During the week commencing October 5, significant reports were issued by Europe’s foremost law enforcement agency and the United States government’s spending oversight body, both calling for a swift acceleration in organizations’ adoption of post-quantum cryptography (PQC). This urgent appeal comes amid growing concerns surrounding the potential rise of cryptographically relevant quantum computers (CRQCs), which could fundamentally undermine the security frameworks upon which both governmental and corporate cybersecurity heavily rely.
While experts are divided on the timeline for the emergence of CRQCs, speculation has intensified regarding a date often referred to as “Q-day.” Reports suggest that on this pivotal date, advancements in quantum computing could enable the decryption of existing cryptographic protocols, which currently protect sensitive data across various sectors. A noteworthy prediction made by Google in March estimated that this could occur as early as 2029, underscoring the urgency of the situation.
In its report, released on October 6, the U.S. Government Accountability Office (GAO) outlined a crucial proactive approach, having already proposed 89 recommendations to 23 federal agencies. These include the necessity to create a prioritized inventory of cryptography that is vulnerable to quantum attacks, alongside identifying necessary funding for the transition to PQC. The GAO’s report serves as a redacted version of an original document submitted to these agencies back in September 2025.
The GAO emphasized three fundamental areas needing immediate attention by federal agencies:
-
Development of a prioritized inventory of vulnerable cryptography: Agencies must catalog the existing cryptographic methods in use that could be compromised by quantum advancements.
-
Identification of funding requirements for PQC: There exists a pressing need for agencies to allocate appropriate financial resources for the transition to technologies that can withstand quantum threats.
- Testing of PQC solutions: Agencies are encouraged to actively conduct testing on PQC systems to ensure readiness before CRQCs emerge.
However, the GAO report noted a concerning trend: none of the 24 cited agencies have fully engaged with all three areas of concern. This incomplete implementation has been attributed to several factors, including a deficiency in specialized cryptographic knowledge, inadequate processes for cataloging cryptographic inventory, and the absence of well-defined plans for testing PQC. Until these gaps are addressed, the report warns, agencies will remain ill-prepared to combat the impending threat posed by CRQCs, jeopardizing the security of sensitive information.
Across the Atlantic, the European Union’s law enforcement agency, Europol, published documents on October 7 highlighting similar vulnerabilities. One of these reports evaluated how encrypted communications and stored information could be at risk from a method known as Harvest Now, Decrypt Later (HNDL) attacks, which some nations are reportedly already executing. The level of exposure to such risks hinges on the protocols, configurations, and key management practices employed by organizations.
A second study from Europol specifically addressed the threats quantum computing poses to cryptocurrency wallets. It asserted that while cryptocurrencies themselves are unlikely to face a total collapse due to quantum computing advances, the long-term integrity of these assets necessitates preemptive and strategic defenses. The report stressed that the cryptocurrency sector must embrace innovation, foster collaborative efforts, and prioritize a phased transition towards quantum-resistant cryptographic solutions to build a robust and trustworthy future.
In light of these evolving threats, Europol has urged organizations to take immediate action. It recommended that they upgrade to more secure transmission protocols such as TLS 1.3 and SSH2, while also deactivating outdated legacy protocols and enforcing measures for forward secrecy. By identifying and eliminating unnecessary sensitive data, organizations can help minimize the risks associated with long-term data storage.
Moreover, organizations are encouraged to explore the adoption of PQC, including the integration of hybrid approaches as such solutions become available. For the cryptocurrency landscape, Europol advised blockchain projects to prioritize the integration of PQC algorithms into their core protocols. Collaboration with wallet providers to facilitate these updates is essential.
For wallet providers specifically, the agency indicated that rigorous testing and deployment of PQC-capable wallets should be conducted, alongside educating users about the ramifications of CRQCs. This collective effort to enhance cybersecurity measures is vital as both governments and private sector organizations brace themselves for the challenges posed by future advancements in quantum computing technologies.

