Confidencial's architecture is crypto-agile by design. Migration to NIST-approved post-quantum algorithms requires no change to how your data is protected today, or historically. Flip the switch when you're ready.
Most PQC discussions focus on a future problem. But many organizations are overlooking the more immediate issue: sensitive enterprise data is already broadly exposed in documents, SaaS platforms, and AI workflows today. This guide is for security leaders who need practical guidance on what to do, in what order, and under what timeline.
Most PQC discussions focus on a future problem. But the more immediate issue is being systematically overlooked. These are not the same threat.
Cryptographically relevant quantum computers will be able to run Shor's algorithm and break RSA, ECDH, and ECDSA. Encrypted data harvested today will become readable.
Most enterprise unstructured data is not encrypted. Anyone who gets through the perimeter can read it. No quantum computer required. AI pipelines amplify exposure across more systems.
“It's not ‘harvest now, decrypt later.’ It's harvest now, read now. Why wait for quantum computers? If you get in today, you can already see everything.”
Karim Eldefrawy, Co-founder & CTO, ConfidencialStop waiting for permission to act. The migration takes 5–10 years. The window to start is now.
When to actDon’t upgrade what you haven’t mapped. The right sequence: inventory first, remediation second.
What to do firstThe present-day risk hidden in your AI stack. Copilots ingest plaintext which amplifies exposure.
Present riskHow to read vendor claims without getting burned. Five questions every vendor must answer.
What to askWhat regulations and auditors actually require today, sector by sector. No speculation.
What’s requiredThe most common and costly mistake is jumping to remediation before knowing what you have. The right sequence is fixed:
A CBOM is an inventory of every cryptographic dependency in your environment: algorithms in use, where they’re used, what they protect, and what breaks if they’re compromised. Without it, PQC migration planning is guesswork.
“Crypto inventory is foundational. Without it, you’re guessing. The first step is knowing what data you have and how it’s protected. Everything else depends on that.”
Karim Eldefrawy"Quantum-safe," "quantum-ready," and "quantum-resistant" are used interchangeably. They do not mean the same thing. These five questions cut through it.
Which algorithm, which implementations and libraries? Name them.
In transit only? At rest? At the content layer? TLS secures the pipe, not what’s inside it once received.
Does protection persist when data moves outside your environment, into third-party systems or AI?
Firmware update? API change? Full re-architecture? Be specific about timeline and scope.
Is the root of protection tied to an HSM or Cloud KMS? Where do the keys live?
The tells of PQC-washing: vague claims with no algorithm specifics; “ready” language with no published roadmap; protection that only applies to data in transit; no answer to what happens when data leaves the system. Vendors doing real work will name the algorithm, show where in the stack it’s applied, and be honest about what’s shipping versus still in progress.
“Quantum is a proxy for a much bigger issue: most data is not properly secured. The problem is not future decryption. The problem is present-day exposure.”
Karim EldefrawyRequirements depend on the sector. As of May 2026:
| Sector | Status | What’s required now |
|---|---|---|
Federal / Defense | Active requirement | NSA CNSA 2.0 sets specific timelines. Some systems required to support PQC by 2027. US federal systems mandate: 2035. Active planning is effectively required now. |
Financial Services | Signaling | No hard mandates yet. SEC, OCC, and FFIEC have all signaled interest. Quantum risk entering operational resilience frameworks. International jurisdictions moving faster. |
Healthcare / HIPAA | Emerging | No specific PQC requirement yet. Underlying data protection obligations apply. Quantum risk to PHI entering compliance conversations. |
Legal / Professional | Evolving | Bar ethics require “reasonable data security.” What “reasonable” means when harvest-now adversaries are active is evolving. Firms advising regulated clients increasingly held to their sectors’ standards. |
Don’t wait for infrastructure migration to complete. Data-layer protection can be deployed now, closes the present-day exposure gap, and makes you PQC-agile for whatever the quantum timeline brings.