{"id":25867636,"date":"2026-09-16T19:53:38","date_gmt":"2026-09-16T17:53:38","guid":{"rendered":"https:\/\/ack3.eu\/quantum-computing-risk-corporate-threat\/"},"modified":"2026-09-21T11:15:51","modified_gmt":"2026-09-21T09:15:51","slug":"computacion-cuantica-el-riesgo-corporativo-empieza-hoy","status":"publish","type":"post","link":"https:\/\/ack3.eu\/es\/computacion-cuantica-el-riesgo-corporativo-empieza-hoy\/","title":{"rendered":"Computaci\u00f3n cu\u00e1ntica: el riesgo corporativo empieza hoy"},"content":{"rendered":"<p>[et_pb_section fb_built=\u00bb1&#8243; admin_label=\u00bbsection\u00bb _builder_version=\u00bb4.16&#8243; custom_padding=\u00bb0px|||||\u00bb global_colors_info=\u00bb{}\u00bb][et_pb_row admin_label=\u00bbrow\u00bb _builder_version=\u00bb4.16&#8243; background_size=\u00bbinitial\u00bb background_position=\u00bbtop_left\u00bb background_repeat=\u00bbrepeat\u00bb custom_padding=\u00bb0px|||||\u00bb global_colors_info=\u00bb{}\u00bb][et_pb_column type=\u00bb4_4&#8243; _builder_version=\u00bb4.16&#8243; custom_padding=\u00bb|||\u00bb global_colors_info=\u00bb{}\u00bb custom_padding__hover=\u00bb|||\u00bb][et_pb_text admin_label=\u00bbText\u00bb _builder_version=\u00bb4.27.9&#8243; background_size=\u00bbinitial\u00bb background_position=\u00bbtop_left\u00bb background_repeat=\u00bbrepeat\u00bb hover_enabled=\u00bb0&#8243; global_colors_info=\u00bb{}\u00bb sticky_enabled=\u00bb0&#8243;]<\/p>\n<p style=\"line-height: 1.8; margin-bottom: 20px; font-size: 19px;\"><strong>La computaci\u00f3n cu\u00e1ntica suele presentarse como una tecnolog\u00eda de futuro. Para la seguridad corporativa no lo es. Los datos cifrados que se interceptan hoy pueden almacenarse y descifrarse en cuanto exista un ordenador cu\u00e1ntico suficientemente potente. La pregunta no es <em>cu\u00e1ndo<\/em> llegar\u00e1 esa m\u00e1quina, sino <em>cu\u00e1nto tiempo<\/em> necesita tu informaci\u00f3n seguir siendo confidencial, y si ese plazo termina antes o despu\u00e9s de que llegue.<\/strong><\/p>\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">Casi toda la criptograf\u00eda que protege la banca, las comunicaciones, la identidad digital, los sistemas de control industrial y las cadenas de suministro se apoya en algoritmos de clave p\u00fablica como RSA y las curvas el\u00edpticas. Un ordenador cu\u00e1ntico grande y tolerante a fallos que ejecutara el algoritmo de Shor los romper\u00eda. Hoy no se conoce p\u00fablicamente ninguna m\u00e1quina as\u00ed. Aun as\u00ed, los reguladores de Estados Unidos, la Uni\u00f3n Europea y el Reino Unido ya han fijado plazos de migraci\u00f3n, y los primeros <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/08\/nist-releases-first-3-finalized-post-quantum-encryption-standards\" target=\"_blank\" rel=\"noopener\">est\u00e1ndares de criptograf\u00eda postcu\u00e1ntica del NIST<\/a> est\u00e1n en vigor desde 2024. La amenaza todav\u00eda no se ha materializado t\u00e9cnicamente, pero la obligaci\u00f3n de actuar ya se ha materializado en la regulaci\u00f3n.<\/p>\n<p style=\"background: #BADFF7; padding: 24px 28px; margin-bottom: 36px; border-left: 6px solid #000;\"><strong>La tesis de este an\u00e1lisis es la siguiente: el riesgo cu\u00e1ntico no es un problema de TI que se resolver\u00e1 en 2035. Es un riesgo estrat\u00e9gico, contractual y de terceros que ya est\u00e1 en marcha, porque los datos que se capturan ahora seguir\u00e1n siendo sensibles cuando puedan leerse. Las organizaciones que lo traten como una curiosidad tecnol\u00f3gica afrontar\u00e1n la transici\u00f3n bajo presi\u00f3n regulatoria, sin inventario y sin capacidad de exigir a sus proveedores.<\/strong><\/p>\n<div style=\"background: #111; color: #fff; padding: 28px 36px; margin-bottom: 44px; display: flex; flex-wrap: wrap;\">\n<div style=\"flex: 1; min-width: 160px; padding: 8px 28px 8px 0; border-right: 1px solid #333;\">\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">3<\/div>\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">Est\u00e1ndares postcu\u00e1nticos<br \/>del NIST finalizados (2024)<\/div>\n<\/div>\n<div style=\"flex: 1; min-width: 160px; padding: 8px 28px; border-right: 1px solid #333;\">\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">&lt; 1 M<\/div>\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">C\u00fabits ruidosos estimados<br \/>para romper RSA-2048<\/div>\n<\/div>\n<div style=\"flex: 1; min-width: 160px; padding: 8px 28px; border-right: 1px solid #333;\">\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">2030<\/div>\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">Objetivo de la UE para<br \/>sistemas de alto riesgo<\/div>\n<\/div>\n<div style=\"flex: 1; min-width: 160px; padding: 8px 0 8px 28px;\">\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">2035<\/div>\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">Horizonte para retirar<br \/>RSA y ECC<\/div>\n<\/div>\n<\/div>\n<p style=\"line-height: 1.8; margin-bottom: 24px;\">Estas cuatro cifras resumen el problema. Los est\u00e1ndares de sustituci\u00f3n ya existen. El umbral de hardware estimado para romper el cifrado actual se ha reducido en m\u00e1s de un orden de magnitud en seis a\u00f1os. Y el calendario regulatorio de la migraci\u00f3n ya est\u00e1 fijado. Lo que todav\u00eda falta en la mayor\u00eda de las organizaciones es el primer paso: saber qu\u00e9 criptograf\u00eda utilizan, d\u00f3nde est\u00e1 y qu\u00e9 datos dependen de ella.<\/p>\n<div style=\"margin-bottom: 44px;\">\n<div style=\"position: relative; width: 100%; overflow: hidden; border-left: 4px solid #BADFF7; border-right: 4px solid #BADFF7; border-bottom: 4px solid #BADFF7;\">\n<p style=\"margin: 0; padding: 0; line-height: 0; font-size: 0;\"><img decoding=\"async\" style=\"display: block; width: 100%; height: auto; margin: 0; padding: 0;\" src=\"https:\/\/ack3.eu\/wp-content\/uploads\/2026\/09\/quantum-computing-risk-timeline-pqc-2030-2035.jpg\" alt=\"Cronolog\u00eda del riesgo de la computaci\u00f3n cu\u00e1ntica: est\u00e1ndares postcu\u00e1nticos del NIST 2024, hitos de migraci\u00f3n PQC de la UE y el NCSC en 2030 y 2035, y la ventana de exposici\u00f3n cosechar ahora, descifrar despu\u00e9s\" \/><\/p>\n<p style=\"font-size: 11px; color: #aaa; margin: 0; padding: 10px 16px; background: #111; line-height: 1.4;\">Fuente: elaboraci\u00f3n propia \u00b7 <a style=\"color: #aaa; text-decoration: underline;\" href=\"https:\/\/ack3.eu\/es\/servicios\/mission-critical-support\/operaciones-soc\/\" target=\"_blank\" rel=\"noopener\">ACK3\u00ae Global Hybrid SOC<\/a><\/p>\n<\/div>\n<\/div>\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 44px;\">\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>\u00abLa mayor\u00eda de los consejos de administraci\u00f3n siguen pensando que el riesgo cu\u00e1ntico empieza el d\u00eda que exista la m\u00e1quina. No es as\u00ed. Empieza el d\u00eda que alguien copia tu tr\u00e1fico cifrado y lo guarda. Si una fusi\u00f3n, una licitaci\u00f3n, una patente o un contrato p\u00fablico tiene que seguir siendo confidencial durante diez a\u00f1os, esa informaci\u00f3n ya est\u00e1 expuesta hoy.