Quantum computing is often discussed as a future threat to encryption. For enterprises, however, the more important question is not when a cryptographically relevant quantum computer will arrive. It is how long sensitive business information needs to remain protected and whether the communications infrastructure protecting that information can adapt in time.
Patient records, financial disclosures, M&A conversations, legal strategy, government and defence communications commonly need to stay confidential for ten, twenty, sometimes thirty years. That makes business communications an important part of the post-quantum security conversation.
A quantum computer capable of breaking today’s encryption does not need to exist yet for that data to already be at risk. That is the premise behind harvest now, decrypt later: encrypted data intercepted and stored today, unreadable now, decrypted the moment the computing power to do so exists. An attacker can collect encrypted information today and retain it until technology becomes capable of decrypting it.
For communications containing information that must remain confidential for years or decades, the risk therefore exists before a quantum computer capable of breaking current encryption ever becomes operational. CISA, the NSA and NIST have said as much themselves, jointly, in writing. The existing research compiled for this discussion identifies this as a key reason organisations are being urged to begin their post-quantum migration now.
Why the Encryption Architecture Matters as Much as the Algorithm
Most of the public conversation about post-quantum cryptography stops at the algorithm: NIST finalised ML-KEM, the lattice-based standard known as FIPS 203, in 2024, and the industry has largely treated adopting it as a checkbox. An algorithm swap alone does not protect a business if the surrounding architecture was not built with the same discipline.
At NetSfere, we treat quantum resistance as a platform-level design decision, not a patch. Our messaging platform runs on ML-KEM 1024, the highest security parameter NIST defines, combined with a zero-knowledge architecture, so that even we cannot access the content of a customer’s communications. It operates alongside AES-256 encryption, hybrid cryptography and forward secrecy, within an architecture designed to provide enterprises with security and administrative controls appropriate for regulated environments.
Crypto-Agility Is the Real Long-Term Strategy
Post-quantum standards will keep evolving as the field learns more, the same way classical cryptography has evolved for decades. Enterprises that build toward a single algorithm and stop are setting themselves up for another disruptive migration in a few years. The more durable approach is crypto-agility: building systems that can adopt the next generation of cryptographic standards without a platform redesign. For enterprises with long-lived data and complex technology environments, that distinction can determine whether the next security transition is manageable or disruptive.
Regulation Has Caught Up, and the Market Should Expect It To
Executive Order 14412, signed in June 2026, gives US federal agencies and their contractors concrete migration deadlines running through 2031. Whatever an organisation’s own timeline, it should expect PQC readiness to become a standard procurement question well before then, particularly in healthcare, financial services, government and critical infrastructure.
The better approach is to begin with the data that matters most, understand where vulnerable cryptography is being used, identify systems that will take the longest to migrate, and prioritise technologies that can support post-quantum standards and future cryptographic changes.
NetSfere brings post-quantum cryptography into secure business messaging without compromising the enterprise controls that IT, security, healthcare, legal and government organisations require. We hold FedRAMP Ready status, which reflects the kind of federal security bar this order is pushing the entire market toward, and our messaging platform already runs on NIST-standardised ML-KEM 1024 rather than treating PQC as a future roadmap item.
The Bar Enterprises Should Set
Quantum computing does not replace the cybersecurity threats organisations face today. Ransomware, credential theft, data breaches, insider threats and attacks targeting communications platforms remain immediate and evolving risks. Preparing for the post-quantum era therefore cannot come at the expense of protecting against the threats enterprises are dealing with now.
Organisations need strong end-to-end encryption, robust authentication and access controls, enterprise governance and compliance capabilities, while also ensuring their cryptographic architecture can evolve to address future quantum threats.
At NetSfere, our approach is not simply to make messaging quantum-ready, but to provide a secure and compliant enterprise communications platform designed to protect sensitive business conversations throughout their lifecycle, while preparing organisations for the threats of tomorrow.
The author is president and CEO of NetSfere. Views are personal.




