Complimentary Gartner® Research

Update Postquantum Cryptography in 3 Waves

Thomas Lintemuth · Published 7 June 2026 · ID G00844819

A quantum computer capable of breaking today's public-key cryptography could arrive as early as 2029, and NIST has already set a hard deadline for retiring classical algorithms. This Gartner report gives cybersecurity leaders a three-wave sequence for the migration, built on a cryptographic inventory as the starting point, so you can prioritize the work instead of boiling the ocean.

Cover of the Gartner report Update Postquantum Cryptography in 3 Waves

Get the report

Complete the form for instant access, courtesy of Axiad.

 

By submitting, you agree to Axiad's Privacy Policy. We'll never share your information with third parties.

Three waves, one starting point

The migration begins with an inventory of every cryptographic asset in your environment: algorithms, keys, certificates, cipher suites, and protocols. From that foundation, Gartner sequences the work into three waves ordered by urgency and by what's actually deployable today.

WAVE 1

Encryption and key exchange

The most pressing risk. Harvest-now-decrypt-later attacks make today's key exchange an immediate exposure, and quantum-resistant options are ready to deploy now.

WAVE 2

Public-key infrastructure

The foundation underneath everything else. Certificate authorities, cryptographic libraries, and HSMs all need upgrades before they can issue and validate quantum-safe certificates.

WAVE 3

Digital signatures

Just as critical, but not yet drop-in ready for most production environments. The play here is testing now so you're ready to move when the standards settle.

What you'll take away

Which algorithms, and when

Guidance on the NIST-approved quantum-resistant algorithms available today, where each fits, and which are ready for production versus testing.

Where the risk is live now

Why key exchange is an immediate exposure even before a quantum computer exists, and how to assess which systems and data face the most harvest-now-decrypt-later risk.

What it takes beyond software

The hardware and infrastructure implications most plans miss, from HSM capacity to the network devices and firmware that need compatibility review.

Get the Gartner Report

Want a data point on where you stand today?

The free Axiad PQC Readiness Tester checks whether your domain supports quantum-safe key exchange. It takes about 30 seconds and requires nothing but a domain name.

Test Your Domain