\u00bb<\/strong><\/p>\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 Antonio Garc\u00eda, Senior Operations Coordinator (GPC), <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/servicios\/consultoria-estrategica-de-riesgos\/\" target=\"_blank\" rel=\"noopener\">ACK3\u00ae \u00b7 Consultor\u00eda Estrat\u00e9gica de Riesgos<\/a><\/strong><\/p>\n<\/div>\n<h2>Qu\u00e9 cambia la computaci\u00f3n cu\u00e1ntica y qu\u00e9 no<\/h2>\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">La computaci\u00f3n cu\u00e1ntica no hace vulnerable cualquier sistema ni va a sustituir a la computaci\u00f3n cl\u00e1sica. Su impacto en la seguridad es concreto y serio. La criptograf\u00eda de clave p\u00fablica (RSA, Diffie-Hellman, curvas el\u00edpticas), que sostiene el intercambio de claves, las firmas digitales, los certificados y las comunicaciones seguras, quedar\u00eda rota ante un ordenador cu\u00e1ntico criptogr\u00e1ficamente relevante. La criptograf\u00eda sim\u00e9trica (como AES) y las funciones hash se ven mucho menos afectadas, y aumentar el tama\u00f1o de clave suele bastar para mantenerlas seguras. El reto de fondo, por tanto, no es que \u00abel cifrado deje de funcionar\u00bb. El reto es que los mecanismos con los que se establece la confianza entre sistemas, personas y organizaciones tienen que sustituirse en toda la infraestructura digital.<\/p>\n<h4>Cosechar ahora, descifrar despu\u00e9s<\/h4>\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">La amenaza m\u00e1s inmediata tiene nombre: <em>harvest now, decrypt later<\/em>, o cosechar ahora, descifrar despu\u00e9s. Los actores estatales con capacidad para interceptar y almacenar grandes vol\u00famenes de tr\u00e1fico cifrado no necesitan hoy un ordenador cu\u00e1ntico. Solo necesitan creer que lo tendr\u00e1n antes de que la informaci\u00f3n pierda su valor. La exposici\u00f3n depende, por tanto, menos de cu\u00e1ndo llegue la m\u00e1quina y m\u00e1s de cu\u00e1nto tiempo deben mantenerse secretos los datos: informaci\u00f3n diplom\u00e1tica y de defensa, propiedad intelectual, estrategia de fusiones y adquisiciones, historiales sanitarios, dise\u00f1os de infraestructuras cr\u00edticas y datos de identidad biom\u00e9trica.<\/p>\n<h4>La desigualdad de Mosca: una prueba para el consejo<\/h4>\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">El cript\u00f3grafo Michele Mosca, cofundador del <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/uwaterloo.ca\/institute-for-quantum-computing\/\" target=\"_blank\" rel=\"noopener\">Institute for Quantum Computing<\/a>, plante\u00f3 el problema en una prueba sencilla. Si el tiempo que tus datos deben permanecer seguros (X) m\u00e1s el tiempo que te llevar\u00e1 migrar tus sistemas (Y) es mayor que el tiempo que falta para que exista un ordenador cu\u00e1ntico criptogr\u00e1ficamente relevante (Z), ya tienes un problema. En las grandes organizaciones, las migraciones de este tipo suelen medirse en a\u00f1os. Eso reduce mucho el margen, incluso con estimaciones conservadoras de Z.<\/p>\n<p>&nbsp;<\/p>\n<h3>El reloj regulatorio ya est\u00e1 en marcha<\/h3>\n<p style=\"line-height: 1.8; margin-bottom: 24px;\">El debate sobre <em>cu\u00e1ndo<\/em> la computaci\u00f3n cu\u00e1ntica romper\u00e1 la criptograf\u00eda actual sigue abierto. El debate sobre <em>cu\u00e1ndo<\/em> deben migrar las organizaciones lo han cerrado, en gran medida, los reguladores.<\/p>\n<div style=\"overflow-x: auto; margin-bottom: 44px;\">\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\n<thead>\n<tr>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 22%;\">Autoridad<\/th>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 38%;\">Marco e hitos<\/th>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px;\">Lectura para la empresa<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">NIST (Estados Unidos)<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">FIPS 203, 204 y 205 publicados en agosto de 2024. Una hoja de ruta de transici\u00f3n propone declarar obsoletos los algoritmos vulnerables a la computaci\u00f3n cu\u00e1ntica a partir de 2030 y prohibirlos en 2035.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">La referencia global de facto. Los fabricantes tecnol\u00f3gicos alinear\u00e1n sus productos con ella, opere o no el cliente en Estados Unidos.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">NSA \u00b7 CNSA 2.0<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Una transici\u00f3n por fases para los sistemas de seguridad nacional, con hitos por categor\u00eda de producto, que debe completarse en la ventana 2030\u20132035.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Un requisito directo para contratistas de defensa y sus cadenas de suministro que trabajan en programas estadounidenses.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Uni\u00f3n Europea<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Una hoja de ruta coordinada por la que los Estados miembros inician la transici\u00f3n antes de que termine 2026, protegen los casos de uso de alto riesgo y las infraestructuras cr\u00edticas en 2030 y migran todo lo posible en 2035.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Enlaza directamente con las obligaciones de NIS2 y DORA. A las entidades esenciales y a las entidades financieras se les pedir\u00e1n evidencias.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">NCSC (Reino Unido)<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Descubrimiento y planificaci\u00f3n en 2028, migraciones prioritarias en 2031 y migraci\u00f3n completa en 2035.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">El modelo de planificaci\u00f3n m\u00e1s claro para estructurar un programa interno en tres fases.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Espa\u00f1a<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Orientaciones del Centro Criptol\u00f3gico Nacional (CCN) y una estrategia nacional de tecnolog\u00edas cu\u00e1nticas.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Una referencia para el sector p\u00fablico, la industria de defensa y los operadores cr\u00edticos que trabajan con la Administraci\u00f3n espa\u00f1ola.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>&nbsp;<\/p>\n<h2>D\u00f3nde impacta: exposici\u00f3n por sectores<\/h2>\n<p style=\"line-height: 1.8; margin-bottom: 24px;\">La exposici\u00f3n no es uniforme entre sectores. Depende de cu\u00e1nto tiempo deben mantenerse confidenciales los datos, de cu\u00e1nta tecnolog\u00eda heredada est\u00e1 en uso y de lo compleja que sea la cadena de suministro.<\/p>\n<div style=\"overflow-x: auto; margin-bottom: 44px;\">\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\n<thead>\n<tr>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 24%;\">Sector<\/th>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 36%;\">Por qu\u00e9 est\u00e1 expuesto<\/th>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px;\">Lectura prioritaria<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Defensa y seguridad<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Informaci\u00f3n clasificada que debe permanecer secreta durante d\u00e9cadas y actores estatales que la tienen como objetivo.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">El objetivo principal de cosechar ahora, descifrar despu\u00e9s. Los requisitos contractuales llegar\u00e1n primero a los proveedores.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Servicios financieros<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Pagos, firmas digitales, comunicaciones interbancarias y datos de clientes de larga vida.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">DORA ya exige gestionar el riesgo criptogr\u00e1fico. La interdependencia sist\u00e9mica multiplica el impacto.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Energ\u00eda, agua e infraestructuras cr\u00edticas<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Sistemas de control industrial con vidas \u00fatiles de 20 a 30 a\u00f1os y criptograf\u00eda integrada en el hardware.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Los equipos que se instalan hoy seguir\u00e1n funcionando cuando la amenaza se materialice. Las decisiones de compra que se tomen ahora importan.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Sanidad y farmac\u00e9utica<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Historias cl\u00ednicas, datos gen\u00e9ticos e I+D con periodos de confidencialidad muy largos.