PQC
The quantum computing industry has largely justified itself through one practical application: Shor’s algorithm breaking RSA and ECC public-key cryptography.
Grover and Grover-like algorithms are the secondary argument. They offer theoretical quadratic improvements for some search and statistical problems, but a quantum result is not obtained from a single clean deterministic run. Each circuit must be measured repeatedly, often thousands or even 100,000 times, to extract a stable answer.
Once repeated shots, state preparation, reversible oracle construction, quantum noise, error correction and hardware cost are included, the theoretical Grover benefit disappears completely. In fact, you’d be mad to even think about using quantum computing for these applications.
The irony is that the PQC response to the perceived quantum threat will reduce the need for the primary quantum computing application.
Post-quantum cryptography is already being standardised and deployed. If banks, governments and critical infrastructure migrate successfully before cryptographically relevant quantum computers exist, then the principal commercial rationale for building those machines is removed.
The important point is that the PQC migration will happen anyway. Regulators cannot wait for proof that cryptographically relevant quantum computers will exist because cryptographic transitions take many years.
Central banks and prudential regulators are therefore likely to define common migration standards that financial institutions will implement regardless of whether large-scale quantum computers ever become practical.
For a bank, the direct PQC exposure by data volume may be small.
Probably less than 1–5% of stored data is directly protected by RSA, ECC or Diffie-Hellman in a way that PQC replaces.
Around 20–50% of applications may contain some quantum-vulnerable cryptographic dependency, including TLS, certificates, SSH, VPNs, APIs, code signing, identity systems, HSM integrations or third-party services.
More importantly, 60–90% of critical business processes may depend indirectly on vulnerable public-key cryptography through payments, trading, customer channels, authentication, interbank connectivity, cloud services and vendor integrations.
The commercial opportunity is therefore not quantum computing. It is regulated cryptographic transition management.
Banks do not need bespoke quantum strategies. They need to understand their exposure, inventory quantum-vulnerable cryptography, classify business risk, comply with regulatory standards and demonstrate progress.
Implementation is then performed by cybersecurity vendors, systems integrators, cloud providers, HSM vendors, PKI vendors and internal technology teams.
The durable proprietary asset is the cryptographic dependency database: a living map of every certificate, key, algorithm, application, vendor dependency and business process that relies on quantum-vulnerable public-key cryptography.
The PQC opportunity is measured in critical operating dependencies that must be inventoried, prioritised, migrated and evidenced. That database remains valuable throughout migration and ongoing compliance, irrespective of whether a quantum computer capable of breaking RSA is ever built.
Which is extremely unlikely. Isaac Chuang has just convinced me that we know in principle how to build a working quantum computer. My counter view is that it won’t be worth investing the enormous funds required to do so. And over long enough timeframes, investment theses always becomes rational. Digital computer technology was in the same boat originally but the competition was pen and paper, slide-rules and the odd mechanical adding machine. Quantum has to compete with digital, which isn’t exactly standing still.
From an education point of view, my take home summary is that quantum computing will be irrelevant to this future story.
What needs to be taught is the basics of PQC.
PQC
PQC is pretty simple stuff when you look into it.
RSA’s assumption was simple: factoring large integers is computationally intractable.
That assumption held until Shor showed that it fails in the quantum computing model.
LWE’s assumption is different: if a secret is hidden inside many slightly incorrect equations, no efficient classical or quantum algorithm is known for recovering it.
That is the basic shift from RSA to PQC: from the assumed hardness of factoring to the assumed hardness of recovering secrets from noisy equations.
The transition away from quantum-vulnerable cryptography is enabled not by quantum computers, but by decades of improvement in classical computing.
PQC is practical because digital processing, memory, storage and network capacity are now distributed everywhere: phones, servers, laptops, cloud platforms, HSMs, payment terminals and network appliances. The global infrastructure has become powerful enough to absorb the additional computational, memory and bandwidth cost of PQC.
Postscript
This is not a theorem. It is a strategic decision under uncertainty.
For that purpose, the decision has to be binary. Quantum computing either becomes the business, or PQC migration becomes the business. Waiting for certainty is itself a (terrible) decision.
My working assumption is that cryptographically relevant quantum computers will not arrive at all and definitely not in the relevant commercial window, but PQC migration will proceed anyway because regulators, boards and risk managers will require it.
Under that assumption, the durable educational opportunity is not in quantum computing. It is in the cryptographic transition.
The assumption ledger is roughly:
• Shor is the only commercially compelling quantum algorithm.
• Grover-derived use cases do not survive end-to-end implementation costs.
• PQC migration will proceed because of regulation and governance, not because quantum computers are demonstrated.
• PQC migration will substantially reduce the value of cryptographically relevant quantum computers.
• The durable commercial value is therefore in transition management rather than quantum computing.
End note
Quantum computing may survive if a high-value niche exists where classical digital computers are genuinely inadequate and where quantum hardware has no practical substitute.
Just like space saved solar cells.
