Post-quantum encryption shift targets 2035 benchmark

Post-quantum encryption planning is shifting to phased migration, using the 2035 CNSA 2.0 benchmark and long-term data risks as priorities.

Atlas Newsdesk ·

Post-quantum encryption shift targets 2035 benchmark

Post-quantum cryptography (PQC) is increasingly being treated as a long, managed technology transition rather than a single emergency replacement of current encryption. Experts cited in the source material frame the shift as work that should be absorbed into normal infrastructure refresh cycles, procurement decisions, and lifecycle management, particularly for systems handling information that must remain confidential for many years.

The planning case is anchored in a quantified risk assumption referenced in the material: a 50% probability that widely used 2048-bit RSA encryption could be vulnerable to quantum decryption by 2040. On that basis, the material argues the near-term issue is not a distant “quantum deadline,” but current exposure tied to data that must stay protected for more than a decade.

U.S. national security systems set a 2035 baseline

A central milestone shaping transition timelines is a 2035 benchmark for U.S. National Security Systems. The source states these systems are mandated to meet the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) by 2035, positioning government baselines and standards-driven frameworks as a minimum adoption level for those environments.

The material also draws a boundary around that requirement, noting it is not presented as a legally binding obligation for private-sector organisations. Even so, it describes the 2035 date as a practical reference point that can influence vendor product roadmaps and help companies align plans across supply chains where shared security requirements and interoperability are important.

“Harvest now, decrypt later” brings risk into the present The source places particular emphasis on the “harvest now, decrypt later” threat pattern. Under this scenario, encrypted traffic or stored encrypted records can be collected today and retained, with the intention of decrypting them later if quantum capabilities mature enough to make that feasible.

National Security Systems

In response, the material recommends prioritising PQC readiness where delayed disclosure would be most damaging. It specifically highlights datasets, systems, and contracts that require confidentiality for more than ten years, urging organisations to identify long-tail exposure that already exists and to reduce it through staged upgrades over time.

Performance and hardware limits complicate the path

Quantum-resistant algorithms are described as potentially increasing computational overhead and latency, which the source says can become significant in production environments. Because of this, the material cautions that some deployments may not be able to transition through software-only changes.

To manage performance and cost, it points to hardware-level integration as part of “future-proofing.” Examples cited include specialised cryptographic accelerators and optimised firmware intended to preserve expected performance while adopting PQC. The direction is framed as a full-stack change spanning hardware, firmware, and procurement decisions, rather than only swapping algorithms inside applications.

Budgeting for phased execution amid uncertain timelines

For security and finance teams, the source presents timeline assumptions as practical inputs for planning and budgeting. The stated is to align funding, procurement, and lifecycle schedules so cryptographic upgrades can be executed with minimal disruption, rather than through rushed and reactive compliance programmes.

The material also flags an unresolved variable: the speed at which quantum capabilities mature remains uncertain. That uncertainty is presented as a reason to rely on risk-based prioritisation and phased execution as the core approach to near-term PQC planning.

More stories