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Datos personales que no pueden \u00abreemitirse\u00bb una vez expuestos, a diferencia de una contrase\u00f1a o una tarjeta.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Telecomunicaciones, puertos y log\u00edstica<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Infraestructura de red, dispositivos conectados y cadenas de confianza entre m\u00faltiples partes.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Un eslab\u00f3n d\u00e9bil en cualquier operador compromete toda la cadena.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Corporativo y legal<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Negociaciones de fusiones y adquisiciones, patentes, litigios y comunicaciones del consejo.<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">El valor de la informaci\u00f3n es estrat\u00e9gico, y tambi\u00e9n lo es el valor de robarla.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"margin-bottom: 44px;\">\n<div style=\"position: relative; width: 100%; overflow: hidden; border-left: 4px solid #BADFF7; border-right: 4px solid #BADFF7; border-bottom: 4px solid #BADFF7;\">\n<p style=\"margin: 0; padding: 0; line-height: 0; font-size: 0;\"><img decoding=\"async\" style=\"display: block; width: 100%; height: auto; margin: 0; padding: 0;\" src=\"https:\/\/ack3.eu\/wp-content\/uploads\/2026\/09\/quantum-computing-corporate-risk-soc-ack3.jpg\" alt=\"Procesador cu\u00e1ntico y el riesgo ciber corporativo de la computaci\u00f3n cu\u00e1ntica, monitorizado por el ACK3\u00ae Global Hybrid SOC\" \/><\/p>\n<div style=\"background: rgba(0,0,0,0.72); padding: 14px 20px; display: flex; justify-content: space-between; align-items: center; flex-wrap: wrap; gap: 8px;\">\n<p style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #badff7; margin: 0; padding: 0; font-weight: bold;\">Hardware cu\u00e1ntico \u00b7 Avances m\u00e1s r\u00e1pidos de lo previsto<\/p>\n<p style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin: 0; padding: 0;\">La correcci\u00f3n de errores es el hito real a vigilar<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">La variable a vigilar no es el n\u00famero de c\u00fabits que se anuncia en cada nota de prensa. Es el avance en la correcci\u00f3n cu\u00e1ntica de errores, que es lo que separa un procesador experimental de una m\u00e1quina capaz de ejecutar el algoritmo de Shor a escala. Los avances recientes de los principales fabricantes, junto con algoritmos de factorizaci\u00f3n cada vez m\u00e1s eficientes, han reducido los recursos estimados para romper RSA-2048. La brecha no se ha cerrado, pero se ha estrechado m\u00e1s r\u00e1pido de lo que anticipaban muchas previsiones.<\/p>\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 44px;\">\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>\u00abLa pregunta cr\u00edtica no es tecnol\u00f3gica. Es qui\u00e9n en tu cadena de suministro tiene tus datos, qu\u00e9 criptograf\u00eda utiliza y si tus contratos te permiten exigirle un plan de migraci\u00f3n. La mayor\u00eda de las organizaciones no puede responder a eso hoy, y ah\u00ed es donde est\u00e1 el riesgo.\u00bb<\/strong><\/p>\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 Antonio Garc\u00eda, Senior Operations Coordinator (GPC), <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/servicios\/servicios-de-investigacion-y-legales\/due-diligence\/\" target=\"_blank\" rel=\"noopener\">ACK3\u00ae \u00b7 Due Diligence<\/a><\/strong><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h2>El riesgo cu\u00e1ntico como riesgo corporativo<\/h2>\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">Para la alta direcci\u00f3n, la computaci\u00f3n cu\u00e1ntica debe entrar en el mapa de riesgos como un conjunto de vectores concretos con distintas probabilidades y horizontes temporales, no como un \u00fanico evento futuro.<\/p>\n<div style=\"overflow-x: auto; margin-bottom: 44px;\">\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\n<thead>\n<tr>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 28%;\">Factor<\/th>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 16%;\">Exposici\u00f3n<\/th>\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px;\">Por qu\u00e9 importa<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Ataque cu\u00e1ntico hoy<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #555; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Bajo<\/span><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">No se conoce p\u00fablicamente ning\u00fan ordenador cu\u00e1ntico criptogr\u00e1ficamente relevante. Sin embargo, eso no reduce el resto de vectores.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Impacto reputacional y de confianza<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #E07000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Medio<\/span><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">La exposici\u00f3n retroactiva de datos hist\u00f3ricos afectar\u00eda a la vez a clientes, socios y reguladores.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Cumplimiento regulatorio y contractual<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #E07000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Medio<\/span><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Crece con rapidez. Licitaciones, auditor\u00edas y grandes clientes empezar\u00e1n a exigir evidencias de un plan de migraci\u00f3n.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Datos confidenciales de larga vida<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #CC0000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Alto<\/span><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Cosechar ahora, descifrar despu\u00e9s hace que la exposici\u00f3n sea real hoy, aunque el da\u00f1o se materialice m\u00e1s adelante.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Cadena de suministro y terceros<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #CC0000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Alto<\/span><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">La seguridad de una organizaci\u00f3n depende del proveedor menos preparado que maneja sus datos.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Sistemas heredados y OT<\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #CC0000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Alto<\/span><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">La criptograf\u00eda integrada en el hardware no se actualiza con un parche. Hay que sustituirla, y eso tiene un coste y un calendario.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 16px;\">\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>El NIST ha publicado los tres primeros est\u00e1ndares finalizados de criptograf\u00eda postcu\u00e1ntica, FIPS 203, FIPS 204 y FIPS 205, y anima a las organizaciones a iniciar la transici\u00f3n sin esperar a nuevos est\u00e1ndares.<\/strong><\/p>\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\" target=\"_blank\" rel=\"noopener\">NIST \u2014 Post-Quantum Cryptography Project<\/a><\/strong><\/p>\n<\/div>\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 16px;\">\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>Las autoridades europeas y brit\u00e1nicas han fijado un horizonte com\u00fan: los sistemas cr\u00edticos deben estar protegidos en 2030\u20132031 y la migraci\u00f3n debe completarse en 2035. El descubrimiento y la planificaci\u00f3n deben empezar ya.