Most security problems are about attackers doing something now. This one is partly about attackers waiting. The move to post-quantum cryptography is driven by a simple mismatch: the deadlines for adopting it are already fixed, but migrating every application to new cryptography takes years. That gap is the problem, and it is why readiness has become a live compliance question rather than a distant technical one.
The threat: harvest now, decrypt later
Today’s widely used encryption relies on mathematics that a sufficiently capable quantum computer is expected to break. Such a machine does not exist yet, but the risk does not wait for it. Encrypted data can be captured and stored now, then decrypted later once the capability arrives, a strategy known as harvest now, decrypt later. For information with a long confidential life, medical records, legal files, state and financial data, the relevant question is not whether a quantum computer exists today, but how long the data must stay secret.
The deadlines are already set
This is no longer hypothetical planning. In 2024, NIST published the first standardised post-quantum algorithms (ML-KEM, ML-DSA and SLH-DSA), giving vendors a stable target. The UK’s NCSC has since set out a migration timeline with milestones in 2028, 2031 and 2035. In the US, the NSA’s CNSA 2.0 requires national security systems to adopt quantum-resistant cryptography on a defined schedule, with new acquisitions expected to support it from 2027. And in the EU, DORA’s technical standard requires financial entities to maintain crypto-agility, the ability to change cryptographic methods as threats evolve, with its recitals naming the quantum threat explicitly.
Why network equipment is near the front of the queue
Infrastructure changes take a long time to plan, validate and roll out, which is why network and communications equipment tends to sit early in these timelines. The NSA’s schedule, for example, expects networking equipment used for national security systems to move to quantum-resistant algorithms well ahead of the final deadline. For anyone operating within or selling into those environments, the practical starting point is now, not the year on the deadline.
The gap the deadlines create
Here is the difficulty. Becoming post-quantum ready means updating cryptography across applications, operating systems, libraries and third-party tools, and that migration depends on every one of those vendors shipping support, which takes years. Organisations are caught between a compliance clock that is already running and an application estate that cannot move as quickly. Demonstrating progress in the meantime is the immediate challenge.
“Don’t browsers and cloud providers already do this?”
It is a fair question and worth answering directly. Some browsers and cloud services have begun adding post-quantum protection to their own connections. But that only covers traffic to those specific services. It does nothing for traffic to applications and endpoints that are not yet post-quantum capable, which is most of them, and it does not address the wider network environment. Piecemeal protection at a few endpoints is not the same as coverage.
How Loxada addresses this
Loxada Quantum Secure applies NIST-standard post-quantum cryptography in a hybrid model at the managed network layer, layering quantum-resistant protection on top of the classical cryptography already in use. Because it operates at the network layer rather than inside each application, it does not require re-engineering software, operating systems or existing tools, which is what closes the gap between the compliance deadline and the pace of application migration.
Quantum Secure is not a replacement for the application-layer migration organisations will eventually complete, and it is not a monitoring product. It is a way to take a documented, standards-based step now, on infrastructure already in place. Loxada Quantum Secure launches in Q3 2026.
Common questions
What is harvest now, decrypt later? Capturing encrypted data today and storing it to decrypt once quantum computers can break current encryption. It makes long-lived data a present-day concern.
What are the key deadlines? NIST standardised the core algorithms in 2024; the UK NCSC sets milestones of 2028, 2031 and 2035; the US NSA’s CNSA 2.0 runs on a schedule from 2027; and DORA requires crypto-agility for financial entities.
Does this require changing our applications? Applying post-quantum protection at the network layer avoids re-engineering individual applications, which is the slow part of migration. Full application-layer migration remains a longer-term task.
Is this fear-based marketing? No. The driver is compliance timelines and long data lifespans, both concrete and documented, rather than a claim that quantum computers are about to break encryption tomorrow.
Sources: NIST post-quantum cryptography standards (FIPS 203, 204, 205), 2024; UK NCSC “Timelines for migration to post-quantum cryptography,” 2025; US NSA CNSA 2.0; DORA RTS 2024/1774.