
Kari Ritacco
Dec 5, 2025
Departments can accelerate the migration to Post-Quantum Cryptography with commercial software solutions.
The June 2025 release of the “Roadmap for the Migration to Post-Quantum Cryptography” (ITSM.40.001) by Canada’s Cyber Centre marks a watershed moment for the Government of Canada’s (GC) cyber agenda. For departmental leaders and IT executives, it crystallizes both a mandate and a deadline:
By April 2026: each department must submit an initial PQC migration plan
By end 2031: critical high-priority systems should be fully migrated or quantum-risk mitigated
By end 2035: the entirety of non-classified systems must be PQC-secure
If agency leads wish to leverage existing budgets, avoid last-minute scramble, and preserve cyber resiliency, this mandate compels agencies to act now — not wait until 2030. Cryptographically relevant quantum computers (CRQC) may still be years off, but the rate of advancement is accelerating. It is no longer a question of if, but a question of how soon.
The near-inevitability of CRQCs inspires adversaries to harvest encrypted traffic today — storing it in the certainty that they will be able to decrypt it in the future. Any agency system protecting sensitive communications or citizen data is vulnerable to retrospective breach unless it transitions to quantum-resistant cryptography now.
The GC roadmap explicitly flags systems in public network zones as high-priority for quantum risk mitigation.