<\/strong><\/p>\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/coordinated-implementation-roadmap-transition-post-quantum-cryptography\" target=\"_blank\" rel=\"noopener\">Comisi\u00f3n Europea \u2014 Hoja de ruta coordinada PQC<\/a> \u00b7 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/www.ncsc.gov.uk\/guidance\/pqc-migration-timelines\" target=\"_blank\" rel=\"noopener\">NCSC \u2014 PQC Migration Timelines<\/a><\/strong><\/p>\n<\/div>\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 44px;\">\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>Una investigaci\u00f3n publicada en 2025 estima que una clave RSA de 2048 bits podr\u00eda factorizarse con menos de un mill\u00f3n de c\u00fabits ruidosos en menos de una semana, muy por debajo de estimaciones anteriores de unos veinte millones.<\/strong><\/p>\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/arxiv.org\/abs\/2505.15917\" target=\"_blank\" rel=\"noopener\">Gidney (2025) \u2014 How to factor 2048 bit RSA integers with less than a million noisy qubits \u00b7 arXiv<\/a><\/strong><\/p>\n<\/div>\n<div style=\"background: #111; color: #fff; padding: 26px 32px; margin-bottom: 44px;\">\n<p style=\"font-size: 13px; font-weight: bold; text-transform: uppercase; letter-spacing: 2px; color: #badff7; margin: 0 0 10px 0;\">El error de encuadre m\u00e1s frecuente<\/p>\n<p style=\"line-height: 1.7; margin: 0;\"><strong>Tratar la computaci\u00f3n cu\u00e1ntica como un evento futuro, cuando es una exposici\u00f3n presente. Mientras nadie pueda romper el cifrado actual, el riesgo parece te\u00f3rico. Pero los datos que se roban hoy no caducan, los proveedores no migran al mismo ritmo y los reguladores ya han fijado el plazo. La organizaci\u00f3n que espere al \u00abQ-Day\u00bb para actuar descubrir\u00e1 que su problema no empez\u00f3 ese d\u00eda. Empez\u00f3 a\u00f1os antes, en cada comunicaci\u00f3n cifrada que alguien decidi\u00f3 guardar.<\/strong><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h2>Antes de la migraci\u00f3n: qu\u00e9 debe hacer la direcci\u00f3n ahora<\/h2>\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">La transici\u00f3n a la criptograf\u00eda postcu\u00e1ntica es un programa plurianual. Su primera fase no es t\u00e9cnica, sino de inteligencia y gobierno. Empieza por identificar qu\u00e9 activos de informaci\u00f3n deben seguir siendo confidenciales m\u00e1s all\u00e1 de 2030, y durante cu\u00e1nto tiempo. El siguiente paso es un inventario criptogr\u00e1fico: qu\u00e9 algoritmos, certificados y protocolos se utilizan, en qu\u00e9 sistemas y bajo el control de qui\u00e9n. El tercer paso es la cadena de suministro. Hay que mapear a los proveedores cr\u00edticos, pedirles sus planes de migraci\u00f3n e incorporar requisitos postcu\u00e1nticos en los nuevos contratos y licitaciones. Con esa foto completa, se pueden fijar prioridades seg\u00fan el riesgo, definir un presupuesto y que el consejo decida si avanzar hacia la cripto-agilidad y esquemas h\u00edbridos durante la transici\u00f3n.<\/p>\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">Para las empresas que operan en sectores o regiones con mayor exposici\u00f3n al ciberespionaje estatal, este an\u00e1lisis tiene adem\u00e1s una dimensi\u00f3n geopol\u00edtica. \u00bfA qui\u00e9n le interesa tu informaci\u00f3n y qu\u00e9 capacidad tiene para interceptarla? Para ese marco, consulta nuestro an\u00e1lisis sobre <a style=\"color: #000; font-weight: bold;\" href=\"URL_ES_AMENAZAS_HIBRIDAS\" target=\"_blank\" rel=\"noopener\">amenazas h\u00edbridas e impacto estrat\u00e9gico<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h2>Preguntas frecuentes sobre computaci\u00f3n cu\u00e1ntica y seguridad<\/h2>\n<h3>\u00bfCu\u00e1ndo podr\u00e1n los ordenadores cu\u00e1nticos romper el cifrado actual?<\/h3>\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">No hay consenso sobre la fecha. Los reguladores planifican en torno a un horizonte 2030\u20132035. Por el efecto de cosechar ahora, descifrar despu\u00e9s, los datos sensibles de larga vida deben considerarse ya expuestos.<\/p>\n<h3>\u00bfQu\u00e9 es la criptograf\u00eda postcu\u00e1ntica?<\/h3>\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">La criptograf\u00eda postcu\u00e1ntica es un conjunto de algoritmos que funcionan en los ordenadores cl\u00e1sicos actuales y est\u00e1n dise\u00f1ados para resistir ataques tanto de ordenadores cl\u00e1sicos como cu\u00e1nticos. El NIST estandariz\u00f3 los primeros en 2024.<\/p>\n<h3>\u00bfQu\u00e9 empresas deber\u00edan empezar a prepararse primero?<\/h3>\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">Las primeras en prepararse deben ser las empresas que manejan datos con un periodo de confidencialidad largo, operan infraestructuras cr\u00edticas, est\u00e1n sujetas a NIS2 o DORA, o son proveedoras de los sectores de defensa y financiero.<\/p>\n<div style=\"height: 8px; background: #BADFF7; width: 100%; margin: 0 0 32px;\">\u00a0<\/div>\n<h2 style=\"text-align: center;\">\u00bfSabe tu organizaci\u00f3n cu\u00e1nto est\u00e1 expuesta a la amenaza cu\u00e1ntica?<\/h2>\n<p style=\"line-height: 1.8; margin-bottom: 24px; text-align: center;\">ACK3\u00ae ayuda a las organizaciones a convertir el riesgo cu\u00e1ntico en decisiones estrat\u00e9gicas. Evaluamos la exposici\u00f3n, verificamos a terceros, planificamos escenarios de continuidad y monitorizamos el entorno de amenaza, y coordinamos con socios especializados la migraci\u00f3n t\u00e9cnica.<\/p>\n<div style=\"overflow-x: auto; margin-bottom: 36px; text-align: center;\">\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\n<thead>\n<tr>\n<th style=\"background: #badff7; color: #000000; padding: 13px 18px; border: 1px solid #a0cce8; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 32%; text-align: left;\">Servicio ACK3\u00ae<\/th>\n<th style=\"background: #badff7; color: #000000; padding: 13px 18px; border: 1px solid #a0cce8; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; text-align: left;\">Qu\u00e9 aporta frente al riesgo cu\u00e1ntico<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/servicios\/consultoria-estrategica-de-riesgos\/\" target=\"_blank\" rel=\"noopener\">Consultor\u00eda estrat\u00e9gica de riesgos<\/a><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Evaluaci\u00f3n de la exposici\u00f3n cu\u00e1ntica a nivel de consejo, identificaci\u00f3n de los activos de informaci\u00f3n cr\u00edticos y su horizonte de confidencialidad, e integraci\u00f3n en el mapa de riesgos corporativo.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/servicios\/servicios-de-investigacion-y-legales\/due-diligence\/\" target=\"_blank\" rel=\"noopener\">Due Diligence e inteligencia econ\u00f3mica<\/a><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Evaluaci\u00f3n de la preparaci\u00f3n criptogr\u00e1fica de proveedores, socios tecnol\u00f3gicos y objetivos de adquisici\u00f3n, y de los requisitos contractuales que exigirles.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/servicios\/gestion-de-crisis\/\" target=\"_blank\" rel=\"noopener\">Gesti\u00f3n de crisis y continuidad de negocio<\/a><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Escenarios de compromiso criptogr\u00e1fico, protocolos de escalado y planes de continuidad ante una exposici\u00f3n retroactiva de informaci\u00f3n sensible.<\/td>\n<\/tr>\n<tr style=\"background: #f7f7f7;\">\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/servicios\/mission-critical-support\/operaciones-soc\/\" target=\"_blank\" rel=\"noopener\">Inteligencia y monitorizaci\u00f3n \u00b7 Global Hybrid SOC<\/a><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Monitorizaci\u00f3n 24\/7 desde Madrid de campa\u00f1as de ciberespionaje estatal, avances tecnol\u00f3gicos y cambios regulatorios que afectan a tu exposici\u00f3n.