Jessica Entwistle
September 4 2026
CyberScoop reports that the G7 nations have issued a joint statement urging governments and industry to accelerate preparations for post-quantum cryptography. The statement warns that quantum computing capable of breaking current encryption standards can no longer be treated as a distant or theoretical possibility, and that organisations must begin transitioning to quantum-resistant algorithms now. The warning reflects growing concern that adversaries may already be harvesting encrypted data with the intention of decrypting it once quantum computing capabilities mature, a threat known as "harvest now, decrypt later". The G7 statement emphasises that the transition to post-quantum cryptography will take years and requires coordinated action across supply chains, standards bodies, and critical infrastructure sectors.
For UK organisations, this represents a significant governance and planning challenge. Post-quantum cryptography is not a simple software update; it requires identifying where cryptography is used across your estate, understanding which systems and protocols are vulnerable to future quantum attacks, and planning a phased transition that maintains security and interoperability throughout. The "harvest now, decrypt later" threat means that data encrypted today using current standards may be at risk in the future, which has particular implications for organisations handling long-lived sensitive data such as health records, financial information, intellectual property, legal documents, or government secrets. If an adversary is harvesting your encrypted data today, they may be able to decrypt it in five or ten years when quantum computing capabilities advance. The G7 statement signals that this is now a priority at the highest levels of government, and that regulatory or compliance expectations may follow, particularly for critical infrastructure, defence, finance, and public sector organisations.
UK businesses should begin understanding their cryptographic inventory: where encryption is used, which algorithms are in place, and which systems would be vulnerable to quantum attacks. Consider whether your long-term data protection strategies account for future quantum threats, particularly for data with retention periods extending beyond the next decade. Review whether your technology roadmaps include post-quantum cryptography as a planning assumption, and whether your suppliers and software vendors have published plans for transitioning to quantum-resistant algorithms. This is not an immediate crisis, but it is a transition that requires early planning and coordination with suppliers, standards bodies, and industry peers. For organisations in regulated sectors, consider whether your risk assessments and compliance frameworks account for quantum threats, and whether your governance structures have clear ownership of cryptographic strategy. This is also a useful moment to engage with your technology leadership and ensure that post-quantum cryptography is understood as a strategic planning issue, not just a technical one.
Source: CyberScoop