AGP Picks
View all

G7 pushes organizations to start post-quantum cryptography planning now

2 hours ago
By AI, Created 12:51 UTC, Sep 10, 2026, AGP -

A September 3 G7 Cybersecurity Working Group call to action urges governments and organizations to begin post-quantum cryptography transition work immediately, even without a firm timeline for quantum computers. Lazarus Alliance says the priority is governance, discovery and migration ownership for long-lived sensitive data and critical systems.

Why it matters: - The G7 call shifts post-quantum readiness from a future watchlist item to an active governance issue. - Organizations with long-lived sensitive data face exposure even before cryptographically relevant quantum computers arrive, because “harvest now, decrypt later” attacks target information that must stay confidential for years. - Boards, risk teams and compliance leaders need a defensible plan now so migration can be prioritized before vendor deadlines, regulatory pressure or system dependencies slow the process.

What happened: - The G7 Cybersecurity Working Group issued a call to action on September 3 urging governments and organizations to begin transitioning toward post-quantum cryptography as soon as possible. - Lazarus Alliance responded by urging organizations to build cryptographic inventories, assign migration ownership and connect long-lived data risk to existing control programs. - The company said uncertainty about when cryptographically relevant quantum computers will arrive is not a reason to delay foundational readiness work.

The details: - The G7 publication identifies a growing threat to widely used public-key cryptography and calls for coordinated action across public and private organizations. - Independent reporting highlighted the risk from “harvest now, decrypt later” activity, where encrypted data is collected today for possible future decryption. - A readiness program should start with discovery across applications, infrastructure, certificates, identity systems, data exchanges and third-party services. - Organizations should classify assets by business criticality and confidentiality life, then document dependencies that could constrain migration. - NIST has already published principal post-quantum standards, but implementation still requires architecture review, testing, change control and proof that new configurations work as intended. - Lazarus Alliance says boards and risk committees should treat the transition as a governed portfolio, not a one-time technology purchase. - The company recommends clear ownership, risk acceptance criteria, supplier engagement, funding checkpoints and records of approved sequencing. - Lazarus Alliance says those controls help connect a long-horizon technical issue to cybersecurity, privacy and compliance programs. - Michael Peters, CEO and founder of Lazarus Alliance, said the first useful post-quantum deliverable is an evidence-backed map of where cryptography protects the organization’s most durable secrets and critical trust relationships. - Peters said that map helps leaders prioritize migration, challenge vendor assumptions and make decisions that can stand up to audit and board scrutiny. - Lazarus Alliance offers cybersecurity and privacy risk assessment, policy and governance support, control mapping, evidence development and remediation roadmaps through its Cybervisor® advisory services. - The firm says those services can help organizations establish ownership, decision criteria and review cadence for multi-year security transformations, including post-quantum readiness.

Between the lines: - The announcement is as much about governance discipline as it is about cryptography. - Organizations that can quickly inventory where encryption is used will have an advantage when standards, vendor products and migration timelines start to harden. - The G7 message suggests quantum readiness should be handled like other enterprise risk programs: measured, documented and tied to decision rights. - Lazarus Alliance is positioning post-quantum planning as part of broader cybersecurity and compliance management, not a separate technical project.

What's next: - Organizations are expected to assess where post-quantum transition applies across their environments and start proportionate planning. - Leaders should align migration plans with contractual, regulatory and sector-specific requirements with qualified counsel and relevant authorities. - The company says there is no single universal compliance deadline from the G7 call to action, which means timing will vary by sector, geography and data sensitivity. - As post-quantum standards mature in practice, more organizations will need migration sequencing, funding and evidence that can survive audit review.

The bottom line: - Post-quantum readiness is no longer a theoretical topic. - The immediate work is inventory, ownership and governance for cryptography that protects data that must remain secret for the long term.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Cryptocurrency Insider Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Cryptocurrency Insider Today

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.