<\/td>\n<\/tr>\n<tr style=\"background: #fff;\">\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/es\/formacion\/\" target=\"_blank\" rel=\"noopener\">Formaci\u00f3n especializada<\/a><\/td>\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Sesiones ejecutivas para la direcci\u00f3n y los comit\u00e9s de riesgos sobre amenazas cu\u00e1nticas, plazos regulatorios y toma de decisiones.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"display: flex; flex-wrap: wrap; gap: 16px; justify-content: center; margin-bottom: 44px;\"><a style=\"display: inline-block; background: #111; color: #fff; padding: 16px 36px; font-size: 15px; font-weight: bold; text-decoration: none;\" href=\"https:\/\/ack3.eu\/es\/servicios\/\">Servicios ACK3\u00ae \u2192<\/a><br \/><a style=\"display: inline-block; background: #BADFF7; color: #000; padding: 16px 36px; font-size: 15px; font-weight: bold; text-decoration: none;\" href=\"https:\/\/ack3.eu\/es\/contacto\/\">Eval\u00faa tu exposici\u00f3n cu\u00e1ntica \u2192<\/a><\/div>\n<p style=\"line-height: 1.8; margin-bottom: 8px; text-align: center;\">La amenaza cu\u00e1ntica no empieza el d\u00eda que exista la m\u00e1quina. Empez\u00f3 el d\u00eda que tus datos fueron capturados.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Computaci\u00f3n cu\u00e1ntica y riesgo corporativo: por qu\u00e9 &#8216;cosechar ahora, descifrar despu\u00e9s&#8217; ya es una amenaza y c\u00f3mo preparar a tu empresa.<\/p>\n","protected":false},"author":2,"featured_media":25867608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<p style=\"line-height: 1.8; margin-bottom: 20px; font-size: 19px;\"><strong>Quantum computing is usually presented as a technology of the future. For corporate security it is not. Encrypted data intercepted today can be stored and decrypted once a sufficiently powerful quantum computer exists. The question is not <em>when<\/em> that machine will arrive, but <em>how long<\/em> your information needs to stay confidential, and whether that period ends before or after it arrives.<\/strong><\/p>\r\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">Almost all the cryptography that protects banking, communications, digital identity, industrial control systems and supply chains relies on public-key algorithms such as RSA and elliptic curves. A large, fault-tolerant quantum computer running Shor's algorithm would break them. No such machine is publicly known to exist today. Even so, regulators in the United States, the European Union and the United Kingdom have already set migration deadlines, and the first <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/www.nist.gov\/news-events\/news\/2024\/08\/nist-releases-first-3-finalized-post-quantum-encryption-standards\" target=\"_blank\" rel=\"noopener\">post-quantum cryptography standards from NIST<\/a> have been in force since 2024. The threat has not yet materialised technically, but the obligation to act has already materialised in regulation.<\/p>\r\n<p style=\"background: #BADFF7; padding: 24px 28px; margin-bottom: 36px; border-left: 6px solid #000;\"><strong>The argument of this analysis is the following: quantum risk is not an IT problem to be solved in 2035. It is a strategic, contractual and third-party risk that is already running today, because the data being captured now will still be sensitive when it can be read. Organisations that treat it as a technological curiosity will face the transition under regulatory pressure, with no inventory and no leverage over their suppliers.<\/strong><\/p>\r\n\r\n<div style=\"background: #111; color: #fff; padding: 28px 36px; margin-bottom: 44px; display: flex; flex-wrap: wrap;\">\r\n<div style=\"flex: 1; min-width: 160px; padding: 8px 28px 8px 0; border-right: 1px solid #333;\">\r\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">3<\/div>\r\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">NIST post-quantum\r\nstandards finalised (2024)<\/div>\r\n<\/div>\r\n<div style=\"flex: 1; min-width: 160px; padding: 8px 28px; border-right: 1px solid #333;\">\r\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">< 1 M<\/div>\r\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">Noisy qubits estimated\r\nto break RSA-2048<\/div>\r\n<\/div>\r\n<div style=\"flex: 1; min-width: 160px; padding: 8px 28px; border-right: 1px solid #333;\">\r\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">2030<\/div>\r\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">EU target for\r\nhigh-risk systems<\/div>\r\n<\/div>\r\n<div style=\"flex: 1; min-width: 160px; padding: 8px 0 8px 28px;\">\r\n<div style=\"font-size: 44px; font-weight: 900; color: #badff7; line-height: 1;\">2035<\/div>\r\n<div style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin-top: 8px; line-height: 1.4;\">Horizon to retire\r\nRSA and ECC<\/div>\r\n<\/div>\r\n<\/div>\r\n<p style=\"line-height: 1.8; margin-bottom: 24px;\">These four figures summarise the problem. The replacement standards already exist. The estimated hardware threshold needed to break current encryption has fallen by more than an order of magnitude in six years. And the regulatory calendar for migration is already fixed. What is still missing in most organisations is the first step: knowing what cryptography they use, where it is, and which data depends on it.<\/p>\r\n\r\n<div style=\"margin-bottom: 44px;\">\r\n<div style=\"position: relative; width: 100%; overflow: hidden; border-left: 4px solid #BADFF7; border-right: 4px solid #BADFF7; border-bottom: 4px solid #BADFF7;\"><img style=\"display: block; width: 100%; height: auto; margin: 0; padding: 0;\" src=\"https:\/\/ack3.eu\/wp-content\/uploads\/2026\/09\/quantum-computing-risk-timeline-pqc-2030-2035.jpg\" alt=\"Quantum computing risk timeline: NIST post-quantum standards 2024, EU and NCSC PQC migration milestones 2030 and 2035, and the harvest now decrypt later exposure window\" \/>\r\n<p style=\"font-size: 11px; color: #aaa; margin: 0; padding: 10px 16px; background: #111;\">Source: own elaboration \u00b7 <a style=\"color: #aaa; text-decoration: underline;\" href=\"https:\/\/ack3.eu\/\" target=\"_blank\" rel=\"noopener\">ACK3\u00ae Global Hybrid SOC<\/a><\/p>\r\n\r\n<\/div>\r\n<\/div>\r\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 44px;\">\r\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>\"Most boards still think quantum risk starts the day the machine exists. It doesn't. It starts the day someone copies your encrypted traffic and stores it. If a merger, a tender, a patent or a government contract has to stay confidential for ten years, that information is already exposed today.\"<\/strong><\/p>\r\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 Antonio Garc\u00eda, Senior Operations Coordinator (GPC), <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/services\/risk-consulting\/\" target=\"_blank\" rel=\"noopener\">ACK3\u00ae \u00b7 Strategic Risk Consulting<\/a><\/strong><\/p>\r\n\r\n<\/div>\r\n<h2>What quantum computing changes, and what it does not<\/h2>\r\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">Quantum computing does not make every system vulnerable, and it will not replace classical computing. Its impact on security is specific and serious. Public-key cryptography (RSA, Diffie-Hellman, elliptic curves), which underpins key exchange, digital signatures, certificates and secure communications, would be broken by a cryptographically relevant quantum computer. Symmetric cryptography (such as AES) and hash functions are affected much less, and larger key sizes are generally enough to keep them secure. The core challenge is therefore not that \"encryption stops working\". The challenge is that the mechanisms used to establish trust between systems, people and organisations have to be replaced across the entire digital infrastructure.