Quantum computers promise to break what digital trust rests on. Experts in the discussion warn that the time to prepare is now, even though we do not know the exact tipping point. They compare it to the year 2000, only this time we do not know when the flag will drop.
Quantum changes the rules of the game
Today’s online world rests on cryptography: we encrypt data, verify identities, and sign documents. Algorithms used for years can, however, be broken given sufficient computing power, and with the advent of quantum computing this moment will rapidly draw nearer. Quantum computers solve certain tasks in a fundamentally different way, as if a third dimension were added to two. If it became possible to compute the private key from the public key, the chain of trust would collapse.
The consequences would affect not only confidentiality, but especially authenticity and enforceability. A certificate on a website might no longer prove that it belongs to a bank, and an electronic signature would not be reliable evidence in legal relations. Electronic communication with the state and between companies would grind to a halt, from timestamps to institutional seals. The panelists do not consider a return to paper realistic in a digitally dependent society.
When will the tipping point arrive, and why not wait
When will it happen? The discussants cite estimates around 2029–2030, which also align with the plans of major players and signals from standardization authorities in the EU and the USA. However, no one knows the exact date — “the year 2030” may arrive sooner than we expect. In the meantime, the scenario of harvest now, decrypt later already looms: leaked encrypted data can be stored today and decrypted tomorrow.
Even without quantum, we have seen how fragile trust is: an attack on the land registry was enough. In elections, therefore, new systems should be designed with post‑quantum protection from the outset, although the next cycles may perhaps still run on the current infrastructure. The key point, however, is that delaying preparation does not pay. When the tipping point comes and the infrastructure is not ready, “tough tomorrows” will follow.
What to do today: inventory, plan, migration
The first step is an inventory of cryptographic assets: everywhere keys, certificates, and algorithms are used — in applications, operating systems, network devices, or storage. This is followed by an analysis of the lifespan of data and signatures and the setting of priorities for what needs to be protected or further safeguarded first. On that basis, the organization prepares an action plan for becoming post‑quantum ready. Methodologies, checklists, and tools already exist today, and security and consulting firms can help with them.
The U.S. NIST has already published post‑quantum algorithms and implementations are available, but for qualified signatures they are not yet a full‑fledged standard. Therefore, the transition will need to be planned so that it respects legislation while also protecting long‑term evidence — from re‑signing to re‑encrypting selected archives. You should count on software and firmware updates, and in some cases even the replacement of devices. The task is comparable in scope to the “year 2000”, only this time we do not know the deadline — all the more reason to start right away.