The G7’s Post-Quantum (PQC) Call to Action: The Hard Part Starts Now

The G7 Cybersecurity Working Group has issued Preparing for the Post-Quantum Era: A Call to Action, a formal warning that quantum computing must no longer be treated as a distant technology concern.
Its central message is clear: the quantum threat is a near-term risk that requires action across all sectors, not only critical infrastructure.
For Boards, C-suites, CISOs and risk leaders, this is important. Post-quantum cryptography, or PQC, is no longer just an emerging technical topic. It is becoming a business-resilience, economic-security, procurement and governance issue.
The G7 is right to call for early action. But the document also leaves a critical challenge to every organisation: how will you actually execute the transition?
The Quantum Risk Starts Before Quantum Arrives
The exact point at which a cryptographically relevant quantum computer becomes available remains uncertain. Such a machine could break the mathematical problems that support much of today’s public-key cryptography, including widely used encryption, key-establishment and authentication mechanisms.
However, the absence of a confirmed date does not remove today’s exposure.
The most immediate concern is known as “harvest now, decrypt later.” A malicious actor can intercept encrypted communications, copy encrypted files, or acquire data archives today. They may not be able to read them now, but they can retain them until a future quantum capability enables decryption.
This matters wherever information must remain confidential for many years.
That includes:
Financial records and payment-related information
Sensitive personal and health data
Trade secrets and intellectual property
Government and defence information
Strategic business plans and legal records
Critical infrastructure data
Digital identities and authentication data
Long-term contractual and commercial communications
Quantum exposure is not only a confidentiality problem. Once public-key cryptography can be attacked, the integrity and authenticity of digital systems can also be affected. A capable adversary could potentially impersonate trusted entities, forge data, compromise devices, undermine trusted communications or exploit supply-chain dependencies.
That is why quantum readiness belongs on the enterprise-risk agenda now.
What the G7 Is Asking Organisations to Do
The G7 document does not call for panic or an immediate wholesale replacement of every system. It calls for a phased, risk-based transition to PQC.
The recommended actions are practical:
Identify the systems, data and assets that matter most.
Determine which information requires long-term confidentiality.
Create an inventory of cryptographic assets.
Map cryptographic dependencies across applications, infrastructure, certificates, APIs, suppliers and cloud services.
Develop a PQC transition plan.
Begin early, rather than waiting for the availability of a cryptographically relevant quantum computer.
Integrate PQC-capable products into ordinary technology renewal and procurement cycles.
Build collaboration among government, industry and academia.
Treat PQC as an expected evolution of cybersecurity practice, not a narrow compliance exercise.
This is significant because cryptography is rarely concentrated in one place. It is embedded throughout the enterprise: in software, protocols, identities, certificates, devices, cloud platforms, network infrastructure, operational technology, vendor products and third-party services.
Many organisations cannot yet answer a deceptively simple question: where is our cryptography, who owns it, and what will fail if it changes?
Without that answer, migration cannot be properly prioritised, governed or assured.
What the G7 Call Does Not Say
The G7 publication is strategically important, but it is not a global regulation. It does not impose a universal deadline for PQC migration. It does not establish a common reporting framework, a minimum assurance baseline, a complete maturity model or mandatory controls.
Those omissions are understandable. The G7 is providing policy direction, not a single global implementation rulebook.
But they matter.
Organisations must still decide how to identify risk, define criticality, fund their transition, manage supplier dependencies, test new implementations, measure progress and provide assurance to Boards, regulators, customers and partners.
The G7 also does not say that deploying a standard PQC algorithm alone will create quantum resilience.
PQC is essential. But it is only one part of a broader capability.
Cryptographic Agility Is the Real Resilience Requirement
The objective should not be to complete a one-time replacement and declare the job done.
The objective should be cryptographic agility: the ability to discover, govern, change, validate and retire cryptographic mechanisms as threats, standards, technologies and business requirements evolve.
A cryptographically agile organisation can:
Maintain an accurate cryptographic inventory.
Identify vulnerable algorithms, keys, certificates and protocols.
Understand dependencies across business services and suppliers.
Prioritise migration based on risk and business impact.
Test changes without disrupting critical operations.
Replace algorithms and configurations in a controlled way.
Validate that cryptographic controls remain securely implemented.
Respond to new vulnerabilities and standards without rebuilding entire systems.
This is why quantum readiness should be treated as a transformation programme, not simply a product-selection exercise.
It touches architecture, engineering, identity, procurement, vendor management, security operations, data governance, business continuity, internal audit and executive oversight.
It also depends on the fundamentals. Strong key management, certificate lifecycle control, secure implementation, trusted randomness, supplier assurance, incident response and recovery remain vital. A quantum-safe algorithm cannot compensate for unknown cryptographic assets, unmanaged legacy systems or weak operational controls.
Why Boards and C-Suites Should Act Now
The G7 itself has no direct enforcement power over individual organisations. Yet its members and national cybersecurity agencies can translate this direction into national guidance, procurement conditions, regulatory expectations and sector-specific requirements.
Bodies such as ANSSI, CISA, the UK NCSC, BSI, ACN and Canada’s Communications Security Establishment can shape the rules, expectations and market conditions under which organisations will operate.
That makes this document an early policy signal.
Boards and executive leadership should not wait until requirements become mandatory, a major customer asks for evidence, or a supplier’s cryptographic weakness creates an urgent problem.
They should ask:
Which business data must remain confidential for the next 10, 15 or 20 years?
Which digital identities, signatures and authentication services are mission-critical?
Where does vulnerable public-key cryptography exist across our enterprise?
Which suppliers, cloud services and products create cryptographic dependency risk?
Can we update cryptography safely and quickly without affecting operations?
Do we have an accountable executive owner, a funded roadmap and measurable progress indicators?
Are cryptographic agility and PQC readiness built into architecture standards, procurement and supplier governance?
SITG-Consulting Opinion
The G7 has issued a valuable call to action, but a call alone does not produce readiness.
The decisive issue is execution.
The G7 does not yet provide universal deadlines, detailed assurance requirements or a binding global enforcement mechanism. Its member states, regulators and national agencies, however, have the power to turn broad policy direction into specific guidance, public-procurement criteria, supervisory expectations and industry requirements.
Organisations should therefore interpret this as an opportunity to act before action is imposed under pressure.
The enterprises that begin now can spread investment through ordinary technology lifecycles, reduce disruption, improve visibility of cryptographic risk and build confidence with customers, regulators and partners.
The enterprises that wait will likely face a more expensive, less controlled and more urgent transition.
The question is no longer simply when quantum computing will become capable enough to threaten public-key cryptography.
The question is whether your organisation has the visibility, governance and agility to respond before that threat becomes operational.




Comments