<\/p>\r\n\r\n<h4>Harvest now, decrypt later<\/h4>\r\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">The most immediate threat has a name: <em>harvest now, decrypt later<\/em>. State-level actors with the capacity to intercept and store large volumes of encrypted traffic do not need a quantum computer today. They only need to believe they will have one before the information loses its value. Exposure therefore depends less on when the machine arrives and more on how long the data must stay secret: diplomatic and defence information, intellectual property, M&A strategy, health records, critical infrastructure designs and biometric identity data.<\/p>\r\n\r\n<h4>The Mosca inequality: a board-level test<\/h4>\r\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">Cryptographer Michele Mosca, co-founder of the <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/uwaterloo.ca\/institute-for-quantum-computing\/\" target=\"_blank\" rel=\"noopener\">Institute for Quantum Computing<\/a>, framed the problem in a simple test. If the time your data must remain secure (X) plus the time it will take you to migrate your systems (Y) is greater than the time until a cryptographically relevant quantum computer exists (Z), you already have a problem. In large organisations, migrations of this kind are usually measured in years. That shortens the margin considerably, even under conservative estimates of Z.<\/p>\r\n\u00a0\r\n<h3>The regulatory clock is already running<\/h3>\r\n<p style=\"line-height: 1.8; margin-bottom: 24px;\">The debate on <em>when<\/em> quantum computing will break current cryptography remains open. The debate on <em>when<\/em> organisations must migrate has largely been settled by regulators.<\/p>\r\n\r\n<div style=\"overflow-x: auto; margin-bottom: 44px;\">\r\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\r\n<thead>\r\n<tr>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 22%;\">Authority<\/th>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 38%;\">Framework and milestones<\/th>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px;\">Reading for the company<\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">NIST (United States)<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">FIPS 203, 204 and 205 published in August 2024. A transition roadmap proposes deprecating quantum-vulnerable algorithms from 2030 and disallowing them by 2035.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">The de facto global reference. Technology vendors will align their products with it, whether or not the client operates in the US.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">NSA \u00b7 CNSA 2.0<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">A phased transition for national security systems, with milestones by product category, to be completed within the 2030\u20132035 window.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">A direct requirement for defence contractors and their supply chains working with US programmes.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">European Union<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">A coordinated roadmap under which Member States begin the transition by the end of 2026, protect high-risk use cases and critical infrastructure by 2030, and migrate as much as feasible by 2035.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">It links directly to NIS2 and DORA obligations. Essential entities and financial institutions will be asked for evidence.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">NCSC (United Kingdom)<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Discovery and planning by 2028, priority migrations by 2031, full migration by 2035.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">The clearest planning model for structuring an internal programme in three phases.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Spain<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Guidance from the National Cryptologic Centre (CCN) and a national strategy for quantum technologies.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">A reference point for the public sector, the defence industry and critical operators working with the Spanish administration.<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n\u00a0\r\n<h2>Where the impact lands: sector exposure<\/h2>\r\n<p style=\"line-height: 1.8; margin-bottom: 24px;\">Exposure is not uniform across sectors. It depends on how long the data needs to stay confidential, how much legacy technology is in use and how complex the supply chain is.<\/p>\r\n\r\n<div style=\"overflow-x: auto; margin-bottom: 44px;\">\r\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\r\n<thead>\r\n<tr>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 24%;\">Sector<\/th>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 36%;\">Why it is exposed<\/th>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px;\">Priority reading<\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Defence and security<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Classified information that must remain secret for decades, and state actors targeting it.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">The main target of harvest now, decrypt later. Contractual requirements will reach suppliers first.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Financial services<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Payments, digital signatures, interbank communications and long-lived customer data.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">DORA already requires cryptographic risk management. Systemic interdependence multiplies the impact.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Energy, water and critical infrastructure<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Industrial control systems with lifespans of 20 to 30 years and cryptography embedded in the hardware.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Equipment installed today will still be running when the threat materialises. Purchasing decisions made now matter.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Healthcare and pharmaceuticals<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Clinical records, genetic data and R&D with very long confidentiality periods.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Personal data that cannot be \"reissued\" once exposed, unlike a password or a card.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Telecoms, ports and logistics<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Network infrastructure, connected devices and multi-party trust chains.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">A weak link in any operator compromises the whole chain.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Corporate and legal<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">M&A negotiations, patents, litigation and board communications.<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">The value of the information is strategic, and so is the value of stealing it.