CISA and G7 Push PQC Into Procurement

CISA and the G7 Cyber Security Working Group have issued a call to action on post-quantum cryptography, urging governments and organizations to start planning the transition now. The joint note lays out five priorities: raise awareness, build national strategies, advance research and development, foster public-private partnerships, and fold PQC into cybersecurity requirements and procurement. The point is not that quantum computers are breaking today’s cryptography today. It is that the buying and standards choices made now will decide which PQC implementations become the defaults later, especially for identity, VPN, PKI, and secure communications systems that depend on certificates and long-lived trust. For government buyers and vendors, this is a planning signal with real downstream effects: early contract language can lock in interoperable paths or create upgrade debt that lasts for years. Organizations that wait for the threat to feel immediate may still inherit the migration constraints set by this round of procurement decisions.

Part of the PlainSec briefing for 2026-09-03

Every edition of this story: CISA and G7 Push PQC Into Procurement

Sources