Skip to main content
AI Engineer
post-quantum cryptography
ai engineer
asd

Post-Quantum Cryptography in Australia 2026: ASD Roadmap, NIST Standards, and What Businesses Must Do Now

The short answer

The ASD requires a refined post-quantum cryptography plan by end of 2026. Learn the NIST standards, ASD milestones, and how an AI engineer can help.

General information only — not personal financial advice.

MyMoney® Editorial15 September 2026 8 min read

Australian businesses are facing a cryptographic deadline that many have not yet registered on their risk radar. The Australian Signals Directorate (ASD) has established a mandatory roadmap requiring organisations to have a refined post-quantum cryptography (PQC) transition plan in place by the end of 2026 — with critical system migrations underway by 2028 and full transition completed by 2030. For businesses that rely on encrypted data, digital signatures, or secure communications, the time to act is now. An AI engineer with cryptographic expertise is an essential partner in navigating this transition.

Understanding Post-Quantum Cryptography and Why It Matters

Post-quantum cryptography refers to cryptographic algorithms that are designed to be secure against attacks from both classical computers and quantum computers. The urgency of this transition stems from the anticipated arrival of cryptographically relevant quantum computers (CRQCs) — machines powerful enough to break the encryption standards that currently protect most of the world's digital infrastructure.

The encryption algorithms most at risk include RSA, Elliptic Curve Cryptography (ECC), Diffie-Hellman key exchange, and ECDSA digital signatures. These algorithms underpin HTTPS connections, digital certificates, VPNs, email encryption, and virtually every secure digital transaction. A sufficiently powerful quantum computer could break these algorithms in hours or days, rendering decades of encrypted data vulnerable.

The threat is not purely theoretical. Security researchers have documented a strategy known as "harvest now, decrypt later" (HNDL), in which adversaries capture and store encrypted data today with the intention of decrypting it once quantum computing capability matures. For data with long-term confidentiality requirements — patient records, legal documents, financial contracts, government intelligence — the HNDL threat is already active.

The ASD's Mandatory Transition Roadmap

The Australian Signals Directorate has established a clear, mandatory timeline for Australian organisations to transition to post-quantum cryptography. The key milestones are:

  • End of 2026 — Organisations must have a refined PQC transition plan in place. This includes a cryptographic inventory, risk assessment, and documented migration strategy.
  • End of 2028 — Migration of critical systems to quantum-resistant algorithms must be underway. Organisations cannot wait until 2030 to begin implementation.
  • End of 2030 — Full transition must be complete. Traditional asymmetric cryptography (RSA, Diffie-Hellman, ECDH, ECDSA) will be considered unapproved for critical security applications after this date.

For Commonwealth entities, these requirements are embedded in the Australian Information Security Manual (ISM). Control ISM-1917 mandates the development and maintenance of a PQC transition plan. Procurement control ISM-2073 requires that new cryptographic equipment, applications, and libraries support specific quantum-resistant standards by 2030.

While the ISM applies directly to government and regulated entities, its influence extends throughout the economy via procurement requirements. Businesses supplying services to banking, critical infrastructure, defence, or government sectors will increasingly face PQC-readiness questionnaires as part of their contractual obligations.

The NIST Standards: What Australian Businesses Must Implement

The technical foundation for post-quantum cryptography is provided by the standards finalised by the U.S. National Institute of Standards and Technology (NIST) in 2024. Australian guidance from the ASD aligns with these international standards:

  • FIPS 203 (ML-KEM) — Module-Lattice-Based Key Encapsulation Mechanism, used for key exchange and encryption. The ASD recommends ML-KEM-1024 for long-term security.
  • FIPS 204 (ML-DSA) — Module-Lattice-Based Digital Signature Algorithm, used for digital signatures and authentication. The ASD recommends ML-DSA-87 for high-security applications.
  • FIPS 205 (SLH-DSA) — Stateless Hash-Based Digital Signature Algorithm, providing an alternative signature scheme based on different mathematical assumptions.

Many cloud providers and browsers currently offer "hybrid" PQC configurations that combine ML-KEM-768 with traditional algorithms. While these hybrid approaches provide some protection, the ASD explicitly identifies them as transitional measures. Organisations that rely solely on vendor-inherited hybrid configurations may face a second, costly migration cycle, as these setups will not meet the 2030 requirements without further action.

