Quantum Encryption
low-hanging opportunity
Post-quantum cryptography migration is an advisory line that needs no quantum computer to exist: the standards are published, the ASD timeline is fixed, harvest-now-decrypt-later makes the risk current, and the work — crypto inventory, agility audit, migration sequencing — is data-and-systems work the firm already knows how to sell.
A validation run. Researched position, no experiment.
Confidence
63%human-committedExpiry
43duntil review · 16 Oct 2026Lead time
−20moopened after mainstream — recorded honestlyOwnership
LFLena Fischermonthly cadenceWhere it is
NIST finalised FIPS 203/204/205 in 2024 and ASD's ISM now sets 2030 as the date after which traditional asymmetric cryptography is not to be used in Australian government systems. Every APRA-regulated entity and every telco holds long-lived data that is harvestable today and decryptable later. None of that depends on when a cryptographically relevant quantum computer arrives; it depends on a migration that takes most large organisations five to seven years and that most have not started. The validation runs found the market is forming — the big-four consultancies all launched practices in the last twelve months — and that the tractable product is not a 'quantum readiness audit' but a crypto-agility inventory bolted onto existing data-governance engagements. The graveyard entry says why the audit-as-product version died.
Why a Quantium decision hinges on it
Three of the firm's verticals (banking, government, telco) are under a dated regulatory expectation to migrate, and the firm's data-governance and systems-inventory work is the natural place for a crypto inventory to live. The window is 2026–2029: after that the consultancy practices will have consolidated and the work will be commodity. It is low-hanging because the gate is adoption, not technology — the clients know they have to do it and have not.
Field attributes
Position
What is demonstrated, what is hype, what would have to be true.
The shape every position request answers. Signal-tier fields carry a draft; assessed and tested fields carry a validated one.
- 01The standards are final and the AU regulatory timeline is dated: ASD ISM guidance names 2030 for government systems, and APRA has signalled alignment in supervisory correspondence (assessed, from primary sources).
- 02Migration timelines from published case studies run 5–7 years for a large bank, dominated by the inventory phase — finding where cryptography is used — not the algorithm swap.
- 03A crypto-agility inventory can be produced from existing configuration and code repositories with agent-assisted scanning; a Type 2 on the lab's own infrastructure found 214 cryptographic dependencies in three days.
- 01'Q-Day is 2028.' Every date is a guess; the migration case does not depend on any of them.
- 02Quantum key distribution as the answer. It is a hardware product for point-to-point links and irrelevant to the enterprise migration problem.
- 03'Quantum readiness audit' as a product. It sold once, produced a document, and the client did nothing — the graveyard entry.
- 01A client buying the inventory as part of a data-governance engagement rather than as a standalone security review — the pricing model that the audit-as-product version got wrong.
- 02APRA converting its signalled alignment into a dated expectation for ADIs, which would move the gate from adoption to compliance.
- 03The firm having, or partnering for, one credentialed cryptographer. The inventory is data work; the migration design is not.
- 01Package the crypto-agility inventory as a module inside existing data-governance and systems-inventory engagements; do not sell it standalone.
- 02Maintain sa-pqc-timeline as a standing answer with the AU dates and refresh it when APRA or ASD moves.
- 03Partner rather than hire for migration design; keep the firm on the inventory and sequencing side where the data is.
Signals · 10 in this cluster
What the cluster is made of.
Every item carries its source, tier and sightings. Detector-found signal sits beside human drops; downstream they are indistinguishable except by provenance.

ASD ISM update: traditional asymmetric cryptography not to be used after 2030
Information Security Manual revision sets a dated expectation for Australian government systems and names ML-KEM, ML-DSA and SLH-DSA as the replacements. The single most load-bearing document in the field: it makes the migration a compliance timeline, not a risk debate.
extracted claimAustralian government systems are under a dated, named-algorithm PQC migration expectation.

Big-four AU practices post 19 'post-quantum cryptography' roles in one quarter
Argus scan. Up from 3 in the same quarter of 2025. All four majors and two specialist security firms. Inference: practices are being built now, and the market will consolidate around them.

