Post-Quantum Cryptography Shift Demands Governance Over Physics Expertise
Organizations moving to post-quantum cryptography can succeed by treating the transition as a staged migration program rather than a technical puzzle, according to security leaders at Daiwa Institute of Research and Deloitte.

The shift to post-quantum cryptography becomes tractable when framed as an organizational migration rather than a mathematical challenge. As enterprises begin moving from planning phases into actual deployment, they can validate components that are ready today while accounting for pieces still in development.
Technical transitions of even modest scope typically stretch across multiple years once organizational budgets, product lifecycles and governance structures come into play. Hands-on testing and phased rollout strategies can break down the problem and make the undertaking less opaque, according to Colin Soutar, managing director at Deloitte Touche Tohmatsu Ltd.
I would take the word 'quantum' out of it. I think that the misconception is that one needs to be an expert [or] have a background in physics to understand what's needed here. There is a threat out there in the future … and the steps to mitigate that are generally known. Working through it again is relatively straightforward, albeit large and complex.
Colin Soutar, Deloitte Touche Tohmatsu Ltd.
Soutar and Sadaaki Yamazaki, senior security specialist for the Digital Solution R&D Department at Daiwa Institute of Research Ltd., discussed implementation strategies with Tim Hollebeek, vice president of industry standards at DigiCert Inc., during DigiCert's World Quantum Readiness Day broadcast.
Starting with components already available
Daiwa conducted a hybrid approach trial within a test environment for Daiwa Securities' online trading platform. The proof of concept deployed a post-quantum-capable load balancer to assess Transport Layer Security behavior under production-like loads, Yamazaki explained.
In our measurements, the average TLS handshake time increased by approximately 1.2 milliseconds. In our environment, which operates in a high-bandwidth data center, the impact was negligible. However, PQC increased both message sizes and packet counts. Organizations operating over wireless networks or constrained bandwidth environments should carefully validate the impact in their own environments.
Sadaaki Yamazaki, Daiwa Institute of Research Ltd.
Readiness differs across cryptographic operations. Federal Information Processing Standard 203, released by the National Institute of Standards and Technology, serves as one component in the incremental strategy Yamazaki outlined.
We understand the attraction of doing everything at once, but key establishment and digital signature are at different stages of readiness. For key establishment, ML-KEM has already been standardized, and hybrid key exchange such as X25519MLKEM768 is becoming available in products and platforms. This is also the part of TLS that can address the 'harvest now, decrypt later' risk, so there is a security benefit to adopting it earlier.
Sadaaki Yamazaki, Daiwa Institute of Research Ltd.
Governance becomes the limiting factor at scale
When enterprises undertake PQC migration, the challenge shifts from pure technology to resource allocation and sequencing. Mapping every system remains a long-term objective, but starting with comprehensive discovery can stall momentum when infrastructure and accountability span many teams, Soutar noted.
About two years ago, we actually started advocating not to do a full discovery in the first instance. Ultimately, you will build towards that, but we think it's much more important to iteratively tackle this, show some results as well [and] start to do discovery around your most critical assets or systems.
Colin Soutar, Deloitte Touche Tohmatsu Ltd.
Enterprise public key infrastructure touches certificates, authentication mechanisms, code signing, application programming interfaces, virtual private networks and cloud platforms. These functions span systems and applications controlled by separate organizational units, according to Yamazaki.
The difficult part is not replacing a single algorithm. The difficult part is identifying where cryptography is used, understanding dependencies and coordinating migration across the organization. From our perspective, technology is only part of the challenge. Governance and cryptographic inventory are likely to be the larger challenges.
Sadaaki Yamazaki, Daiwa Institute of Research Ltd.