The G7 wants every business on the planet to start planning for a future where today's encryption no longer holds.
The G7 issued guidance urging governments and organizations to begin transitioning to post-quantum cryptography (PQC) now, rather than waiting for a cryptographically relevant quantum computer (CRQC) to show up. The advice: inventory your cryptographic assets, prioritize critical systems, map dependencies, and build a phased, risk-based migration plan. To limit costs, the guidance suggests buying products that already support PQC and swapping in quantum-safe systems as part of normal renewal cycles, rather than a costly rip-and-replace. The G7 also warns that laggards risk more than a future breach: they could lose contracts, including government procurement, once buyers start requiring quantum-safe systems.
Here's the nuance the warning glosses over. The real risk isn't AES, the algorithm protecting your bank transfers, which survives quantum attacks reasonably well with a longer key. The actual casualty is public-key cryptography, RSA and ECC, the systems that set up those encrypted connections in the first place. A sufficiently powerful quantum computer could break that outright using Shor's algorithm, while only weakening AES. Businesses chasing 'quantum-safe AES' are solving the wrong problem while the handshake protecting their data stays exposed.
No one knows exactly when a cryptographically relevant quantum computer will exist, but harvest-now-decrypt-later attacks mean data intercepted today could be unlocked years from now. That's what makes the G7's timeline pressure less hypothetical and more actuarial.