<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n<div style=\"margin-bottom: 44px;\">\r\n<div style=\"position: relative; width: 100%; overflow: hidden; border-left: 4px solid #BADFF7; border-right: 4px solid #BADFF7; border-bottom: 4px solid #BADFF7;\"><img style=\"display: block; width: 100%; height: auto; margin: 0; padding: 0;\" src=\"https:\/\/ack3.eu\/wp-content\/uploads\/2026\/09\/quantum-computing-corporate-risk-soc-ack3.jpg\" alt=\"Quantum processor and the corporate cyber risk of quantum computing, monitored by the ACK3\u00ae Global Hybrid SOC\" \/>\r\n<div style=\"background: rgba(0,0,0,0.72); padding: 14px 20px; display: flex; justify-content: space-between; align-items: center; flex-wrap: wrap; gap: 8px;\">\r\n<p style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #badff7; margin: 0; font-weight: bold;\">Quantum hardware \u00b7 Faster progress than expected<\/p>\r\n<p style=\"font-size: 11px; text-transform: uppercase; letter-spacing: 2px; color: #aaa; margin: 0;\">Error correction is the real milestone to watch<\/p>\r\n\r\n<\/div>\r\n<\/div>\r\n<\/div>\r\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">The variable to watch is not the number of qubits announced in each press release. It is progress in quantum error correction, which is what separates an experimental processor from a machine capable of running Shor's algorithm at scale. Recent advances by the main manufacturers, together with increasingly efficient factoring algorithms, have reduced the estimated resources needed to break RSA-2048. The gap has not closed, but it has narrowed faster than many forecasts anticipated.<\/p>\r\n\r\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 44px;\">\r\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>\"The critical question is not technological. It is who in your supply chain holds your data, what cryptography they use, and whether your contracts let you demand a migration plan from them. Most organisations can't answer that today, and that is where the risk sits.\"<\/strong><\/p>\r\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 Antonio Garc\u00eda, Senior Operations Coordinator (GPC), <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/services\/due-diligence\/\" target=\"_blank\" rel=\"noopener\">ACK3\u00ae \u00b7 Due Diligence<\/a><\/strong><\/p>\r\n\r\n<\/div>\r\n\u00a0\r\n<h2>Quantum risk as corporate risk<\/h2>\r\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">For senior management, quantum computing should enter the risk map as a set of concrete vectors with different probabilities and time horizons, rather than as a single future event.<\/p>\r\n\r\n<div style=\"overflow-x: auto; margin-bottom: 44px;\">\r\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\r\n<thead>\r\n<tr>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 28%;\">Factor<\/th>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 16%;\">Exposure<\/th>\r\n<th style=\"background: #111; color: #fff; padding: 13px 18px; border: 1px solid #333; text-align: left; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px;\">Why it matters<\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Quantum attack today<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #555; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Low<\/span><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">No cryptographically relevant quantum computer is publicly known to exist. However, that does not reduce the other vectors.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Reputational and trust impact<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #E07000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Medium<\/span><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Retroactive exposure of historical data would affect customers, partners and regulators all at once.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Regulatory and contractual compliance<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #E07000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">Medium<\/span><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">It is rising quickly. Tenders, audits and major clients will start requiring evidence of a migration plan.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Long-lived confidential data<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #CC0000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">High<\/span><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Harvest now, decrypt later makes the exposure real today, even though the damage materialises later.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Supply chain and third parties<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #CC0000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">High<\/span><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">An organisation's security depends on the least prepared supplier handling its data.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; font-weight: 600;\">Legacy and OT systems<\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd; text-align: center;\"><span style=\"background: #CC0000; color: #fff; padding: 3px 9px; font-size: 11px; font-weight: bold; text-transform: uppercase; white-space: nowrap;\">High<\/span><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #ddd;\">Cryptography embedded in hardware cannot be updated with a patch. It has to be replaced, and that has a cost and a schedule.<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 16px;\">\r\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>NIST has published the first three finalised post-quantum cryptography standards, FIPS 203, FIPS 204 and FIPS 205, and encourages organisations to begin transitioning to them without waiting for further standards.<\/strong><\/p>\r\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\" target=\"_blank\" rel=\"noopener\">NIST \u2014 Post-Quantum Cryptography Project<\/a><\/strong><\/p>\r\n\r\n<\/div>\r\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 16px;\">\r\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>European and British authorities have set a shared horizon: critical systems must be protected by 2030\u20132031, and the migration must be completed by 2035. Discovery and planning should begin now.<\/strong><\/p>\r\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/coordinated-implementation-roadmap-transition-post-quantum-cryptography\" target=\"_blank\" rel=\"noopener\">European Commission \u2014 PQC Coordinated Roadmap<\/a> \u00b7 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/www.ncsc.gov.uk\/guidance\/pqc-migration-timelines\" target=\"_blank\" rel=\"noopener\">NCSC \u2014 PQC Migration Timelines<\/a><\/strong><\/p>\r\n\r\n<\/div>\r\n<div style=\"background: #EAEADF; border-left: 6px solid #000; padding: 22px 26px; margin-bottom: 44px;\">\r\n<p style=\"line-height: 1.7; font-style: italic; margin: 0 0 10px 0;\"><strong>Research published in 2025 estimates that a 2048-bit RSA key could be factored with fewer than one million noisy qubits in under a week, well below earlier estimates of around twenty million.<\/strong><\/p>\r\n<p style=\"font-size: 12px; margin: 0; color: #000;\"><strong>\u2014 <a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/arxiv.org\/abs\/2505.15917\" target=\"_blank\" rel=\"noopener\">Gidney (2025) \u2014 How to factor 2048 bit RSA integers with less than a million noisy qubits \u00b7 arXiv<\/a><\/strong><\/p>\r\n\r\n<\/div>\r\n<div style=\"background: #111; color: #fff; padding: 26px 32px; margin-bottom: 44px;\">\r\n<p style=\"font-size: 13px; font-weight: bold; text-transform: uppercase; letter-spacing: 2px; color: #badff7; margin: 0 0 10px 0;\">The most common framing error<\/p>\r\n<p style=\"line-height: 1.7; margin: 0;\"><strong>Treating quantum computing as a future event, when it is a present exposure. As long as no one can break current encryption, the risk seems theoretical. But the data being stolen today does not expire, suppliers are not migrating at the same pace, and regulators have already set the deadline. The organisation that waits for \"Q-Day\" to act will discover that its problem did not start that day. It started years earlier, in every encrypted communication that someone decided to keep.