ASD/ACSC have updated their Guidance to Planning for Post-Quantum Cryptography.
Organisations should prioritise the protection of their information technology (IT) environment against the threat of a cryptographically relevant quantum computer (CRQC) now, even though a CRQC may not exist for some time. Early action is crucial because:
- deploying protections against a CRQC may take longer than expected
- estimating the timeline to achieve a CRQC is uncertain as quantum computing is an active area of research
- storing highly sensitive or classified data using classical encryption methods may be vulnerable to ‘harvest now, decrypt later’ attacks.
Read more
Document
Planning for Post-Quantum CryPlanning for post-quantum cryptography (September 2025)ptography –