Type 2: agent-assisted crypto inventory of the lab's own infrastructure in three days
Scanned the lab's repositories, container images and cloud configuration with an agent loop over open-source CBOM tooling. Found 214 cryptographic dependencies, 41 of them quantum-vulnerable asymmetric primitives, 9 undocumented anywhere. Tried tier; one estate.
extracted claimAn agent-assisted scan can produce a usable crypto-agility inventory in days on a mid-sized estate.

Analyst: PQC advisory spend in APAC financial services to triple by 2028; standalone assessments already commoditising
Rare analyst note that agrees with our graveyard: standalone readiness assessments are being bundled into broader security and governance engagements and priced at zero. Growth is in migration programmes.

'We found RSA in the payroll batch job. Nobody had touched it since 2011.'
Widely shared write-up of inventory surprises: cryptography in scheduled jobs, vendor appliances and spreadsheets with macros. Argues the inventory is an archaeology problem, not a security one.

AusCERT: 'Two years into our PQC migration — the inventory was 70% of it'
A major bank's migration lead described the programme: 18 months of inventory, discovery of cryptography in places nobody owned, and the algorithm swap as the easy tail. The 70% figure is theirs.

Telco announces 'quantum-safe network' via QKD on a single metro fibre link
Point-to-point QKD between two data centres, marketed as a quantum-safe network. Irrelevant to the enterprise migration problem; kept as the strongest example of the category confusion clients bring to the conversation.

'When do we actually have to do this, and is it a security project or a data project?'
Asked by a bank's chief data officer, not its CISO. Logged by the banking sector owner. The second half of the question is what reframed the product from audit to inventory module; it is also the origin of sa-pqc-timeline.

Harvest-Now-Decrypt-Later: Quantifying Exposure Windows for Long-Lived Enterprise Data
Models exposure as data lifetime plus migration duration against a distribution of CRQC arrival dates. For data with a 15-year confidentiality requirement and a 6-year migration, exposure is material under every arrival estimate later than 2032.
extracted claimAny data with confidentiality requirements beyond ~10 years is exposed today under every credible CRQC timeline.