Common Mistakes and Red Flags

Australian businesses approaching their PQC transition should be alert to the following pitfalls:

  • Assuming vendor inheritance is sufficient — Relying on cloud providers or browser vendors to manage cryptographic configurations without understanding what is actually deployed is a significant risk. Vendor defaults may not meet ASD requirements.
  • Failing to conduct a cryptographic inventory — Many organisations do not know where cryptography is used across their systems, including shadow IT, third-party integrations, and legacy applications. Without a complete inventory, a transition plan cannot be developed.
  • Ignoring the HNDL threat for historical data — Data that was encrypted years ago using vulnerable algorithms may already have been harvested. Organisations with long-term data retention obligations should assess their historical exposure.
  • Treating PQC as a future problem — The ASD's 2026 deadline for a refined transition plan is current, not future. Organisations that have not yet begun planning are already behind schedule.
  • Neglecting supply chain exposure — Even businesses that are not directly subject to ISM requirements may face PQC obligations through their supply chain relationships with regulated entities.

Australian Regulatory Context

Post-quantum cryptography obligations in Australia sit at the intersection of several regulatory frameworks. The ASD's Australian Information Security Manual (ISM) provides the primary technical guidance and mandatory controls for government and regulated entities. The Security of Critical Infrastructure Act 2018 (SOCI Act) imposes obligations on critical infrastructure operators — including energy, water, communications, and financial services — to manage cyber risks, which increasingly includes quantum-related cryptographic risks.

The Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme require organisations to protect personal information using reasonable security measures. As quantum computing capability matures, continuing to rely on quantum-vulnerable encryption may no longer constitute "reasonable" security, creating potential Privacy Act exposure for organisations that fail to transition.

The Australian Prudential Regulation Authority (APRA) has also signalled interest in quantum risk through its CPS 234 Information Security standard, which requires APRA-regulated entities to maintain information security capabilities commensurate with the threats they face. An AI engineer with expertise in cryptographic risk can help regulated entities assess their PQC obligations under each of these frameworks.

Practical Steps: Building Your PQC Transition Plan

The ASD's requirement for a refined transition plan by end of 2026 means organisations need to move quickly. A structured approach includes the following steps:

  • Cryptographic discovery — Map all instances where cryptography is used across your systems, including applications, APIs, databases, network infrastructure, and third-party dependencies.
  • Risk prioritisation — Identify data with long-term confidentiality requirements and systems where cryptographic failure would have the highest impact. These are the priority targets for early migration.
  • Crypto-agility assessment — Evaluate whether your systems can support rapid replacement of cryptographic primitives as standards evolve. Hard-coded algorithms are a significant technical debt risk.
  • Vendor engagement — Engage with software and hardware vendors to understand their PQC roadmaps and ensure procurement decisions account for quantum-resistant capability requirements.
  • Pilot implementation — Begin implementing NIST-approved algorithms in lower-risk systems to build organisational capability before tackling critical infrastructure.
  • Documentation and governance — Maintain a documented transition plan that satisfies ISM-1917 requirements and can be presented to regulators, auditors, or procurement counterparties on request.

How MyMoney® Can Help

Post-quantum cryptography is a highly specialised domain that sits at the intersection of advanced mathematics, software engineering, and regulatory compliance. Most businesses do not have the in-house expertise to develop and execute a PQC transition plan without external support. An AI engineer with cryptographic expertise can conduct the cryptographic inventory, assess your risk exposure, design a migration architecture, and help you meet the ASD's 2026 planning deadline.

MyMoney® connects Australian businesses with AI engineers and technology consultants who specialise in cryptographic security, quantum risk, and regulatory compliance. Whether you need a PQC readiness assessment, a documented transition plan, or hands-on implementation support, the right professional is available through our marketplace.

Post a Brief to describe your post-quantum cryptography needs and receive proposals from qualified AI engineers. Or Browse AI Engineers to find a specialist who can help your business meet the ASD's mandatory transition milestones and protect your data against the quantum threat. The 2026 deadline is approaching — the time to act is now.

This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).

Need Professional Help?

Post a brief and let verified professionals compete with transparent, scored proposals.