The Challenge
When the G7 Cyber Security Working Group and CISA issued their joint advisory urging organizations to migrate to post-quantum cryptography, they highlighted a current vulnerability that many compliance managers haven't yet addressed. Quantum computers, once powerful enough, will break asymmetric encryption algorithms like RSA, ECC, and Diffie-Hellman, which protect your data. The real challenge is justifying budget and executive attention for a control that addresses a future threat while your current SOC 2 Type II report and ISO/IEC 27001 audit focus on present-day risks.
The Environment and Constraints
Organizations face several constraints in addressing the quantum cryptography problem through standard risk treatment processes.
First, there's no established timeline. The advisory notes "the exact timeline is uncertain," making it hard to build a traditional risk assessment. ISO/IEC 27001 Clause 6.1.2 requires evaluating the likelihood and consequence of information security risks. How do you assign likelihood to an event that could happen in three years or thirty?
Second, your current cryptographic controls meet compliance requirements. Your SOC 2 report likely addresses CC6.7 (encryption of data at rest and in transit), and your ISO/IEC 27001 implementation covers Annex A 8.24 (use of cryptography). This makes it difficult to classify post-quantum migration as corrective action or risk reduction.
Third, budget cycles don't align with emerging threats. You're competing for resources against control gaps identified by auditors, regulatory requirements with enforcement dates, and system upgrades demanded by business units. "We need to replace our encryption before quantum computers exist" doesn't win budget battles against "We have three Major Nonconformities to close before recertification."
Fourth, the technical scope is vast. You're not just replacing certificates or updating a configuration file. Post-quantum cryptography affects key exchange, digital signatures, VPN tunnels, API authentication, code signing, and every system relying on public-key infrastructure.
The Recommended Approach
The G7 and CISA advisory suggests a strategy within existing compliance frameworks rather than treating quantum readiness as a separate program.
Start with asset identification tied to data classification. Identify systems that store or process information requiring long-term confidentiality. This aligns with ISO/IEC 27001 Annex A 5.12 (classification of information) and A 8.11 (data masking). You're not creating new categories; you're determining which existing data classifications need protection beyond the likely timeline for quantum threat realization.
Prioritize "systems containing their most sensitive information and critical assets." In compliance terms, this means your Annex A 8.8 (management of technical vulnerabilities) process should now include cryptographic algorithm obsolescence as a vulnerability category.
Integrate with normal upgrade cycles. Instead of funding a dedicated quantum migration project, incorporate quantum-resistant technology into routine system replacements and upgrades. This reduces cost and disruption while extending your timeline.
From a controls perspective, update your Annex A 5.37 (documented operating procedures) to require that any new system procurement or major upgrade evaluates post-quantum cryptography support. It becomes a standard criterion in your technology selection process, not an emergency retrofit.
Results and Metrics
The advisory frames the outcome in terms of risk reduction and business continuity. Organizations that begin migration now will complete the transition "cheaper and less disruptive" than those who wait.
More significantly, there's a competitive and contractual risk: companies that fail to adopt quantum-resistant technology "could lose a competitive advantage or eventually be shut out of contracts, including government procurement."
This creates a measurable compliance outcome. If you hold or pursue government contracts, quantum-resistant cryptography will likely become a contractual requirement before quantum computers pose an operational threat. The U.K.'s 2035 target for transition completion, with banking, finance, and telecommunications sectors expected as early adopters, provides a concrete planning horizon.
For organizations under ISO/IEC 27001, this transforms post-quantum cryptography from a speculative future concern into a present-day risk treatment requirement under Clause 6.1.3. The risk isn't just data compromise; it's contract exclusion and market access.
Avoiding Mistakes
The advisory implies that treating this as a future problem to be solved later will lead to compressed timelines, higher costs, and potential business impact.
Don't wait for quantum computers to become operational before beginning your migration. By then, you'll be in reactive mode, competing for limited vendor capacity and implementation resources alongside every other organization that delayed.
Also, don't treat this as purely a technical infrastructure project. Post-quantum cryptography is a risk treatment decision that should flow through your existing ISMS processes.
Takeaways for Your Team
Add cryptographic algorithm obsolescence to your risk register as a distinct risk scenario. Frame it under ISO/IEC 27001 Clause 6.1.2(c) as a risk related to "loss of confidentiality" with a likelihood that increases over time.
Update your asset inventory and data classification processes to flag systems and data types that require long-term confidentiality protection. These become your priority candidates for early migration.
Revise your technology procurement and system upgrade procedures to include post-quantum cryptography support as an evaluation criterion. This ensures new investments are quantum-resistant.
Don't wait for your auditor to ask about quantum readiness. If you're holding data that must remain confidential beyond 2030, you're already exposed to harvest-now-decrypt-later attacks. That's a present-day control gap, not a future one.



