cavendish
AssessedEmerginggate · AdoptionNear · 1–3 years×3 sightings

Quantum Encryption

low-hanging opportunity

Post-quantum cryptography migration is an advisory line that needs no quantum computer to exist: the standards are published, the ASD timeline is fixed, harvest-now-decrypt-later makes the risk current, and the work — crypto inventory, agility audit, migration sequencing — is data-and-systems work the firm already knows how to sell.

A validation run. Researched position, no experiment.

Join with…

Confidence

63%human-committed

Expiry

43duntil review · 16 Oct 2026

Lead time

20moopened after mainstream — recorded honestly

Ownership

LFLena Fischermonthly cadence

Where it is

NIST finalised FIPS 203/204/205 in 2024 and ASD's ISM now sets 2030 as the date after which traditional asymmetric cryptography is not to be used in Australian government systems. Every APRA-regulated entity and every telco holds long-lived data that is harvestable today and decryptable later. None of that depends on when a cryptographically relevant quantum computer arrives; it depends on a migration that takes most large organisations five to seven years and that most have not started. The validation runs found the market is forming — the big-four consultancies all launched practices in the last twelve months — and that the tractable product is not a 'quantum readiness audit' but a crypto-agility inventory bolted onto existing data-governance engagements. The graveyard entry says why the audit-as-product version died.

Why a Quantium decision hinges on it

Three of the firm's verticals (banking, government, telco) are under a dated regulatory expectation to migrate, and the firm's data-governance and systems-inventory work is the natural place for a crypto inventory to live. The window is 2026–2029: after that the consultancy practices will have consolidated and the work will be commodity. It is low-hanging because the gate is adoption, not technology — the clients know they have to do it and have not.

Field attributes

StateEmerging
GateAdoption · ready — blocked by trust, regulation, procurement or change capacity
OriginQuestion
Measurablepartial
Audience · TLPexec
Horizonnear
Opened2 Apr 2026
Mainstream13 Aug 2024
Last validated19 Aug 2026
Sightings3

Position

What is demonstrated, what is hype, what would have to be true.

The shape every position request answers. Signal-tier fields carry a draft; assessed and tested fields carry a validated one.

What is demonstrated
  • 01The standards are final and the AU regulatory timeline is dated: ASD ISM guidance names 2030 for government systems, and APRA has signalled alignment in supervisory correspondence (assessed, from primary sources).
  • 02Migration timelines from published case studies run 5–7 years for a large bank, dominated by the inventory phase — finding where cryptography is used — not the algorithm swap.
  • 03A crypto-agility inventory can be produced from existing configuration and code repositories with agent-assisted scanning; a Type 2 on the lab's own infrastructure found 214 cryptographic dependencies in three days.
What is hype
  • 01'Q-Day is 2028.' Every date is a guess; the migration case does not depend on any of them.
  • 02Quantum key distribution as the answer. It is a hardware product for point-to-point links and irrelevant to the enterprise migration problem.
  • 03'Quantum readiness audit' as a product. It sold once, produced a document, and the client did nothing — the graveyard entry.
What would have to be true
  • 01A client buying the inventory as part of a data-governance engagement rather than as a standalone security review — the pricing model that the audit-as-product version got wrong.
  • 02APRA converting its signalled alignment into a dated expectation for ADIs, which would move the gate from adoption to compliance.
  • 03The firm having, or partnering for, one credentialed cryptographer. The inventory is data work; the migration design is not.
What we would do
  • 01Package the crypto-agility inventory as a module inside existing data-governance and systems-inventory engagements; do not sell it standalone.
  • 02Maintain sa-pqc-timeline as a standing answer with the AU dates and refresh it when APRA or ASD moves.
  • 03Partner rather than hire for migration design; keep the firm on the inventory and sequencing side where the data is.

Signals · 10 in this cluster

What the cluster is made of.

Every item carries its source, tier and sightings. Detector-found signal sits beside human drops; downstream they are indistinguishable except by provenance.

band 1 · bleeding edgeband 2 · early adoptionband 3 · demand
2030
migration date
Regulatory·band 1Signal

ASD ISM update: traditional asymmetric cryptography not to be used after 2030

Information Security Manual revision sets a dated expectation for Australian government systems and names ML-KEM, ML-DSA and SLH-DSA as the replacements. The single most load-bearing document in the field: it makes the migration a compliance timeline, not a risk debate.

extracted claimAustralian government systems are under a dated, named-algorithm PQC migration expectation.
ASD / ACSC26 Mar 2026
ABLFdropped 4
19
openings
Job posting·band 2Signal

Big-four AU practices post 19 'post-quantum cryptography' roles in one quarter

Argus scan. Up from 3 in the same quarter of 2025. All four majors and two specialist security firms. Inference: practices are being built now, and the market will consolidate around them.

