling retroactive forgery of financial transactions, signed contracts, or software updates. The G7 QTWG report flags TNFL as potentially more disruptive than HNDL for financial infrastructure where non-repudiation is foundational.
What are the NIST PQC migration deadlines?
NIST IR 8547 (Initial Public Draft, November 2024) proposes deprecating RSA, ECDSA, ECDH, and finite-field Diffie-Hellman after 2030 and disallowing them after 2035. NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) in August 2024. For U.S. National Security Systems, NSA CNSA 2.0 requires quantum-resistant algorithms for new software and firmware signing acquisitions from January 1, 2027.
Does the G7 PQC guidance apply outside the financial sector?
Yes. The underlying threats (HNDL, TNFL) and NIST IR 8547’s deprecation timeline apply to every enterprise using RSA, ECDSA, or ECDH. Organizations in healthcare, manufacturing, critical infrastructure, and technology face the same quantum risk. Financial sector G7 guidance also consistently precedes broader regulatory expectations across sectors.
What is Mosca’s Inequality?
Mosca’s Inequality, formulated by cryptographer Dr. Michele Mosca, states: if the time data must stay confidential (X) plus your migration timeline (Y) exceeds the years until a CRQC arrives (Z), you already have a problem. Applied practically: if sensitive data has a ten-year confidentiality horizon and migration takes seven years, an organization must start migration now regardless of whether a CRQC exists today.
- Quick Answer: Why Does the G7's PQC Warning Matter to Enterprises?
- The Two G7 Documents: What Each One Says
- Why This Guidance Changes the Conversation
- The Uncomfortable Math: Why Migration Takes Longer Than the Threat Allows
- Enterprise Decision Table: How to Prioritize Your PQC Program
- Migration Is an Operational Program, Not an Algorithm Swap
- Hybrid Cryptography and the Transition Period
- What the G7 Guidance Does Not Do
- How Encryption Consulting Can Help
- Conclusion
- Frequently Asked Questions
