## Is the G7 Treating Post-Quantum Cryptography as an Emergency?
The G7 Cybersecurity Working Group has formally reframed post-quantum cryptography (PQC) migration from a long-horizon planning exercise into an immediate operational obligation — and it is explicitly telling organizations not to wait for a cryptographically relevant quantum computer (CRQC) to arrive before acting. The group's core argument, published September 6, 2026, is blunt: "Transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition." That framing matters. It shifts accountability from individual enterprise security teams to entire sectors, supply chains, and governments simultaneously.
The most acute near-term threat the group identifies is not a CRQC that doesn't yet exist — it's the "store now, decrypt later" attack vector, which is already operational. Adversaries can intercept and archive encrypted communications today, then decrypt them once a sufficiently powerful quantum machine becomes available. Governmental data, sensitive personal information, and proprietary business secrets with multi-year confidentiality requirements are already at risk under this model. The group identifies five priority areas for PQC migration and recommends a phased, risk-based transition strategy, beginning with the most critical cryptographic assets.
---
## What Is a CRQC and Why Does the Timing Question Matter?
A cryptographically relevant quantum computer — CRQC — is defined by the G7 group as a machine powerful enough to solve the factorization and discrete logarithm problems that underpin vulnerable public-key cryptography systems in current use. No publicly confirmed CRQC exists as of this writing, but the G7's language signals that recent, unspecified hardware advances have prompted a formal re-evaluation of timelines. The group does not name specific systems or companies, nor does it quantify how close the industry is — a deliberate hedge that reflects genuine uncertainty at the policy level.
The analytical shift here is significant. For years, enterprise security teams could defer PQC planning by pointing to the absence of confirmed CRQC capability. The G7 is explicitly closing that argument. A reactive posture, the group warns, "leaves systems vulnerable for an unacceptable period, given the lengthy timelines associated with transitioning to post-quantum cryptography." In practice, full cryptographic migration across a large organization — inventorying all cryptographic assets, mapping dependencies, updating hardware and software, retraining staff — is a multi-year project under the best conditions.
---
## Five Priority Areas and the Risk-Based Transition Framework
The G7 group identifies five priority areas for PQC migration, though the source text does not enumerate them explicitly by name. What the group does specify is a clear sequencing logic:
1. **Identify the most critical data first.** Organizations should begin with a comprehensive cryptographic asset inventory before any technical migration work begins.
2. **Map dependencies.** Cryptographic vulnerabilities rarely sit in isolation — compromised authentication mechanisms can enable lateral movement across networks, exposing multiple organizations in a chain.
3. **Develop a detailed transition plan** aligned with timelines set by national cybersecurity authorities.
4. **Integrate PQC into broader digital security frameworks** rather than treating it as a standalone cryptographic upgrade.
5. **Address the awareness gap.** The group found that a significant barrier to adoption is simply that many organizations are unaware of the risk, or deprioritize it against more immediate security concerns.
That last point is worth pausing on. The G7 is not just issuing a technical mandate — it is describing a market failure in security awareness. The implication for vendors in the PQC space, including firms like [SandboxAQ](https://quantumintel.tech/companies/sandboxaq) and [Arqit Quantum](https://quantumintel.tech/companies/arqit) that operate at the cryptography-quantum intersection, is that enterprise sales cycles will likely require significant education investment before procurement decisions accelerate.
---
## The Competitive and Procurement Pressure
One underreported element of the G7 statement is its explicit linkage between PQC migration and market access. Delaying the transition, the group warns, may result in "lost competitive advantages or exclusion from future contracting opportunities, including public procurement processes." This is a meaningful escalation in language. It signals that G7 governments are moving toward making PQC compliance a prerequisite for government contracts — a procurement lever that has historically been one of the most effective mechanisms for forcing enterprise security upgrades.
For vendors supplying governments or large enterprises in G7 countries, this creates a hard deadline pressure that pure technical risk arguments have historically failed to generate. The security community has struggled for years to translate abstract quantum threat timelines into boardroom urgency. Tying non-compliance to contract exclusion is a more legible incentive structure.
