Expert Insight

Preparing for the Post-Quantum Transition: First Steps for Organisations

27 May 2026

The post-quantum transition has moved from a specialist cryptography discussion to a practical cybersecurity planning issue.

For years, the question was whether organisations should prepare for quantum-era risks. That question is now being replaced by a more practical one: where should they begin?

The answer is not to rush into replacing algorithms system by system. The first step is to understand the environment. Cryptography is deeply embedded in modern infrastructure, often in places that are not immediately visible. It protects websites, remote access, software updates, identity systems, databases, APIs, certificates, devices, communication channels and supply-chain connections.

For organisations involved in space research, this complexity is especially important. Secure communication may depend on multiple partners, distributed infrastructure, specialised equipment and long operational lifecycles. A poorly planned migration could introduce disruption. A delayed migration could leave sensitive data and systems exposed for longer than necessary.

The right starting point is therefore not urgency alone. It is disciplined preparation.

What standards bodies are saying

In August 2024, the U.S. National Institute of Standards and Technology finalised its first three post-quantum cryptography standards and encouraged system administrators to begin integrating them, noting that full integration will take time. The standards cover key encapsulation and digital signatures, including ML-KEM, ML-DSA and SLH-DSA.

The UK National Cyber Security Centre has described migration to post-quantum cryptography as a mass technology change that will take several years. Its guidance sets milestones for organisations to define migration goals, complete discovery and build an initial plan by 2028; carry out the highest-priority migration activities by 2031; and complete migration of systems, services and products by 2035.

At European level, EU Member States, supported by the European Commission, have also issued a coordinated implementation roadmap for the transition to post-quantum cryptography. The roadmap highlights the need for a timely, comprehensive and coordinated transition, including awareness of the quantum threat to cryptography.

These developments point in the same direction: post-quantum migration should be planned before it becomes urgent.

Step 1 — Build a cryptographic inventory

For many organisations, the first practical step is to build a cryptographic inventory.

This means identifying where cryptography is used across the organisation and what purpose it serves. Which systems use public-key encryption? Where are digital signatures used? Which certificates are deployed? Which protocols protect internal and external communication? Which software updates rely on signing? Which vendors manage cryptographic functions on behalf of the organisation?

This inventory does not need to be perfect on day one. It does need to become a living asset. Without it, decision-makers cannot accurately assess exposure, prioritise work or coordinate migration.

Step 2 — Classify data and systems by risk

Not all systems require the same level of attention at the same time. A public website, a temporary test environment and a long-term research data archive do not carry the same risk profile. The most important questions are simple but revealing: how sensitive is the data, how long must it remain confidential, and what would happen if the trust mechanism failed?

This is where “harvest now, decrypt later” risk becomes relevant. If encrypted information is valuable for many years, an attacker may have an incentive to collect it now and wait for future capabilities. Long-lived research data, strategic technical documentation, operational information and sensitive partner communications may therefore require earlier attention than data with short-term value.

Step 3 — Map dependencies

Post-quantum migration will not happen inside one isolated system. It will involve operating systems, browsers, cloud platforms, network equipment, applications, identity providers, certificate authorities, hardware security modules, embedded devices and external suppliers. In specialised environments, some dependencies may be proprietary or difficult to update.

For space research, the dependency map may also include partner organisations and shared infrastructure. A communication system is only as strong as the trust model around it. If one party migrates while another remains tied to outdated assumptions, interoperability and security can both become difficult.

Step 4 — Prioritise high-impact communication paths

Organisations should identify which communication channels carry sensitive or long-lived information. These may include partner-to-partner exchanges, remote administration, research data transfers, secure APIs, mission-support environments, cloud connections and software distribution channels.

The objective is not to migrate everything at once. It is to understand which systems matter most and where early planning will reduce future risk.

Step 5 — Build crypto-agility into the migration strategy

A post-quantum programme should not simply replace one fixed cryptographic approach with another fixed approach. Standards, implementations and interoperability requirements will continue to mature. Organisations should therefore design systems so cryptographic components can be updated in a controlled way.

This includes clear ownership of cryptographic decisions, documented key-management processes, upgradeable protocols, tested fallback plans and procurement requirements that avoid unnecessary lock-in.

Step 6 — Engage suppliers early

Many organisations do not directly control every cryptographic mechanism they rely on. Vendors may manage encryption, certificates, signing infrastructure, authentication flows or secure update mechanisms. Procurement and supplier-management teams should therefore ask practical questions: what is the supplier’s post-quantum roadmap, which standards are being supported, when will updates be available, and how will migration affect compatibility?

Waiting for vendors to solve the problem without scrutiny is not a strategy. At the same time, attempting to migrate without vendor coordination can create avoidable operational risk.

Step 7 — Treat migration as a governance issue

Post-quantum readiness should involve security teams, system owners, procurement, legal, risk management and executive leadership. It affects budgets, contracts, architecture, compliance, operational continuity and long-term resilience.

For organisations with critical systems or sensitive research environments, the transition should be managed as a multi-year programme rather than a technical task assigned at the end of a project lifecycle.

The COSMOS-SECURE perspective

COSMOS-SECURE approaches secure communication in space research from this long-term perspective. The project recognises that future-ready security depends not only on strong cryptography, but also on planning, adaptability and trusted implementation.

The first steps do not need to be dramatic. They need to be deliberate.

Know where cryptography is used. Understand what it protects. Prioritise the systems that matter most. Work with partners and suppliers. Build flexibility into future architecture. And make post-quantum readiness part of wider cyber resilience planning.

The transition to post-quantum cryptography will take time. Organisations that begin early will have more control, better visibility and fewer rushed decisions later.

For space research, where trust, continuity and long-term confidentiality are central to cooperation, that preparation is not optional. It is part of building secure communication for the decades ahead.