Job boards · AU professional services31 Jul 2026
detector · early adoption
214
crypto deps found
Finding·band 1Tried

Type 2: agent-assisted crypto inventory of the lab's own infrastructure in three days

Scanned the lab's repositories, container images and cloud configuration with an agent loop over open-source CBOM tooling. Found 214 cryptographic dependencies, 41 of them quantum-vulnerable asymmetric primitives, 9 undocumented anywhere. Tried tier; one estate.

extracted claimAn agent-assisted scan can produce a usable crypto-agility inventory in days on a mid-sized estate.
Lab · Type 2 · Lena Fischer · Lena Fischer24 Jul 2026
LFdropped
Analyst·band 3Signal

Analyst: PQC advisory spend in APAC financial services to triple by 2028; standalone assessments already commoditising

Rare analyst note that agrees with our graveyard: standalone readiness assessments are being bundled into broader security and governance engagements and priced at zero. Growth is in migration programmes.

Industry analyst briefing17 Jun 2026
RMdropped
Post·band 2Signal

'We found RSA in the payroll batch job. Nobody had touched it since 2011.'

Widely shared write-up of inventory surprises: cryptography in scheduled jobs, vendor appliances and spreadsheets with macros. Argues the inventory is an archaeology problem, not a security one.

Personal blog · A bank platform engineer9 Jun 2026
?dropped 3
70%
inventory share of effort
Talk·band 2Signal

AusCERT: 'Two years into our PQC migration — the inventory was 70% of it'

A major bank's migration lead described the programme: 18 months of inventory, discovery of cryptography in places nobody owned, and the algorithm swap as the easy tail. The 70% figure is theirs.

AusCERT conference21 May 2026
MLdropped 2
Announcement·band 3Signal

Telco announces 'quantum-safe network' via QKD on a single metro fibre link

Point-to-point QKD between two data centres, marketed as a quantum-safe network. Irrelevant to the enterprise migration problem; kept as the strongest example of the category confusion clients bring to the conversation.

Company press release14 May 2026
detector · demand
Client question·band 3Signal

'When do we actually have to do this, and is it a security project or a data project?'

Asked by a bank's chief data officer, not its CISO. Logged by the banking sector owner. The second half of the question is what reframed the product from audit to inventory module; it is also the origin of sa-pqc-timeline.

Engel · banking engagement1 Apr 2026
CDdropped 2
~10yr data
exposure threshold
Paper·band 1Signal

Harvest-Now-Decrypt-Later: Quantifying Exposure Windows for Long-Lived Enterprise Data

Models exposure as data lifetime plus migration duration against a distribution of CRQC arrival dates. For data with a 15-year confidentiality requirement and a 6-year migration, exposure is material under every arrival estimate later than 2032.

extracted claimAny data with confidentiality requirements beyond ~10 years is exposed today under every credible CRQC timeline.
arxiv.org · Brenner, Achterberg et al.11 Feb 2026
LFdropped 2
3.1k
stars
Repository·band 2Tried

cbom-scan — cryptographic bill-of-materials scanner for repos, images and cloud config

Open-source CBOM tooling used in the Type 2. Emits CycloneDX CBOM; the agent loop sat on top of it to resolve ownership and usage context, which the tool cannot.

github.com20 Jan 2026
LFOGdropped 2
Seen something that belongs here?Under fifteen seconds, or it will not be used.

Claims · 5 supporting, 1 refuting

The atoms.

A document cannot go stale; an assertion can. Claims are immutable and stamped with the extractor that produced them, so staleness, diffs and the graveyard operate at claim level.

The PQC migration case is independent of when a cryptographically relevant quantum computer arrives; harvest-now-decrypt-later and dated regulation make it current.

Assessedc-quantum-encryption-1dalton-0.419 Aug 2026ASD / ACSC, arxiv.org
86%

The inventory phase dominates PQC migration effort and timeline; the algorithm swap is a minority of the work.

Assessedc-quantum-encryption-2dalton-0.419 Aug 2026AusCERT conference, Lab · Type 2 · Lena Fischer, Personal blog
78%

A standalone 'quantum readiness audit' does not sell repeatably; the inventory sells only when embedded in existing governance work.

Assessedc-quantum-encryption-3dalton-0.430 Jun 2026Engel · banking engagement, Industry analyst briefing
70%

Agent-assisted scanning of code and configuration repositories can produce a usable crypto inventory in days rather than months.

Triedc-quantum-encryption-5dalton-0.424 Jul 2026Lab · Type 2 · Lena Fischer, github.com
64%

The big-four consultancies' PQC practices will have consolidated the AU market by 2029, closing the entry window.

Assessedc-quantum-encryption-6dalton-0.419 Aug 2026Job boards · AU professional services, Industry analyst briefing
55%

Quantum key distribution hardware is a material part of the enterprise PQC opportunity.

Assessedc-quantum-encryption-4dalton-0.314 May 2026Company press release
12%

Position history · the diff is the product

3 validation runs against a fixed brief. Confidence 50% → 63%.

runs compare claim sets, never prose
What we said · run 3

Second validation run plus a Type 2 on the lab's own infrastructure. Inventory dominates the migration; agent-assisted scanning makes it a days-not-months exercise. Entry window closes around 2029 as big-four practices consolidate. Standing answer published.