---
## What the G7 Statement Does Not Do
It is worth being precise about what this document is and isn't. This is a policy statement from a working group, not a binding directive with enforcement mechanisms. The G7 group explicitly defers to national cybersecurity agencies for locally applicable implementation guidance — meaning the practical teeth of this statement will vary significantly by jurisdiction. Organizations in countries with strong national PQC frameworks (the U.S. NIST standardization process, for instance, has already produced finalized standards) are better positioned than those relying solely on this G7-level framing.
The statement also does not provide a specific CRQC arrival timeline, which is simultaneously intellectually honest and strategically frustrating. The "store now, decrypt later" threat is real regardless of when a CRQC materializes, but organizations seeking a hard date to trigger budget conversations will not find one here.
---
## Industry Trajectory
The G7 statement reinforces a trajectory that has been building since NIST finalized its first PQC standards: the policy window for voluntary early adoption is closing, and the compliance window is opening. Organizations that have already begun cryptographic agility programs — the ability to swap cryptographic primitives without full system rebuilds — are structurally better positioned than those starting from scratch.
For the quantum hardware community, the indirect message is that the perceived proximity of CRQC capability is now influencing G7-level policy. That's a signal to enterprise buyers, too: the hardware roadmaps being published by companies across the superconducting, trapped-ion, and neutral atom sectors are being read at the highest levels of government security planning, even when specific systems go unnamed in official documents.
---
## Key Takeaways
- The G7 Cybersecurity Working Group has formally declared PQC migration an immediate necessity, not a future consideration.
- The "store now, decrypt later" threat is active today — adversaries can archive encrypted data now for future quantum decryption.
- A phased, risk-based transition strategy is recommended, starting with the most critical cryptographic assets.
- The group identifies five priority areas for PQC migration and emphasizes coordinated public-private action.
- Non-compliance may lead to exclusion from public procurement processes in G7 countries.
- Lack of organizational awareness remains a primary barrier to adoption, according to the group's findings.
- No CRQC timeline is specified, but the group's language signals that recent hardware advances have accelerated policy urgency.
---
## Frequently Asked Questions
**What is a cryptographically relevant quantum computer (CRQC)?**
A CRQC is a quantum computer powerful enough to break current public-key cryptography by solving factorization and discrete logarithm problems. No publicly confirmed CRQC exists yet, but the G7 Cybersecurity Working Group has flagged recent hardware advances as sufficient to require immediate PQC transition planning rather than continued deferral.
**What is "store now, decrypt later" and why does it matter now?**
Store now, decrypt later (SNDL) is an attack strategy where adversaries intercept and archive encrypted communications today, intending to decrypt them once a CRQC becomes available. It represents an active threat to any data requiring long-term confidentiality — government communications, personal data, and trade secrets — even before a CRQC exists.
**What does the G7 recommend organizations do first?**
The G7 Cybersecurity Working Group recommends starting with a comprehensive inventory of cryptographic assets, identifying the most critical data, mapping system dependencies, and developing a detailed transition plan aligned with national cybersecurity authority timelines.
**Will PQC compliance become mandatory for government contracts?**
The G7 statement explicitly warns that delayed PQC migration could result in exclusion from public procurement processes. While this is not yet a binding directive, it signals the direction of travel for government contracting requirements across G7 nations.
**What is post-quantum cryptography (PQC)?**
PQC is a class of cryptographic algorithms designed to resist attacks from both classical and quantum computers. Unlike current public-key systems (RSA, ECC), PQC algorithms are based on mathematical problems believed to be hard for quantum computers to solve. NIST has already finalized initial PQC standards that organizations can begin implementing.
BREAKING
G7 Declares PQC Transition a Collective Urgency
Published: September 6, 2026 at 16:56 EDTLast updated: September 7, 2026 at 09:29 EDTBy Jonas Vogel, Senior EditorLast reviewed by Jonas Vogel on September 7, 20267 min read
G7 Cybersecurity Working Group declares PQC transition an immediate collective obligation, not a future individual problem.
post-quantum-cryptographypqcg7crqccybersecuritystore-now-decrypt-laterpolicy