TL;DR: As governments, regulators, and analysts push post-quantum cryptography timelines toward 2030, organisations are being forced to redesign encryption across existing networks rather than waiting for cryptographically relevant quantum computers to arrive, according to SSH Communications Security. The strategic issue is crypto-agility, because migration paths that preserve compatibility while reducing future decryption risk will determine how quickly security teams can move.
NHIMG editorial — based on content published by SSH Communications Security: quantum-safe encryption and post-quantum cryptography migration
By the numbers:
- Key industries such as finance, healthcare, telecommunications, and critical infrastructure are expected to have completed the PQC transition by 2030.
Questions worth separating out
A: Start with the links that carry long-lived sensitive data and high-value administrative traffic, then use hybrid cryptography where classical and post-quantum methods can coexist.
Q: Why do quantum-safe encryption projects matter to IAM and NHI teams?
A: Because identity assurance depends on the confidentiality and integrity of the sessions that carry authentication, delegation, and service-to-service trust.
Q: What breaks if organisations delay crypto-agility until quantum computing is mature?
A: Fixed cryptographic dependencies become a governance problem because systems, devices, and applications will still need to support multiple algorithms during migration.
Practitioner guidance
- Inventory long-confidentiality traffic paths Identify the data flows that must remain confidential for years, including intellectual property, regulated records, and privileged machine communications, then rank them for PQC migration first.
- Prioritise hybrid cryptography for transition zones Use hybrid exchanges where classical and post-quantum algorithms can operate together, especially on links that must stay compatible with current infrastructure while standards stabilise.
- Test encryption throughput before broad rollout Measure latency, port density, and encrypted throughput under realistic east-west and routed traffic loads so performance limits do not force exceptions later.
What's in the full article
SSH Communications Security's full article covers the operational detail this post intentionally leaves for the source:
- Hybrid cryptography examples using ML-KEM, FrodoKEM, ECDH, and FFDHE in the same exchange.
- How to think about Layer 2 and Layer 3 encryption placement across data centres, branches, and routed networks.
- The performance implications of 100-gigabit interfaces, latency, and high port density for PQC rollout.
- Why crypto-agility matters when software upgrades must preserve compatibility across mixed infrastructure.
👉 Read SSH Communications Security's analysis of quantum-safe encryption and PQC migration →
Quantum-safe encryption and PQC migration: what IAM teams need now?
Explore further
Quantum-safe encryption is becoming an identity problem, not just a cryptography problem. Network encryption protects the channels that carry authentication, delegation, and machine-to-machine trust, so PQC migration changes the reliability of the identity fabric beneath them. When transport security becomes crypto-agile, identity teams have to treat encryption as part of access assurance rather than a separate infrastructure layer. The implication is that IAM, PAM, and NHI programmes now depend on cryptographic transition planning.
A few things that frame the scale:
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures.
A question worth separating out:
Q: How do security teams decide between Layer 2 and Layer 3 encryption?
A: Use Layer 2 for high-speed, low-latency traffic inside data centres or between nearby sites, and Layer 3 for routed traffic that crosses networks and the internet. Many environments need both. The right choice follows the traffic path, latency budget, and segmentation requirement, not a one-size-fits-all standard.
👉 Read our full editorial: Quantum-safe encryption shifts from theory to network design reality