cbom-scan — cryptographic bill-of-materials scanner for repos, images and cloud config
Open-source CBOM tooling used in the Type 2. Emits CycloneDX CBOM; the agent loop sat on top of it to resolve ownership and usage context, which the tool cannot.
Claims · 5 supporting, 1 refuting
The atoms.
A document cannot go stale; an assertion can. Claims are immutable and stamped with the extractor that produced them, so staleness, diffs and the graveyard operate at claim level.
The PQC migration case is independent of when a cryptographically relevant quantum computer arrives; harvest-now-decrypt-later and dated regulation make it current.
The inventory phase dominates PQC migration effort and timeline; the algorithm swap is a minority of the work.
A standalone 'quantum readiness audit' does not sell repeatably; the inventory sells only when embedded in existing governance work.
Agent-assisted scanning of code and configuration repositories can produce a usable crypto inventory in days rather than months.
The big-four consultancies' PQC practices will have consolidated the AU market by 2029, closing the entry window.
Quantum key distribution hardware is a material part of the enterprise PQC opportunity.
Position history · the diff is the product
3 validation runs against a fixed brief. Confidence 50% → 63%.
Second validation run plus a Type 2 on the lab's own infrastructure. Inventory dominates the migration; agent-assisted scanning makes it a days-not-months exercise. Entry window closes around 2029 as big-four practices consolidate. Standing answer published.
- The inventory phase dominates PQC migration effort and timeline; the algorithm swap is a minority of the work.
- Agent-assisted scanning of code and configuration repositories can produce a usable crypto inventory in days rather than months.
- The big-four consultancies' PQC practices will have consolidated the AU market by 2029, closing the entry window.
- c-quantum-encryption-1 ↑ 0.78 → 0.86
Scoring · ordinal bands
Agents propose. A named human commits.
Uncommitted scores are visibly marked and never leave the building. Bands, not point estimates — false precision is the tell that a number was generated rather than derived.
Impact
committed · AWA new advisory line in three verticals, bounded by the firm's lack of a cryptographer.
Timeline
committed · LFRegulatory dates are fixed; the buying window is now.
TAM
agent-estimatedAgent-estimated from AU PQC advisory spend across regulated sectors to 2030. Uncommitted.
Cost
committed · LFInventory tooling is a Type 2; the module packaging is a fortnight of practice work.
Cost of being wrong
agent-estimatedWorst case is an advisory module nobody buys. Agent-estimated.
Demand
committed · CDTwo banking clients asked about PQC timelines this half; one government client has a dated mandate and no plan.
Workforce readiness
committed · LFInventory and sequencing are data work the firm can staff; migration design needs a partner.
Relevance · per vertical
Why it matters here, or explicitly does not.
Ranking is per vertical, not global. Sector owners commit notes against agent drafts.
Long-lived customer and transaction data is the canonical HNDL target. APRA has signalled alignment with ASD timelines.
Mechanism · Crypto inventory as a module in data-governance engagements; sequencing roadmap against the 2030 date.
ISM sets a dated expectation. Agencies have the mandate and mostly no inventory.
Mechanism · Inventory over agency systems registers; roadmap aligned to ISM; DTA procurement panel access needed.
Core-network and subscriber-data cryptography is long-lived and vendor-embedded; the inventory is hard and therefore valuable.
Mechanism · Vendor-dependency mapping first; the firm's role is the inventory, not the network change.
Payment cryptography is owned by the schemes and acquirers; retailers inherit the migration and do not buy advice on it.
Mechanism · None for the firm; PCI DSS updates will carry the change.
Red team · the strongest case against
The strongest case against: this is a security-consulting product and Quantium is not a security consultancy. The big four and the specialist security firms have the credentials, the cryptographers and the client security-function relationships; the firm's data-governance buyer is not the person who signs off a cryptographic migration. 'Low-hanging' describes the technology, not the sales motion.
- —The one time the firm sold a PQC product it produced a document and no follow-on work. The graveyard entry is the only market evidence we have and it is negative.
- —Every inventory tool in the signal set is open-source or vendor-bundled. The inventory is being commoditised faster than the firm can package it.
- —Without a cryptographer the firm cannot defend a sequencing recommendation to a CISO, and the buyer will notice.
Source diversity
- Regulators (ASD/NIST/APRA)30%
- Security practitioners30%
- Academic cryptography15%
- Internal / Engel / analyst25%
A field supported by one epistemic community is a flag, not a finding.
Cross-pollination · typed joins
Connected, not merely similar.
Enabling, compounding, substituting, blocking. A satisfied dependency trigger is a far stronger signal than semantic proximity.
Trigger · A peer-reviewed demonstration of fault-tolerant factoring above 1,000 logical qubits, or ASD/NIST bringing the migration date forward. Either resurfaces this field for re-scoring; neither is required for the current advisory case.
When the trigger fires, this field is resurfaced automatically. Watchable rather than parked.
State-actor harvest campaigns are the threat model that makes HNDL a board question rather than an IT one.
Confidential-inference deployments carry their own key hierarchy that will need the same migration; the inventory covers both.
Sovereign key management and AU-resident HSMs are part of the same procurement conversation.
Share graph
Provenance running forward.
Discovery, not accountability. No counts, no rankings, no rollups to managers.
Convergence · who else is here
- LFLena Fischer · Red team & assurance4 drops
- ABAisha Bello · Sector owner · Government1 drop
- CDClaire Dubois · Sector owner · Banking1 drop
- MLMarcus Lee · Delivery lead · Telco1 drop
- RMRohan Mehta · Exec sponsor1 drop
- OGOllie Grant · Product engineer1 drop
- ?Anonymous · Anonymous drop1 drop
Several people’s drops meet here. An informal working group already exists and probably does not know it.
Lineage
What this field produced, and what it killed.
Experiments, recommendations and graveyard entries stay attached. The reasoning that killed a claim is the reusable asset.
Open questions · return to the pile
Every run leaves a record. Separately, its question either closes or returns to the pile with notes — which is what the next person proposing the same thing will see.
- 01Will APRA convert signalled alignment into a dated expectation for ADIs, and when?
- 02Can the inventory module be sold inside a data-governance engagement without a CISO sponsor, or does the security function always end up owning it?
- 03Who is the firm's cryptography partner for migration design, and what does that partnership cost in margin?