
























The shift to Post-Quantum Cryptography (PQC) is no longer just an academic topic. It is now a key focus in areas such as security, architecture, procurement, and compliance.
The White House Executive Order “Securing the Nation Against Advanced Cryptographic Attacks” marks an important step in the federal government’s transition to PQC. It establishes December 31, 2030, as the deadline for federal high-value assets and high-impact systems to use PQC for key establishment, followed by December 31, 2031, deadline for their transition to PQC digital signatures.
The order also initiates a separate rulemaking process for federal contractors. It directs the Federal Acquisition Regulatory Council to publish a proposed rule amending the Federal Acquisition Regulation that would require covered federal contractors, by December 31, 2030, to comply with applicable NIST Federal Information Processing Standards, including standards that incorporate PQC algorithms.
While these requirements are primarily aimed at federal agencies and contractors, their effects are expected to extend across critical infrastructure, technology providers, regulated industries and the broader federal supply chain. For many organizations, 2026 and 2027 should therefore be treated as critical planning years for establishing ownership, inventorying cryptographic dependencies, assessing vendors, incorporating PQC requirements into procurement decisions, and developing migration roadmaps ahead of the principal 2030 and 2031 implementation deadlines.
This does not imply that organizations must replace every cryptographic algorithm immediately. The shift to PQC will take several years. The urgent focus should be on practical steps: increasing visibility, assessing risks, enhancing crypto-agility, and targeting the systems most vulnerable to “harvest now, decrypt later” (HNDL) threats.
Industry experts warn that adversaries with quantum capabilities may eventually compromise widely used public-key cryptography, which underpins today’s digital communications. This poses an immediate risk, since encrypted data collected now could be decrypted in the future as quantum technology advances.
Organizations face the challenge of not just replacing cryptography but also ensuring operational readiness. Security and infrastructure teams must identify where cryptography is employed, determine which systems safeguard long-term sensitive data, and evaluate vendors, technologies, and architectures capable of supporting a future transition to quantum-safe standards.
Answering these questions requires a structured approach that integrates security visibility, risk reporting, and protection for the most critical encrypted pathways.
Organizations cannot manage cryptographic risk without visibility. The first step is to identify where cryptography is used across their managed infrastructure, applications, devices, certificates, protocols, and encrypted communications.
This discovery process should identify unsafe or legacy algorithms, systems dependent on aging cryptographic components, and high-value services needing urgent remediation. It should also assist security teams in understanding where cryptographic decisions are embedded in configurations, vendor products, or application architectures.
FortiManager with FortiAI-Assist helps teams develop cryptographic inventory checklists, review configurations of managed Fortinet devices, and detect the usage of unsafe or outdated cryptographic algorithms. This offers security teams a practical foundation for understanding cryptographic vulnerabilities and developing an actionable plan for remediation.
FortiManager can then help organizations translate that plan into consistent action across a large FortiGate fleet. Rather than updating devices individually, teams can centrally standardize and deploy PQC-related configurations, policy changes, and broader configuration optimizations at scale. This centralized approach can also support complex initiatives such as SD-WAN migrations, helping organizations reduce configuration drift, improve operational consistency, and manage cryptographic modernization more efficiently.
After organizations determine their cryptographic exposure, they need a way to assess risk and track improvements. Executives, security leaders, compliance teams, and infrastructure managers must have a common understanding of where risks are, which systems face the greatest exposure, and how remediation efforts develop over time.
This report should emphasize practical business and security concerns, such as unsafe algorithms, externally accessible systems, high-value applications, and the implementation of quantum-safe methods when applicable. Clear reporting can also assist organizations with procurement decisions, vendor discussions, and communication with the board.
FortiAnalyzer monitors unsafe algorithm usage in web and application traffic and offers visibility into the adoption of quantum-safe algorithms when applicable. This enables security teams to assess cryptographic risks, pinpoint high-priority applications, and demonstrate progress to leadership through measurable metrics.
Not all cryptographic risks carry the same urgency. Organizations should focus on encrypting traffic and systems that are most vulnerable to untrusted networks, such as site-to-site connections, partner communication channels, branch networks, remote access points, cloud integrations, and data center interconnections.
These external pathways are especially crucial since they frequently handle sensitive business, operational, or regulated information outside trusted environments. They can also be more exposed to interception and prolonged collection by advanced adversaries. A boundary-first approach helps organizations reduce HNDL exposure while broader cryptographic modernization continues.
The FortiGate IPsec hardware acceleration enables organizations to secure external boundaries and vital encrypted tunnels. This focus allows prioritizing protection for high-value communications, leaving trusted networks and minimizing long-term risks by reducing encrypted traffic that could be captured and stored now and later decrypted.
Transitioning to PQC does not have to begin with a large-scale transformation program. Organizations can initiate a targeted readiness sprint to establish ownership, increase visibility, and pinpoint immediate priorities.
Gather stakeholders from security, architecture, infrastructure, procurement, legal, compliance, and risk management teams. Since PQC readiness impacts technology choices, vendor relations, regulatory standing, and long-term data protection, responsibility should be shared across multiple teams.
Outcome: Clear ownership plus cross-functional accountability
Identify the use of cryptography throughout infrastructure, applications, certificates, protocols, keys, VPNs, web services, and third-party dependencies. This inventory should separate systems that safeguard short-term data from those protecting long-term or high-value information.
Outcome: Improved visibility into algorithms, certificates, protocols, keys, and crypto dependencies
Begin your initial planning by focusing on systems most vulnerable to HNDL threats. This includes encrypted communications over untrusted networks, systems managing sensitive or regulated data, and essential services with long-term operational needs.
Outcome: An initial roadmap for remediation, vendor engagement, and PQC migration planning
Quantum migration is not a one-time upgrade or a matter of deploying a single PQC algorithm and moving on. As standards mature, organizations may need to adopt different algorithms for different use cases, including key exchange, digital signatures, device identity, VPNs, TLS, and code signing.
Each option may also introduce different operational and performance considerations, such as larger keys, bigger handshakes, increased CPU or memory requirements, and added latency. The right approach may therefore vary by application, device, connection, and business requirement.
Organizations should build toward crypto-agility: the ability to update algorithms, certificates, policies, and supporting infrastructure over time as standards evolve, interoperability improves, and performance requirements become clearer. This flexibility will be essential to managing PQC as an ongoing operational discipline rather than a one-time technology replacement.
The Fortinet Security Fabric assists organizations in transitioning from policy awareness to operational execution through a practical readiness framework.
Discover → Measure → Protect → Modernize
This approach encourages organizations to view PQC not as a one-time replacement project but as a continuous operational practice. It involves understanding cryptography usage, assessing exposure, focusing on the riskiest areas, and developing adaptable architectures that can evolve with changing requirements.
The transition to post-quantum security will probably span years. However, organizations should not wait until quantum threats create compliance or operational crises. The most prepared organizations for the upcoming cryptographic security challenges will be those that identify where cryptography is employed, assess their level of exposure, and focus their protection efforts on their most vital systems and data.
Fortinet assists organizations in taking the first practical steps toward PQC readiness by identifying vulnerable cryptography, reporting potential exposure, and safeguarding essential encrypted connections. Transitioning from awareness to action now enables organizations to develop the visibility, resilience, and crypto-flexibility necessary for the coming quantum era.
Watch our on demand webinar in which we explore how enterprises can address quantum risk and begin the shift to quantum‑resilient security.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。