The Quantum Leap: Preparing for Post Quantum Cryptography Featuring Futurex

Welcome to the PCI Security Standards Council’s blog series, The Quantum Leap: Preparing for Post Quantum Cryptography. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to share information about how they are taking steps to ensure their systems are crypto-agile into the future.
Quantum computers are computing systems that operate in very different ways to classical computers, using quantum bits (or ‘qubits’) rather than the classical ‘bits’ of an existing computer. Quantum computing threatens some forms of cryptography, as it allows for operations that are not possible with traditional computing systems and therefore were not considered threats when creating traditional encryption algorithms. As continual progress is being made on quantum computers, it is generally expected to be only a matter of time before ‘cryptographically relevant quantum computers’ (CRQC) can be used to attack some of the widely deployed cryptographic systems used today.
In this edition of The Quantum Leap, Futurex Vice President, Global and Strategic Alliances, Adam Cason, offers insight into how his company is preparing for migration to post-quantum cryptography, the challenges our industry faces, and advice for maintaining strong cryptography practices to protect the future of payment security.
What steps is your organization taking to prepare for migration to post-quantum cryptography? If it is too soon yet to address within your environment, what will the catalyst be for action?
As an HSM manufacturer, the PQC world has been front-and-center for Futurex for years. We first released our PQC-enabled firmware (general availability, not just a beta program) in August of 2024 as soon as NIST ratified FIPS 203, 204, and 205. As NIST has moved toward the likely ratification of Falcon as FIPS 206/FN-DSA, we have proactively implemented that algorithm as well.
Our philosophy around PQC centers around two principles:
- Organizations wishing to implement PQC ahead of any industry shifts or mandates should have the ability to easily do so, while not limiting their ability to continue using classical algorithms like RSA and ECC.
- Cryptographic agility is crucial (and of all industries, I think the payments industry has a greater appreciation for this than most!). The shift to post-quantum algorithms is not the last cryptographic transition we will see. Well-prepared organizations are treating this as an opportunity to mature their overall processes, not just switching to a new set of algorithms.
What kind of previous impactful technological change, or business shift, would you compare to quantum computing?
Quantum computing itself will have an impact similar to the creation of the Internet or cloud computing (and perhaps the PQC transition will be most similar to Y2K?). Early adopters “get it” today and are planning accordingly, and within a few years, everyone else is going to understand why.
Especially in the payment security field, we look at quantum computing as a potentially devastating technology for organizations who don’t transition to post-quantum cryptographic algorithms in time. Key exchange, communication, digital signatures, and numerous other methods of establishing digital trust could be broken.
What we often overlook, however, are the areas where we could see tremendous advances in technology as a result of quantum computing. Medicine development, chemical and materials simulation, financial modeling, and so much more.
I’m an optimist, and despite the cryptanalytic risks of quantum computing, I’m excited to see all the great things it may bring to our society.
What aspect of migrating to post-quantum cryptography do you see as being the most challenging?
I’ll cheat at my response to this question and give you two, instead of just a single aspect that I see as being most challenging:
-
PQC readiness, and the process by which an organization can identify which data, objects, and cryptographic libraries require migration. This can be addressed with various tools and solutions, but the most important part is getting organizational buy-in. Migration to post-quantum cryptography is an effort that spans virtually all business units in tech-centric organizations, and they need to have a centralized strategy supported by data.
-
Interoperability. This is particularly important for the payments industry, since so much of what we do requires communication between multiple entities. If any one link in the chain didn’t meet PQC transition timelines, the ability to communicate effectively will be limited, and the security risk will be increased.
For an organization that hasn’t started this effort yet – what are your initial recommendations for designing a readiness strategy?
Gather your stakeholders, make sure they understand the risks and urgency, and start planning. Work with trusted advisors who know your cryptographic ecosystem and can offer guidance. Do a deep dive into your existing environment to understand where you’re using cryptographic libraries (don’t forget to scope your cloud service providers into this) and build an inventory of cryptographic objects throughout your enterprise that could be vulnerable. These will form the foundation of your remediation and PQC readiness strategy.
How do security professionals and cryptography teams need to position the PQC-readiness needs and priorities to the C-Suite and Boardroom?
Start with the big-picture risks, outline what the industry has been doing to prepare, and present your recommended solution.
The most important thing is to give your executive stakeholders a clear view of the exposure risk and the migration lead time. And especially if you have data that today is at risk of Harvest Now, Decrypt Later attacks, where data encrypted using classical cryptography could be stored now and decrypted in the future, that needs to be actioned quickly.
Where possible, align your PQC work with your normal application, infrastructure, certificate, and hardware refresh cycles. That can help from a budgeting and logistical perspective and can make executive buy-in easier to achieve.
One last reminder as well: be careful to put your anticipated timelines in perspective! If your crystal ball is telling you that you need to complete your PQC migration by 2029, make sure your stakeholders understand the steps involved in the migration and don’t get caught in the trap of “that sounds like 2028’s problem”. This is a marathon, not a sprint!
There are a lot of different opinions on how soon it will really be necessary to complete the migration to PQC, which brings us to our poll (no wrong answers here!) – when do you think we will see RSA2048 bit demonstrably broken by a quantum computer?

For more information on strong cryptography and key management best practices, see PCI SSC’s Cryptography Guidance document, available for download in the Document Library.

