Microsoft and SAP became the latest names to bolster enterprise software with quantum-proof cryptography.
The hyperscaler followed in Google's footsteps by accelerating the Microsoft Quantum Safe Program timeline to transition Microsoft's services and products to a post-quantum cryptography (PQC) footing by 2029. According to Microsoft Azure CTO Mark Russinovich, cryptographically relevant quantum computers could arrive "sooner than previously expected and the work required to prepare is significant so organizations need to start now."
This means Microsoft is to step up modernizing its network cryptography, as well as safeguard stored data with crypto-agility, which is the ability to change cryptography without redesigning systems from scratch.
Russinovich added Microsoft would modernize cryptographic trust chains.
German enterprise resource planning (ERP) giant SAP, meanwhile, updated its SAP HANA cloud system with PQC for transport layer security (TLS) connections. This mean the database system, which outside of SAP can be found as infrastructure-as-a-service (IaaS) from the three main hyperscalers, will now handle network connections with a hybrid key exchange combining classical and quantum-resistant algorithms. This occurs during the so-called TLS handshake, where TLS 1.3 encrypts internet traffic and enables clients and servers to share secure socket layer (SSL) certificates for authentication.
SAP said the decision was to thwart harvest-now, decrypt-later attacks, in which threat actors steal encrypted data in the present to wait for the occasion of quantum computers coming to bear with decryption technologies capable of breaking today's cryptography methods.
Building back better
Microsoft, a long-time SAP partner, also considers the harvest threat as a major driver behind its 2029 deadline. Other factors included general cybersecurity hygiene, with companies embarking on PQC able to unearth vulnerabilities independent of quantum-related risk; and a clear visibility of where cryptography exists across legacy infrastructure.
As explored in SDxCentral's recent Quantum Supplement, experts see PQC as an opportunity to rip and replace cryptographic architecture approaching three decades in age, and identity data with a long shelf-life – the sort under threat from harvest attackers.
Mark Pecen, chair of ETSI's Technical Committee on Quantum Technology, also pointed to classical computers already being a major threat to enterprises, reminding this title that they are capable of cracking the aging standard public-key systems Rivest-Shamir-Adleman (RSA) and elliptic curve cryptography (ECC).
While Microsoft's Russinovich said customer concerns around such areas had spurred its 2029 gambit, it's likely recent moves from both Google and the U.S. government accelerated decisions at the hyperscaler.
Google was arguably first out of the gate when it declared it would be accelerating its PQC transition to 2029. Some understood this to mean Alphabet and company to be expecting the first quantum computer to go online that year, when instead it was the throwing down of a security gauntlet of sorts in preparation for "Q-day" during the next decade.
"Google framed 2029 as a PQC migration timeline, intended to create 'clarity and urgency' across industry, not as a certain date for a cryptographically relevant quantum computer," Pecen confirmed.
America's quantum leap
That urgency was compounded when the White House issued various executive orders this month to spur quantum development and security in the United States.
The first order aimed to accelerate the U.S. transition to PQC with an explicit warning of the harvest-now, decrypt-later threat. Federal agencies were ordered to appoint PQC migration leaders and begin transitioning high-value systems within the next several years.
ETSI's Pecen explained the EO gives the civilian federal side harder near-term goals. With it agencies must transition high-impact systems to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031.
"It also requires a National Institute of Standards and Technology (NIST) pilot by the end of 2027 and it starts procurement rulemaking so covered federal contractors must comply with NIST Federal Information Processing Standards (FIPS) FIPS, including PQC FIPS, by December 31, 2030," Pecen added.
A second executive order broadens beyond security to a more network-centric vision of America's quantum future. Titled "Ushering in the Next Frontier of Quantum Innovation," President Donald Trump declared that the U.S. is "at the cusp of a quantum revolution" and that maintaining leadership in quantum information science and technology (QIST) was now a strategic national priority.
The administration said it intends to update the national quantum strategy within 180 days, with a stronger emphasis on commercialization, manufacturing, deployment, and supply-chain security rather than solely on academic research.
A interesting wrinkle was a strong emphasis on quantum sensing and quantum networking. The Pentagon was ordered to identify at least three quantum sensor programs to deploy by September 2028, while the Departments of Commerce and Energy, the National Science Foundation, and NASA were instructed to develop five-year plans covering quantum sensing, timing, networking, and distributed quantum computing.
Quantum networks in 2026
As may be expected, quantum networking is a developing area, especially compared to the faster nature of software which underpins PQC technologies. Cisco has some pedigree here, having established partnerships with IBM, Qunnect, and Atom Computing, as it builds out an end-to-end framework for quantum networking.
Research from BCG noted that since 2023, fiber-based links interconnecting quantum computers have grown from around 124 miles to reach approximately 622 miles in lab fiber tests and more than 500 miles in field tests.
Jean-Francois Bobier, partner and VP at BCG, told this title that fiber remains key to quantum networking development, overcoming the absence of quantum repeater tech. This Q-day dependent device would sit along the network and "refresh" the signal so quantum key distribution (QKD) is able to travel much farther, similar to how relay stations boost old telegraph or radio signals.
"The key distinction now is between better use of ordinary fiber and genuinely better fiber. QKD over fiber looks materially less constrained than in 2023, but general entanglement or quantum-state transmission still hits the same deep loss limit, so repeaters remain central," Bobier explained.
"No new paradigm has made repeaters obsolete; what happened instead is that the field diversified into use-case-specific workarounds around the repeater problem," Bobier added, pointing to trusted-node fiber networks such as the China Quantum Communication Network (CN-QCN), which spans more than 6,213 miles with 145 fiber backbone nodes.
Bobier also said there are also satellite/fibre hybrids in the mix, such as Chinese microsatellite Jinan-1, which is reportedly able to distribute up to 1.07 million secure bits of data over across an 8,000-plus mile China–South Africa key link.
With such progress dominated by China, it becomes clear why the White House has sharpened its focus on America's quantum progress.
Comments