Post-quantum cryptography migration has quietly become one of the most consequential infrastructure projects in the telecom industry — and one of the least discussed outside of standards bodies, security teams, and a handful of specialist conferences. While the trade press spends its attention on AI data center buildouts, spectrum auctions, and the satellite-to-phone race, a slower and arguably more structural deadline is closing in on every carrier, hyperscaler, and enterprise network operator: the point at which a sufficiently capable quantum computer can break the RSA and elliptic-curve cryptography that currently authenticates almost every SIM, secures almost every signaling link, and signs almost every piece of network software in use today.
This is not a hypothetical problem for the 2030s. It is an active planning problem for 2026, with regulatory deadlines already on the books, a widening gap between stated intent and actual deployment, and a threat model — data harvested today, decrypted whenever the hardware catches up — that makes “wait and see” a genuinely risky strategy rather than a cautious one.
The threat doesn’t wait for the computer to exist
The cryptography protecting telecom networks today — RSA and elliptic-curve algorithms embedded in TLS, IPsec, SSH, and the public-key infrastructure behind eSIM provisioning — relies on math problems that are hard for classical computers but, in theory, tractable for a sufficiently large fault-tolerant quantum computer. No such machine exists yet. Estimates vary widely on when one might: GSMA’s Post Quantum Telco Network Task Force puts the probability of a cryptographically relevant quantum computer emerging within the next decade at greater than 30%, and several hardware roadmaps point to systems with roughly 100 stable logical qubits — a widely cited threshold — arriving around 2028–2029.
The reason operators aren’t waiting for certainty is a strategy known as “harvest now, decrypt later” (also called “store now, decrypt later”): adversaries — largely assumed to be well-resourced nation-state actors — intercept and store encrypted traffic today, with the expectation of decrypting it once quantum computing matures. For data with a short shelf life, that’s a non-issue. For data that needs to stay confidential for years or decades — government communications, financial records, long-term contracts, health data, and increasingly the signaling and authentication material that underpins telecom networks themselves — it means the exposure window has already opened, regardless of when the code-breaking hardware arrives. In DigiCert’s 2026 survey of IT and security decision-makers, 84% said they believe at least some of their encrypted data is already vulnerable to this kind of retroactive decryption, and more than a third estimated that over a quarter of their encrypted data is exposed.
The data: universal planning, almost no deployment
The clearest evidence that this is an underrated story is the gap between how many organizations say they’re preparing and how many have actually finished anything. DigiCert’s 2026 Global Post-Quantum Cryptography Readiness Survey — 1,001 IT and cybersecurity decision-makers across the US, UK, and Australia, published in July 2026 — found that 87% of organizations are planning, testing, or implementing post-quantum cryptography initiatives. But only 7% report that quantum-safe or hybrid cryptography is deployed across most of their digital certificates, and that figure is up just two percentage points from 5% in May 2025.

Figure 1. Share of surveyed organizations by post-quantum cryptography deployment status. Source: DigiCert, 2026 Global Post-Quantum Cryptography Readiness Survey (n=1,001), published July 2026.
That’s not a story about apathy. Nearly all respondents (85%) believe current encryption standards will be broken within a decade, and half expect it within five years. Half have completed a quantum risk assessment, 45% have a transition plan, and 44% have built a cryptographic inventory — the unglamorous first step of cataloging every algorithm, key length, certificate, and dependent system across the network. What’s slowing deployment down is largely structural: 26% of respondents cite legacy system complexity as the primary obstacle, with performance impact and budget constraints tied at 19% each, and skills gaps, interoperability, and standards uncertainty rounding out the list. None of that is unique to telecom — but telecom has more of it than most industries.
Why telecom carries more exposure than most industries
Mobile networks are unusually cryptography-dependent, and unusually hard to re-key quickly. Public-key cryptography underpins SIM and eSIM remote provisioning and the SUCI (Subscription Concealed Identifier) mechanism that protects subscriber identity over the air; it secures the IPsec tunnels and S1/N2 interfaces linking radio access networks to the 5G core; it authenticates IMS signaling for voice and messaging; it governs administrative access to OSS/BSS systems; and it signs the firmware and software updates pushed to base stations, routers, and customer-premises equipment. Much of that equipment — subsea cable systems, core routers, RAN hardware — is provisioned on capital cycles measured in a decade or more, and a meaningful share of connected endpoints (IoT sensors, embedded modules, legacy CPE) can’t easily be patched or re-certified at all. That combination of scale, protocol diversity, and long asset life is exactly what makes cryptographic migration slow in any industry — and telecom has all three at once.
The industry seems to know this. DigiCert’s readiness index — a composite confidence score, not a deployment percentage — has telecommunications and media leading every sector it tracked, at +21.6, ahead of banking and financial services (+16.2) and high tech (+13.5); manufacturing showed almost no net readiness (+1.3), and retail scored lowest at –7.9. Confidence isn’t deployment, though, and the same survey’s overall 7%-deployed figure is a reminder that even the most prepared sector still has most of its migration ahead of it.
