Quantum Security
4 mins read

G7 Advisory: Businesses Must Prepare for Quantum Risk Now

Horizen Labs Quantum Security TeamSeptember 8, 2026

On September 3, 2026, the G7 Cybersecurity Working Group and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a joint advisory naming harvest-now-decrypt-later (HNDL) a present-tense threat, not a future one. Seven governments and the agency responsible for U.S. federal civilian cybersecurity have never said this together before.

Nothing in "Preparing for the Post-Quantum Era: A Call to Action" is new information to anyone who has been paying attention. What changed is who signed it, and when. Canada, France, Germany, Italy, Japan, the United Kingdom, and the United States moving in the same week is a signal to procurement committees and board risk registers, not a technical disclosure. If your cryptographic exposure is still unmapped, the excuse that this is a speculative, future problem no longer holds up in a board meeting.

Most Organizations Assume This Is a Defense-Sector Problem. It Isn't

Many readers of a G7 and CISA advisory might assume it applies to defense contractors and government agencies, because the loudest quantum-security deadline, CNSA 2.0, is scoped specifically to U.S. National Security Systems. That assumption is wrong, and the advisory itself says so directly: it stresses that the threat needs addressing across all sectors, not just critical infrastructure operators.

The regulatory record outside defense confirms it.

  • Financial services have carried their own quantum-relevant obligation since DORA required demonstrated crypto-agility starting January 2025, and PCI DSS 4.0 activated future-dated cryptographic controls affecting payment card data in March 2025. Neither framework has anything to do with National Security Systems.
  • DigiCert's July 2026 Quantum Readiness Outlook, an independent survey of 1,001 enterprise IT and security decision-makers across the United States, United Kingdom, and Australia, found that 87 percent of organizations are now planning, testing, or implementing quantum-resistant cryptography, yet only 7 percent have deployed it across most of their certificate estate.

Those are commercial enterprises, not defense contractors, and the gap between planning and deployed protection shows up with no CNSA 2.0 obligation in sight, which is the clearest evidence this was never a defense-only problem.


The Regulatory Runway Is Now Measured in Weeks

The regulatory calendar is no longer an abstraction. On September 21, 2026, FIPS 140-2 certificates move to Historical status, meaning only FIPS 140-3 validated cryptographic modules are eligible for new federal procurement. That date is two weeks from this advisory's publication. It sits ahead of a sequence of dates that were already on the calendar: the National Institute of Standards and Technology (NIST) finalized its post-quantum cryptography standards, FIPS 203, 204, and 205, in August 2024. The NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requires all new acquisitions for National Security Systems to be compliant starting January 1, 2027. The EU's post-quantum cryptography roadmap mandates critical infrastructure migration by 2030. In financial services, DORA has required demonstrated crypto-agility since January 2025, and PCI DSS 4.0 activated future-dated cryptographic controls in March 2025.

None of these deadlines is coordinated with each other by design. They are coordinated by consequence: they all trace back to the same underlying constraint, which is that migrating cryptographic infrastructure inside a large organization takes years, not months, and the agencies setting these dates know it.


Cryptographic Inventory Comes Before Cryptographic Migration

The instinct after reading an advisory like this is to reach for a solution. That instinct is premature. An organization cannot migrate what it has not inventoried, and in practitioner terms, the most consistent failure point in early cryptographic inventories is not the primary application. It is the middleware, the message queues, and the third-party integrations where TLS defaults were set once, years ago, and never revisited by anyone who understood what algorithm was running underneath.

A cryptographic exposure assessment answers three questions before any migration plan is credible:

  1. where public-key cryptography is actually in use across the estate,
  2. which of those instances protect data with a confidentiality requirement measured in years or decades,
  3. and which regulatory deadline applies first.

That assessment does not require ripping out infrastructure or committing to a vendor. It requires a clear, board-ready picture of exposure, which is the actual gap the ISACA data points to.

The Boards That Treat This as a Governance Item Will Be Ahead

The organizations that come out of 2027 in the strongest position will not be the ones with the most advanced cryptography. They will be the ones that treated cryptographic exposure as a standing board risk item in 2026, the same way they treat any other risk with a known deadline and an unknown cost of inaction.

The G7 and CISA advisory does not create that risk. It confirms that seven governments have stopped treating it as optional to disclose. Whether an individual organization continues to treat it as optional to act on is now a governance decision, not a technical one.

Quantum SecurityGovernment Policy
Horizen Labs Quantum Security Team

About Horizen Labs Quantum Security Team

Horizen Labs delivers expert-led quantum security consulting, helping organizations assess and address cryptographic exposure before regulatory and threat timelines force the issue.