<\/strong><\/p>\r\n\r\n<\/div>\r\n\u00a0\r\n<h2>Before the migration: what management should do now<\/h2>\r\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">The transition to post-quantum cryptography is a multi-year programme. Its first phase is not technical but one of intelligence and governance. It starts with identifying which information assets must remain confidential beyond 2030, and for how long. The next step is a cryptographic inventory: which algorithms, certificates and protocols are in use, in which systems, and under whose control. The third step is the supply chain. Critical suppliers need to be mapped, their migration plans requested, and post-quantum requirements built into new contracts and tenders. Once that picture is in place, priorities can be set by risk, a budget can be defined, and the board can decide whether to proceed with crypto-agility and hybrid schemes during the transition.<\/p>\r\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">For companies operating in sectors or regions with a higher exposure to state-level cyber espionage, this analysis also has a geopolitical dimension. Who is interested in your information, and what capacity do they have to intercept it? For that framework, see our analysis of <a style=\"color: #000; font-weight: bold;\" href=\"URL_HYBRID_THREATS_ARTICLE\" target=\"_blank\" rel=\"noopener\">hybrid threats and strategic impact<\/a>.<\/p>\r\n\u00a0\r\n<h2>Frequently asked questions about quantum computing and security<\/h2>\r\n<h3>When will quantum computers be able to break current encryption?<\/h3>\r\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">There is no consensus on the date. Regulators are planning around a 2030\u20132035 horizon. Because of harvest now, decrypt later, sensitive long-lived data should be treated as exposed already.<\/p>\r\n\r\n<h3>What is post-quantum cryptography?<\/h3>\r\n<p style=\"line-height: 1.8; margin-bottom: 16px;\">Post-quantum cryptography is a set of algorithms that run on today's classical computers and are designed to resist attacks from both classical and quantum computers. NIST standardised the first of them in 2024.<\/p>\r\n\r\n<h3>Which companies should start preparing first?<\/h3>\r\n<p style=\"line-height: 1.8; margin-bottom: 36px;\">The first to prepare should be companies that handle data with a long confidentiality period, operate critical infrastructure, fall under NIS2 or DORA, or supply the defence and financial sectors.<\/p>\r\n\r\n<div style=\"height: 8px; background: #BADFF7; width: 100%; margin: 0 0 32px;\"><\/div>\r\n<h2 style=\"text-align: center;\">Does your organisation know how exposed it is to the quantum threat?<\/h2>\r\n<p style=\"line-height: 1.8; margin-bottom: 24px; text-align: center;\">ACK3\u00ae helps organisations turn quantum risk into strategic decisions. We assess exposure, verify third parties, plan continuity scenarios and monitor the threat environment, and we coordinate with specialised partners for the technical migration.<\/p>\r\n\r\n<div style=\"overflow-x: auto; margin-bottom: 36px; text-align: center;\">\r\n<table style=\"border-collapse: collapse; width: 100%; font-size: 15px; line-height: 1.5;\">\r\n<thead>\r\n<tr>\r\n<th style=\"background: #badff7; color: #000000; padding: 13px 18px; border: 1px solid #a0cce8; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; width: 32%; text-align: left;\">ACK3\u00ae Service<\/th>\r\n<th style=\"background: #badff7; color: #000000; padding: 13px 18px; border: 1px solid #a0cce8; font-weight: bold; text-transform: uppercase; letter-spacing: 1px; font-size: 11px; text-align: left;\">What it delivers against quantum risk<\/th>\r\n<\/tr>\r\n<\/thead>\r\n<tbody>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/services\/risk-consulting\/\" target=\"_blank\" rel=\"noopener\">Strategic risk consulting<\/a><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Board-level quantum exposure assessment, identification of critical information assets and their confidentiality horizon, and integration into the corporate risk map.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/services\/due-diligence\/\" target=\"_blank\" rel=\"noopener\">Due Diligence and economic intelligence<\/a><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Assessment of the cryptographic readiness of suppliers, technology partners and acquisition targets, plus the contractual requirements to demand from them.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/services\/crisis-management\/\" target=\"_blank\" rel=\"noopener\">Crisis management and business continuity<\/a><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Cryptographic compromise scenarios, escalation protocols and continuity plans in the event of retroactive exposure of sensitive information.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #f7f7f7;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"URL_GLOBAL_HYBRID_SOC\" target=\"_blank\" rel=\"noopener\">Intelligence and monitoring \u00b7 Global Hybrid SOC<\/a><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">24\/7 monitoring from Madrid of state-level cyber espionage campaigns, technological developments and regulatory changes that affect your exposure.<\/td>\r\n<\/tr>\r\n<tr style=\"background: #fff;\">\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; font-weight: 600; text-align: left;\"><a style=\"color: #000; font-weight: bold;\" href=\"https:\/\/ack3.eu\/services\/training\/\" target=\"_blank\" rel=\"noopener\">Specialised training<\/a><\/td>\r\n<td style=\"padding: 12px 18px; border: 1px solid #dddddd; text-align: left;\">Executive briefings for management and risk committees on quantum threats, regulatory deadlines and decision-making.<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n<div style=\"display: flex; flex-wrap: wrap; gap: 16px; justify-content: center; margin-bottom: 44px;\"><a style=\"display: inline-block; background: #111; color: #fff; padding: 16px 36px; font-size: 15px; font-weight: bold; text-decoration: none;\" href=\"https:\/\/ack3.eu\/services\/\">ACK3\u00ae Services \u2192<\/a>\r\n<a style=\"display: inline-block; background: #BADFF7; color: #000; padding: 16px 36px; font-size: 15px; font-weight: bold; text-decoration: none;\" href=\"https:\/\/ack3.eu\/contact\/\">Assess your quantum exposure \u2192<\/a><\/div>\r\n<p style=\"line-height: 1.8; margin-bottom: 8px; text-align: center;\">The quantum threat does not begin the day the machine exists. It began the day your data was captured.<\/p>","_et_gb_content_width":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[120],"tags":[1642,1643,1644,1645,1646,1647,1648],"dipi_cpt_category":[],"class_list":["post-25867636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-risk-pulse-es","tag-harvest-now-decrypt-later","tag-nist-post-quantum-standard","tag-post-quantum-cryptography","tag-pqc-migration","tag-q-day","tag-quantum-computing-risk","tag-quantum-threat"],"jetpack_featured_media_url":"https:\/\/ack3.eu\/wp-content\/uploads\/2026\/09\/quantum-processor-public-key-cryptography-risk.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/posts\/25867636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/comments?post=25867636"}],"version-history":[{"count":3,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/posts\/25867636\/revisions"}],"predecessor-version":[{"id":25867643,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/posts\/25867636\/revisions\/25867643"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/media\/25867608"}],"wp:attachment":[{"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/media?parent=25867636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/categories?post=25867636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/tags?post=25867636"},{"taxonomy":"dipi_cpt_category","embeddable":true,"href":"https:\/\/ack3.eu\/es\/wp-json\/wp\/v2\/dipi_cpt_category?post=25867636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}