Quantum readiness
Move your encryption to post-quantum standards
Quantum computers are expected to break the public-key encryption most systems rely on today, such as RSA and elliptic-curve cryptography. Quantum readiness means finding where your company uses it and moving to post-quantum standards before the deadlines, and attackers, catch up.
Why act before quantum computers arrive?
Attackers can copy encrypted data today and decrypt it once a capable quantum computer exists. Security teams call this harvest now, decrypt later. Contracts, health records, financial data and designs that must stay confidential for years are already exposed.
Moving to new encryption takes years. It touches websites, VPNs, email, databases, payment links, hardware and every vendor in between. That's why regulators have started setting dates, and why Singapore has said post-quantum cryptography will be the mainstream route for quantum-safe migration.
Is your data already exposed?
Security researchers use a simple test, known as Mosca's theorem. Add how long your data must stay secret to how long your move will take. If that's longer than the time until a quantum computer can break today's encryption, some of your data is already exposed.
Think contracts, health and financial records, designs and personal data.
Include your vendors. Large companies often plan for several years.
Nobody knows for sure, and estimates vary. Regulators are already setting deadlines from 2030.
Exposed for 4 years
Your data needs 10 years of secrecy and your move takes 4 years: 14 years in all. If a quantum computer arrives in 10 years, data you encrypt today could be read during the last 4 years it should stay secret.
- Moving to new encryption
- Data must stay secret
- Exposed
Key dates
- August 2024
NIST publishes the first post-quantum standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).
- October 2025
CSA releases its Quantum-Safe Handbook and Quantum Readiness Index, developed with GovTech, IMDA and industry.
- March 2026
Singapore confirms post-quantum cryptography as the mainstream route for quantum-safe migration.
- July 2026
MAS says it aims for financial institutions to be quantum resilient before the end of the decade.
- By 2030
MAS aims for financial institutions to be quantum resilient. NIST's draft transition plan deprecates RSA-2048 and similar algorithms.
- By 2035
NIST's draft plan disallows quantum-vulnerable public-key algorithms altogether.
NIST's transition plan (IR 8547) was published as a draft in November 2024.
Who should start now
- Banks, insurers and payment firms working to MAS's 2030 target
- Suppliers to financial institutions, CII owners and government
- Healthcare, legal and professional firms holding long-lived confidential data
- Manufacturers with devices or equipment in the field for ten years or more
- Anyone signing multi-year technology contracts now
How we get you there
Weeks 1 to 4
Inventory
Find every place you use public-key encryption: websites, VPNs, email, databases, payment links, code signing, devices and vendor services.
Weeks 4 to 6
Prioritise
Rank systems by how long their data must stay secret and how hard they are to change. Score where you stand with CSA's Quantum Readiness Index.
Weeks 6 to 8
Plan
Set a migration roadmap and budget, add crypto-agility to new purchases, and agree timelines with vendors.
Ongoing
Migrate
Pilot post-quantum options on priority systems, then roll out in waves with your IT team and vendors.
What you receive
- Cryptographic inventory of your systems and vendors
- Quantum Readiness Index score and priorities
- Register of long-lived sensitive data
- Migration roadmap and budget
- Vendor questions and contract wording for crypto-agility
- Board briefing on quantum risk
Ways to engage
Readiness assessment
Inventory, readiness score, priorities and a costed roadmap.
Best as a first step for most companies.
Migration oversight
A senior lead runs the migration with your IT team and vendors.
Best once the roadmap is agreed.
Leadership briefing
What quantum risk means for your company, and the decisions you need to make.
Best for boards and leadership teams.
Questions about quantum readiness
Can quantum computers break encryption today?
Not as far as anyone has shown publicly. But data stolen now can be decrypted later, and migration takes years, so planning has to start well before that point.
What is post-quantum cryptography?
Encryption designed to resist attacks from quantum computers while running on ordinary computers. NIST published the first standards in August 2024.
Do we have to replace our systems?
Usually not. Most changes arrive as updates from vendors. The work is knowing where encryption is used, which systems matter most, and holding vendors to a timeline.
We're not a bank. Does this apply to us?
MAS's target applies to financial institutions, but they pass requirements down to their suppliers, and NIST's 2030 and 2035 dates shape the products everyone buys.
How does this connect to the Cyber Trust mark?
Both rest on knowing your systems and managing risk. A cryptographic inventory strengthens the asset management and data protection work the Cyber Trust mark already asks for.
Pairs well with
Talk to us about quantum readiness
A 30-minute call to size your exposure and agree the first steps.