AI

Quantum threat forces enterprises into massive cryptography overhaul by 2029

As quantum computing capabilities grow, organizations are shifting from planning to execution on replacing the encryption systems that have secured the internet for decades. The work amounts to a once-in-a-generation infrastructure rebuild with a hard deadline.

·3 min read
Quantum readiness moves from blueprint to build as 2029 deadlines converge
Quantum readiness moves from blueprint to build as 2029 deadlines converge

The cryptographic systems that have safeguarded internet communications for years are nearing obsolescence. Quantum computing's advancement is compelling enterprises to undertake a sweeping replacement of the encryption infrastructure embedded in their applications, devices and certificates. The industry has moved past theoretical discussion and into active implementation, with organizations now executing migration strategies rather than debating necessity.

Amit Sinha, chief executive officer of DigiCert Inc., observed that companies have progressed through skepticism toward acceptance that quantum readiness demands immediate action. "It is a once in a 30-year upgrade to the core trust foundations of the internet," Sinha said. "So, it is more like a skyscraper. But the important point I tell every customer is you don't need to build a skyscraper in one shot. You don't need the full final blueprint. You need to start with the foundations, build the next floor and then stack up floors on top."

Encryption inventory is the first step toward quantum safety

The primary challenge is no longer convincing leadership of the risk. Rather, enterprises grapple with the sheer scale of a migration affecting every cryptographic component across the organization, while the teams responsible for public key infrastructure have historically operated with constrained resources.

"I think it's the scope of the project," Sinha said. "In many cases, PKI teams who are underfunded and now they look at this massive, Y2K-like times 10 event that is going to hit them. What we tell customers is you don't need a perfect inventory, you need a good enough inventory. Identify crown jewels in your application suite that you want to attack first."

Cataloging systems, applications and cryptographic libraries forms the foundation for what the sector terms cryptographic posture—a risk measurement tool that DigiCert introduced through Quantum Central in July. Simultaneously, shorter certificate validity periods are driving adoption of automation technologies across the industry.

"The road to crypto agility with the 47-day mandate is kind of the same road to post-quantum cryptography," Sinha said. "Both of those deadlines are now 2029. So, having a good system in place, bringing public and private PKI together, having last-mile automation capabilities that give you crypto agility, foundational steps — both for the 47-day mandate that we have today and the migration to post-quantum cryptography."

Rather than separate initiatives, public key infrastructure modernization and cryptographic migration represent a unified program with aligned timelines.

"Prioritize the migration to quantum safety," Sinha said. "PKI modernization is long overdue. And the deadline to do that is 2029. If you don't start today, you're already out of time."