top of page

🇨🇴 Colombia PQC Spotlight: Early Stage Readiness, Digital Signature Reform, Sector Exposure

  • Writer: Brian Couzens
    Brian Couzens
  • 1 day ago
  • 2 min read

Colombia is in the early stage of PQC adoption. The country faces elevated quantum risk due to heavy reliance on classical cryptography across financial services, government platforms, and telecom networks. Movement has begun through digital signature reform and initial alignment with NIST standards, but Colombia has no national PQC roadmap yet.


Government Posture: Digital Signature Reform

Colombia’s digital signature law, Law 527 of 1999, is being updated to include post quantum digital signatures. Legal and technical reviews recommend recognizing NIST algorithms such as ML DSA and ML KEM to replace vulnerable RSA and ECC. This reform is Colombia’s first concrete PQC regulatory action and will modernize authentication, identity, and evidentiary guarantees.


Quantum Risk Profile

A 2026 assessment places Colombia at Q Day Readiness Score 43 out of 100, classified as early stage with elevated risk. Financial and government systems rely on RSA 2048, ECDSA, and AES 256, creating a long vulnerability window under quantum attack models. Colombia faces a high harvest now decrypt later threat level, meaning intercepted data today may be decrypted later by quantum adversaries.


Financial Sector

Colombia’s financial sector is the most exposed domain. Interbank messaging, digital asset ecosystems, and payment infrastructure depend on classical cryptography. Regulators are being advised to adopt crypto agile planning and begin transition toward ML DSA and ML KEM. The sector requires coordinated migration due to systemic risk.


Government and Public Services

Government communications and digital platforms rely on legacy cryptography. The reform of Law 527 is expected to introduce PQC valid signatures, align Colombia with NIST and ISO standards, and strengthen digital identity and authentication. This is Colombia’s most important PQC policy shift so far.


Telecom and Infrastructure

Telecom networks are identified as a major vulnerability vector. Encrypted traffic is at risk of future quantum decryption, and infrastructure lacks crypto agility. Colombia has not published a PQC migration timeline and remains in the assessment and awareness phase.


International Alignment

Colombia is not listed among countries with formal PQC programs or migration timelines in GSMA’s 2026 PQC government index. This confirms Colombia’s early stage posture and the absence of a national PQC strategy.


Bottom Line

Colombia is early but moving. The country has a digital signature reform underway, an elevated quantum risk profile, high exposure in financial services and telecom, and growing pressure to align with NIST and ISO standards. Colombia is transitioning from awareness to initial regulatory action and beginning its PQC journey.




 
 
 

Comments


bottom of page