CISA and the G7 just told the world's governments and companies: start swapping out your encryption, or a future quantum computer will read your secrets retroactively.
CISA and the G7 Cyber Security Working Group published "Preparing for the Post-Quantum Era: A Call to Action," urging organizations to begin transitioning to post-quantum cryptography (PQC). The document lays out five priorities: raising awareness of quantum risk, building national PQC strategies, funding research into quantum-safe technology, fostering public-private partnerships, and folding PQC requirements into procurement rules. It's a coordination document, not a mandate - there's no deadline attached, no funding, and no single technical standard beyond "start now."
The risk here isn't that quantum computers can break today's encryption - they can't, yet. It's "harvest now, decrypt later": adversaries can already be siphoning encrypted traffic today to crack open once sufficiently powerful quantum hardware exists, possibly years from now. That makes this advisory a slow-motion warning aimed at anyone holding long-lived sensitive data - health records, state secrets, trade secrets - where "eventually decrypted" is still a real problem.
Call it the security world's version of "eat better, exercise more": sound advice, thin on specifics, and easy to shelve until a compliance deadline forces the issue.