The G7 Wants Post-Quantum Migration Now—Inventory Comes First

On September 3, 2026, the G7 Cybersecurity Working Group released a joint call urging public- and private-sector organizations to begin transitioning from quantum-vulnerable public-key cryptography to post-quantum cryptography now. The Canadian Centre for Cyber Security’s September 3 notice says the arrival date of a cryptographically relevant quantum computer remains uncertain, but preparation should not wait.
The September 3 call does not demand an immediate, organization-wide algorithm replacement. It sets out a phased, risk-based opening sequence: inventory cryptographic assets, identify critical systems, map dependencies and develop transition plans. That sequence makes discovery and prioritization the work to begin now, while particular deployments still have to follow national timelines and the availability of suitable products and implementations.
Five priorities make migration a coordinated program

The call treats post-quantum cryptography, or PQC, as an economic and cybersecurity transition involving governments, researchers, technology suppliers and the organizations that operate digital systems. It defines five priority areas:
- Raise awareness of quantum-related cybersecurity risks and the benefits of PQC.
- Develop national strategies that support the adoption and availability of PQC technologies.
- Advance research and development so quantum-resistant approaches can move into practical deployment.
- Strengthen public-private partnerships for sharing expertise, resources and implementation practices.
- Integrate PQC into cybersecurity requirements so the transition becomes part of formal security expectations.
The priorities divide responsibility without making the work sequential at the policy level. Governments can establish national direction and requirements; researchers and vendors can develop compatible, tested implementations; and operators can determine where vulnerable cryptography exists in their environments. Progress in one area does not remove the need for the others.
This framing also explains why migration is larger than installing a new cryptographic library. Public-key mechanisms support confidentiality, authentication and integrity across interconnected systems. Changing one mechanism can affect software, devices, communications and services supplied by third parties, so a transition plan needs both technical scope and coordination.
Inventory defines what actually has to change

A cryptographic inventory answers the question that must come before a replacement decision: where is vulnerable public-key cryptography being used, and what does each use protect? A useful inventory connects cryptographic assets to the relevant systems, sensitive data and operational functions. Without that context, an organization may know which algorithms it permits but still not know which applications or services require migration.
Dependency mapping adds the second half of the picture. Some cryptography can be changed directly by an internal engineering team; other mechanisms are embedded in purchased software, managed platforms, network equipment or supplier-controlled services. Selecting an algorithm without identifying those constraints can produce a technically sound choice that a critical product cannot yet support.
Prioritization then distinguishes the systems that need early attention from those that can follow normal replacement cycles. ITPro’s September 7 account confirms that the G7 recommends a phased, risk-based strategy built around sensitive assets, a cryptographic inventory, dependency mapping and a transition plan.
Data lifetime is part of that ranking. In a “harvest now, decrypt later” attack, an adversary collects encrypted material before a capable quantum computer exists and retains it for possible future decryption. Information that must remain confidential for many years can therefore create an exposure today even though the machine needed to exploit it has not been built.
Planning starts now; production changes remain staged
The immediate work is readiness rather than a blanket cryptographic cutover. The G7’s sequence can be translated into four connected tasks:
- Locate cryptographic assets and identify the systems and data they protect.
- Prioritize critical systems and long-lived sensitive information according to risk.
- Map internal, product and supplier dependencies that govern when changes are possible.
- Build a phased transition plan aligned with the relevant national cybersecurity authority’s guidance and timelines.
Those tasks can begin without committing every system to a particular implementation. The inventory reveals which cryptographic functions are involved; dependency mapping shows where vendor support, interoperability or coordinated upgrades will be required. Testing can then address the actual environments in scope instead of an assumed standard configuration.
Early planning can also be coordinated with procurement and scheduled refreshes. TechRadar’s September 7 report says the guidance favors PQC-capable purchases and quantum-safe replacements during normal renewal cycles where appropriate, while warning that delayed transitions may affect competitiveness or eligibility for contracts, including public procurement.
That is not an instruction to postpone migration until every supplier is ready. It is a boundary between work that is already actionable and deployment decisions that depend on tested support. Organizations can establish scope, priorities and supplier requirements now; production changes still need to respect change management, compatibility and the deadlines set by their national authorities.
The quantum deadline remains uncertain

The call does not announce that a cryptographically relevant quantum computer exists, and it does not establish one universal date for its arrival. Its urgency rests on two different clocks: encrypted data may retain value long enough to be collected now and attacked later, while complex migrations can take years to discover, coordinate, test and complete.
The confirmed development is therefore narrower—and more actionable—than a prediction of an imminent “Q-Day.” The G7 wants coordinated preparation and phased migration to begin now. What remains unsettled varies by jurisdiction and system: national deadlines, detailed requirements, supplier road maps, compatible products and validated implementations.
Inventory comes first because those later decisions require an accurate migration scope. Until an organization knows which cryptographic assets it operates, what they protect and which internal or external systems depend on them, it cannot reliably prioritize replacements or judge whether a proposed algorithm and implementation will work across the affected environment.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.