Europe’s leading law enforcement agency and the US government’s spending watchdog have both released reports this week urging organizations to accelerate their post-quantum cryptography (PQC) push.
Consensus on when cryptographically relevant quantum computers (CRQCs) will emerge is divided. But when “Q-day” happens, these machines will be able to crack the crypto on which most government and corporate cybersecurity depend.
In March, Google predicted that the date could be as soon as 2029.
The US GAO said it has already made 89 recommendations to 23 agencies to develop inventories of vulnerable cryptography and identify funding for PQC, among other things.
The report published on October 6 is a redacted version of that document, first sent to these government agencies in September 2025, it claimed.
Read more on quantum computing: CISA Releases List of Post-Quantum Cryptography Product Categories.
The GAP said it wants federal government agencies to address three core areas:
- Develop prioritized inventory of vulnerable cryptography
- Identify PQC funding needs
- Test PQC
However, none of the 24 agencies cited in the report have fully addressed all three, it noted.
“The incomplete implementation of these practices is due in part to a lack of (1) cryptography expertise, (2) processes for developing cryptography inventories and identifying funding needed to transition to post-quantum cryptography, and (3) plans to guide post-quantum cryptography testing,” it continued.
“Until the selected agencies address these weaknesses, they will not be well-positioned to address the threat of CRQCs to cryptography that agencies rely on to protect sensitive information.”
On the other side of the Atlantic, Europol published two reports on quantum on October 7.
The first assessed how encrypted communications and stored files could become vulnerable to harvest now decrypt later (HNDL) attacks, which some governments are already rumored to be conducting.
It claimed that the extent of an organization’s exposure depends on the protocols, configurations and key management practices it’s using.
A second study warned of the quantum threat to cryptocurrency wallets.
“Cryptocurrencies will not collapse due to quantum computing, but their long-term security requires proactive defence,” it noted. “By embracing innovation, fostering collaboration and prioritising a phased transition to quantum-resistant cryptography, the cryptocurrency ecosystem can build a safer, more resilient and trustworthy future.”
Organizations Urged to Take Action Today
Europol urged organizations to mitigate the HNDL threat by upgrading to TLS 1.3 and SSH2, disabling legacy protocols and enforcing forward secrecy as soon as possible. They should also identify and delete any unnecessary sensitive data to limit long-term storage, it added.
Finally, organizations should explore options for adopting PQC, including hybrid approaches, as they become available.
For the cryptocurrency ecosystem, Europol urged blockchain projects to prioritize integration of PQC algorithms into core protocols and share resources with wallet providers so they can implement these changes.
For the wallet providers, it recommended testing and deploying PQC-enabled wallets and educating users about the risks of CRQCs.
