Quan­tum Risk: Is Your Encryp­ti­on Future-Proof?

Why inter­na­tio­nal busi­nesses in the EU must prepa­re for post-quantum cyber­se­cu­ri­ty risks

Quan­tum com­pu­ting has long been con­side­red a distant tech­no­lo­gi­cal deve­lo­p­ment. Recent advan­ces, howe­ver, indi­ca­te that prac­ti­cal appli­ca­ti­ons may arri­ve much soo­ner than pre­vious­ly expec­ted. This rai­ses a cri­ti­cal ques­ti­on for inter­na­tio­nal com­pa­nies ope­ra­ting in the EU or Ger­ma­ny: will today’s encryp­ti­on methods still be con­side­red secu­re in the coming years? This ques­ti­on is no lon­ger purely tech­ni­cal — it is incre­asing­ly rele­vant from a regu­la­to­ry com­pli­ance per­spec­ti­ve under frame­works such as NIS‑2, DORA and the Cyber Resi­li­ence Act (CRA).

The emer­ging quan­tum threat

Many wide­ly used encryp­ti­on methods rely on mathe­ma­ti­cal pro­blems that are prac­ti­cal­ly unsol­va­ble for clas­si­cal com­pu­ters. Powerful quan­tum com­pu­ters could fun­da­men­tal­ly chall­enge this assump­ti­on. In this con­text, the term “Q‑Day” is often used to descri­be the point in time when quan­tum com­pu­ters are capa­ble of brea­king estab­lished cryp­to­gra­phic algo­rith­ms. Important­ly, the risk does not begin at Q‑Day. Alre­a­dy today, atta­ckers may inter­cept and store encrypt­ed data with the inten­ti­on of decryp­ting it in the future once more powerful tech­no­lo­gies beco­me available (“har­ve­st now, decrypt later”). This is par­ti­cu­lar­ly rele­vant for data requi­ring long-term con­fi­den­tia­li­ty, such as trade secrets, sen­si­ti­ve busi­ness infor­ma­ti­on, or security-critical data.

Sta­te of the art as a moving target

EU cyber­se­cu­ri­ty frame­works requi­re com­pa­nies to imple­ment “appro­pria­te tech­ni­cal and orga­niza­tio­nal mea­su­res,” inclu­ding robust encryp­ti­on. The bench­mark for the­se obli­ga­ti­ons is the “sta­te of the art,” which is inher­ent­ly dyna­mic. Under NIS 2, com­pa­nies must regu­lar­ly reas­sess whe­ther their cyber­se­cu­ri­ty mea­su­res remain ade­qua­te in light of fore­seeable tech­no­lo­gi­cal deve­lo­p­ments. This includes eva­lua­ting the resi­li­ence of exis­ting cryp­to­gra­phic mecha­nisms against emer­ging thre­ats such as quan­tum com­pu­ting. The CRA extends simi­lar requi­re­ments to manu­fac­tu­r­ers of pro­ducts with digi­tal ele­ments. The­se must ensu­re cyber­se­cu­ri­ty throug­hout the expec­ted life­cy­cle of their pro­ducts. For long-lived pro­ducts, this impli­es that cryp­to­gra­phic methods must be adap­ta­ble or replaceable over time. A docu­men­ted risk assess­ment is cen­tral to this requi­re­ment, taking into account pro­duct life­cy­cle, sen­si­ti­vi­ty of pro­ces­sed data, cur­rent cryp­to­gra­phic methods, their poten­ti­al vul­nerabi­li­ties, and tech­ni­cal update capabilities.

Prac­ti­cal impli­ca­ti­ons for inter­na­tio­nal companies

Post-quantum cryp­to­gra­phy should alre­a­dy be inte­gra­ted into enter­pri­se risk manage­ment. Com­pa­nies ope­ra­ting in or tar­ge­ting the EU mar­ket should sys­te­ma­ti­cal­ly iden­ti­fy and docu­ment their use of cryp­to­gra­phic tech­no­lo­gies, the data sen­si­ti­vi­ty and requi­red pro­tec­tion level, assess sys­tem life­cy­cles, and eva­lua­te whe­ther future migra­ti­on or updates are tech­ni­cal­ly feasible.

For manu­fac­tu­r­ers and tech­no­lo­gy pro­vi­ders, this has direct impli­ca­ti­ons for pro­duct design, tech­ni­cal docu­men­ta­ti­on, vul­nerabi­li­ty manage­ment, and con­trac­tu­al frame­works within sup­p­ly chains. Orga­niza­ti­ons fal­ling within the scope of NIS 2 should extend their cyber­se­cu­ri­ty stra­te­gies to expli­cit­ly include quan­tum resi­li­ence considerations.

We sup­port you in asses­sing the regu­la­to­ry impli­ca­ti­ons of cryp­to­gra­phy and secu­ri­ty con­cepts, eva­lua­ting post-quantum risks, defi­ning neces­sa­ry mea­su­res, and estab­li­shing audit-proof cyber­se­cu­ri­ty documentation.

back

Stay up-to-date

We use your email address exclusively for sending our newsletter. You have the right to revoke your consent at any time with effect for the future. For further information, please refer to our privacy policy.