The regulatory clock is already running
Unlike a lot of “the future of telecom” trend pieces, post-quantum cryptography migration comes with hard dates attached, set by regulators and standards bodies rather than vendor marketing calendars. NIST finalized its first three post-quantum cryptographic standards — FIPS 203, 204, and 205, based on the CRYSTALS-Kyber and CRYSTALS-Dilithium algorithms plus a hash-based signature scheme — in August 2024, and selected an additional key-encapsulation algorithm in March 2025. The NSA’s CNSA 2.0 suite, which governs cryptography for US national security systems (and, by extension, much of the defense and critical-infrastructure supply chain, including telecom vendors that sell into it), requires quantum-resistant algorithms for new acquisitions starting in January 2027, moves networking equipment to exclusive use by 2030, becomes mandatory across its covered categories by 2031, and extends to operating systems, custom applications, and cloud services by 2033, with full compliance across national security systems targeted for 2035. The European Commission has set its own marker, pushing critical infrastructure sectors — telecom included — toward post-quantum readiness by the end of 2030.

Figure 2. Key regulatory deadlines for post-quantum cryptography migration, 2024–2035. Sources: NIST (FIPS 203/204/205); NSA CNSA 2.0 transition timetable; European Commission post-quantum roadmap. Dates as published as of mid-2026.
Put together, these deadlines describe a migration that has to be substantially built out well before 2030, not started then. Cryptographic inventories, risk assessments, and hybrid classical-plus-PQC deployments are 2025–2027 work; the actual cutover of legacy algorithms is what the 2030–2035 deadlines are enforcing.
Who’s actually moving
The scale of the coordination effort is easy to underestimate: GSMA’s Post Quantum Telco Network Task Force — formed with IBM and Vodafone among its initial members — now counts more than 50 companies including over 20 major mobile operators, and Bain & Company reports that 35 carriers worldwide had active quantum programs by the end of 2025.
Individual operators are approaching the problem from different angles, and it’s worth being precise about what each is actually testing, since “quantum” gets used loosely in telecom marketing. Vodafone has been trialing quantum-assisted fiber routing with ORCA Computing. SK Telecom operates one of the larger commercial quantum key distribution (QKD) networks, built with ID Quantique. Orange has piloted a hybrid PQC-QKD enterprise service with Toshiba. Deutsche Telekom demonstrated quantum teleportation over roughly 30 kilometers of commercial fiber in Berlin in early 2026. BT runs a metro-scale QKD network in London, also with Toshiba.
It’s worth flagging a real disagreement inside the standards community here: QKD (which distributes encryption keys using quantum physics rather than math) and PQC (classical, software-based algorithms designed to resist quantum attacks) are often bundled together in coverage, but NIST, the NSA, the UK’s NCSC, and France’s ANSSI all treat PQC as the primary migration path and QKD as a niche complement at best — it needs dedicated hardware, doesn’t scale the way software-based cryptography does, and (per ANSSI) isn’t recommended outside specialized links. The operator trials above are genuinely useful research, but the actual migration that regulatory deadlines are enforcing runs through PQC algorithm adoption in existing protocols, not through building parallel quantum-physical networks.
What operators and enterprises should actually do now
Vendor-neutral, the sequence that GSMA, NIST, and the operators furthest along all converge on looks the same regardless of which network equipment or PKI vendor is involved. Start with a cryptographic inventory — the 44% of organizations that have done this are ahead of the other 56% by definition, since you can’t migrate what you haven’t catalogued. Run a risk assessment that prioritizes systems by data sensitivity and how long that data needs to stay confidential, not just by how exposed the system is today. Build crypto-agility into procurement and architecture decisions now, so that algorithm updates can be pushed through configuration rather than requiring a hardware refresh — this matters especially for RAN and core equipment with 10-plus-year service lives. Deploy hybrid classical-plus-PQC schemes where standards support them, which preserves compatibility while adding quantum resistance as a second layer. And track the telecom-specific protocol work happening at 3GPP, ETSI, and GSMA, since generic enterprise PQC guidance doesn’t automatically cover SUCI generation, RAN interfaces, or IMS signaling.
None of this requires certainty about when a cryptographically relevant quantum computer will exist. That’s precisely why it’s underrated as a story: it doesn’t have a single dramatic headline moment, it has a decade of unglamorous inventory work, protocol updates, and phased cutovers — set against a threat that, per the harvest-now-decrypt-later logic, is arguably already live. The 87%-planning, 7%-deployed gap isn’t evidence that telecom is behind schedule so much as evidence that the schedule itself hasn’t landed yet in most budget cycles. Given the asset lifespans involved and the regulatory dates already on the calendar, that’s likely to change faster than the current pace of deployment suggests it will.
Sources
- DigiCert, “Quantum Security Deployment Remains Stuck Despite Enterprise Planning” (2026 Global Post-Quantum Cryptography Readiness Survey), July 23, 2026 — https://www.digicert.com/news/quantum-security-deployment-remains-stuck
- Bain & Company, “How Telecom Carriers Are Preparing for Quantum” — https://www.bain.com/insights/how-telecom-carriers-are-preparing-for-quantum/
- GSMA, “Post Quantum Telco Network Task Force” — https://www.gsma.com/solutions-and-impact/technologies/security/post-quantum-telco-network-task-force/
- GSMA, “PQ.01 – Post Quantum Telco Network Impact Assessment Whitepaper,” Version 1.0, February 17, 2023 — https://www.gsma.com/newsroom/wp-content/uploads//PQ.1-Post-Quantum-Telco-Network-Impact-Assessment-Whitepaper-Version1.0.pdf
- NIST, Post-Quantum Cryptography Migration (FIPS 203/204/205, finalized August 2024) — https://pages.nist.gov/nccoe-migration-post-quantum-cryptography/
- The Quantum Insider, “Quantum Security Deadlines are Here – What Happens Next?,” May 8, 2026 — https://thequantuminsider.com/2026/05/08/post-quantum-migration-timelines-government-industry-impact/
Subscribe for more Telco & Beyond analysis:
