Quantum Readiness Day on 24 September is a useful reminder that the security work we do today is not only about preventing breaches tomorrow. It is about protecting data and digital trust for years to come.
As a CISO Advisor and Quantum Security Lead for the Association of Information Security Professionals (AiSP) in Singapore, I see quantum readiness as a governance and engineering program, not a single technology upgrade. The industry conversation often starts with post-quantum cryptography, but the real challenge is broader. It includes understanding what your organization must keep confidential for a long time, mapping where cryptography is embedded across systems, engaging vendors early, and building the ability to migrate cryptographic algorithms without a painful redesign.
What Quantum Readiness Day means for the industry
Quantum readiness is industry-wide because cryptography is woven into nearly every part of modern operations. It is used to secure communications, authenticate users and devices, verify software integrity, and anchor trust through certificates and signatures. As quantum computers advance, the risk shifts toward public key systems that could be broken faster than organizations can respond.
One of the most important concepts for decision makers is harvest now, decrypt later. Attackers can steal encrypted data today and keep it until they have the capability to decrypt it later. That means the “start date” for quantum risk is effectively already here, especially for data that must remain secret for a decade or more.
World Quantum Readiness Day also signals that preparation is becoming an expected part of digital security programs. Standards development, vendor roadmaps, and migration guidance are converging. The organizations that move first will not be the ones that panic. They will be the ones who execute with planning, testing, and crypto agility.
The National Institute of Standards and Technology (NIST) released its first three post-quantum cryptography standards in late 2024, and has strongly pushed for organizations to start migrating to these standards. In more recent news, NIST has just launched a center to drive the manufacture of quantum technologies, further advancing the frontier of quantum innovation.
Helpful tips to get your organization started
If you are looking for practical actions to take around 24 September, use this checklist as a starting point.
- Establish an awareness program across your organization: Build a holistic Cybersecurity awareness program and embed the cyber threats coming from quantum computing. It will take the whole organization to help enable the crypto migration strategy over the next several years.
- Take stock of your cryptographic dependencies: Build a clear inventory list of where cryptography lives in your environment. Focus on public key usage, certificates, signing processes, key management systems, and any long-lived secrets or trusted data. If you cannot see it, you cannot migrate it.
- Prioritize long-lived, high-value data and trust anchors: Not every system needs the same level of urgency. Rank what matters by confidentiality lifespan, impact if exposed, and role in trust. Root trust elements, firmware for long-lived devices, and systems that underpin identity and software integrity usually deserve early attention.
- Create a quantum readiness roadmap with owners and milestones: A roadmap should include timelines, dependencies, and responsible teams. It should also define what “done” means, such as completion of pilots, adoption of specific standards where applicable, and integration into certificate and signing workflows.
- Start pilot testing and interoperability checks: Post-quantum and hybrid approaches can introduce performance, latency, and operational changes. Test in controlled environments first. Measure interoperability with existing infrastructure and confirm that the operational model supports roll out, monitoring, and troubleshooting.
- Build crypto agility: Crypto agility is the ability to swap algorithms, keys, certificates, and protocols without rebuilding everything from scratch. Make it a design requirement for new systems and a modernization target for older ones. This is one of the highest-leverage capabilities you can build, because it reduces the cost of every future cryptographic change.
- Engage vendors now and get clarity: Procurement and security teams should ask vendors about their post-quantum roadmaps, support for emerging standards, and how migration will be handled across product lifecycles. Vendor readiness directly impacts your ability to protect customer and organizational data.
- Train your teams on the operational implications: Quantum readiness is not only for cryptographers. Engineering, identity teams, PKI administrators, architects, and compliance stakeholders all need a shared understanding of what will change, why it matters, and how migration will be coordinated.
Turning awareness into action
Quantum Readiness Day should not be the final step. It should be the prompt that moves your program from discussion to execution. If you start with inventory, prioritize high-impact systems, pilot safely, and build crypto agility, you will be better prepared for whatever timeline reality brings.
And just like any other security milestone, progress is measured by execution quality, not by announcements.