63%
Changed since run 2
  • The inventory phase dominates PQC migration effort and timeline; the algorithm swap is a minority of the work.
  • Agent-assisted scanning of code and configuration repositories can produce a usable crypto inventory in days rather than months.
  • The big-four consultancies' PQC practices will have consolidated the AU market by 2029, closing the entry window.
  • c-quantum-encryption-1 ↑ 0.78 → 0.86
Positions are superseded, never edited. The prediction record is worthless if it can be quietly revised.Crystal ball

Scoring · ordinal bands

Agents propose. A named human commits.

Uncommitted scores are visibly marked and never leave the building. Bands, not point estimates — false precision is the tell that a number was generated rather than derived.

Impact

committed · AW
medium

A new advisory line in three verticals, bounded by the firm's lack of a cryptographer.

Timeline

committed · LF
0–18mo

Regulatory dates are fixed; the buying window is now.

TAM

agent-estimated
$100M–1B

Agent-estimated from AU PQC advisory spend across regulated sectors to 2030. Uncommitted.

Cost

committed · LF
low

Inventory tooling is a Type 2; the module packaging is a fortnight of practice work.

Cost of being wrong

agent-estimated
low

Worst case is an advisory module nobody buys. Agent-estimated.

Demand

committed · CD
medium

Two banking clients asked about PQC timelines this half; one government client has a dated mandate and no plan.

Workforce readiness

committed · LF
medium

Inventory and sequencing are data work the firm can staff; migration design needs a partner.

Relevance · per vertical

Why it matters here, or explicitly does not.

Ranking is per vertical, not global. Sector owners commit notes against agent drafts.

Banking
relevant

Long-lived customer and transaction data is the canonical HNDL target. APRA has signalled alignment with ASD timelines.

Mechanism · Crypto inventory as a module in data-governance engagements; sequencing roadmap against the 2030 date.

CD committed by Claire Duboiscommitted
Government
relevant

ISM sets a dated expectation. Agencies have the mandate and mostly no inventory.

Mechanism · Inventory over agency systems registers; roadmap aligned to ISM; DTA procurement panel access needed.

AB committed by Aisha Bellocommitted
Telco
relevant

Core-network and subscriber-data cryptography is long-lived and vendor-embedded; the inventory is hard and therefore valuable.

Mechanism · Vendor-dependency mapping first; the firm's role is the inventory, not the network change.

Agent draft · awaiting a sector owneragent-estimated
Retail & FMCG
not-relevant

Payment cryptography is owned by the schemes and acquirers; retailers inherit the migration and do not buy advice on it.

Mechanism · None for the firm; PCI DSS updates will carry the change.

DS committed by Dev Sharmacommitted

Red team · the strongest case against

The strongest case against: this is a security-consulting product and Quantium is not a security consultancy. The big four and the specialist security firms have the credentials, the cryptographers and the client security-function relationships; the firm's data-governance buyer is not the person who signs off a cryptographic migration. 'Low-hanging' describes the technology, not the sales motion.

  • The one time the firm sold a PQC product it produced a document and no follow-on work. The graveyard entry is the only market evidence we have and it is negative.
  • Every inventory tool in the signal set is open-source or vendor-bundled. The inventory is being commoditised faster than the firm can package it.
  • Without a cryptographer the firm cannot defend a sequencing recommendation to a CISO, and the buyer will notice.
Stored permanently alongside the thesis. Sources are correlated; without an adversary, synthesis converges on consensus and calls it insight.thesis weakened

Source diversity

  • Regulators (ASD/NIST/APRA)30%
  • Security practitioners30%
  • Academic cryptography15%
  • Internal / Engel / analyst25%

A field supported by one epistemic community is a flag, not a finding.

Cross-pollination · typed joins

Connected, not merely similar.

Enabling, compounding, substituting, blocking. A satisfied dependency trigger is a far stronger signal than semantic proximity.

Trigger · A peer-reviewed demonstration of fault-tolerant factoring above 1,000 logical qubits, or ASD/NIST bringing the migration date forward. Either resurfaces this field for re-scoring; neither is required for the current advisory case.

When the trigger fires, this field is resurfaced automatically. Watchable rather than parked.

compoundingCyber Cold War

State-actor harvest campaigns are the threat model that makes HNDL a board question rather than an IT one.

compoundingTEE and Secure Inference

Confidential-inference deployments carry their own key hierarchy that will need the same migration; the inventory covers both.

compoundingUS Non-Dominance

Sovereign key management and AU-resident HSMs are part of the same procurement conversation.

Share graph

Provenance running forward.

Discovery, not accountability. No counts, no rankings, no rollups to managers.

Convergence · who else is here

Several people’s drops meet here. An informal working group already exists and probably does not know it.

ContributorsLFAWCDABML

Lineage

What this field produced, and what it killed.

Experiments, recommendations and graveyard entries stay attached. The reasoning that killed a claim is the reusable asset.

Open questions · return to the pile

Every run leaves a record. Separately, its question either closes or returns to the pile with notes — which is what the next person proposing the same thing will see.

  1. 01Will APRA convert signalled alignment into a dated expectation for ADIs, and when?
  2. 02Can the inventory module be sold inside a data-governance engagement without a CISO sponsor, or does the security function always end up owning it?
  3. 03Who is the firm's cryptography partner for migration design, and what does that partnership cost in margin?