India processes over billions of UPI transactions a month. Also, billions of citizens are linked to Aadhaar, and hundreds of millions access banking, insurance and government services through digital channels. Every one of these interactions relies on cryptography to stay secure.
And now, according to tech pioneers, intelligence agencies and governments opine that cryptography is at risk. Why? Because quantum computers, once sufficiently powerful, will be able to break the public-key encryption that protects these systems.
What makes this different from past threats is that adversaries do not need a quantum computer yet. They are collecting encrypted data now, with the intent to decrypt it once quantum capability arrives. This is the “Harvest Now, Decrypt Later” (HNDL) attack, and it is already underway.
Post-quantum cryptography (PQC) migration is the process of replacing quantum-vulnerable algorithms with quantum-safe alternatives across an organisation’s entire cryptographic estate.
For Indian enterprises, it is important because the Government of India has set binding timelines, and the window for planned action is narrowing. This blog explains why India’s digital infrastructure is particularly exposed, what the government has mandated, which sectors must act and by when.
Why India’s digital scale creates unique quantum exposure
India’s digital growth story is also its quantum vulnerability story. The same infrastructure that powers digital payments, e-governance, health records and financial markets is built on cryptographic standards that quantum computing will eventually break.
1. The infrastructure at risk
Public-key algorithms such as RSA and Elliptic Curve Cryptography (ECC) are used across every layer of India’s digital stack, from TLS certificates securing web traffic, to the digital signatures underpinning DigiLocker documents, to the encryption protecting SWIFT transactions in banking.
These algorithms derive their strength from mathematical problems that classical computers cannot solve efficiently. Quantum computers, using Shor’s algorithm, can solve them.
India’s interconnectedness amplifies the risk. A cryptographic failure in one sector can cascade into others. A compromised PKI in the banking system does not stay confined to banking.
2. The HNDL threat is not theoretical
Adversaries may be intercepting Indian government communications, strategic data and financial records today, storing them for future decryption. The May 2026 Government of India Task Force report on quantum-safe security explicitly flags the “Trust Now, Forge Later” (TNFL) risk alongside HNDL, noting that digital signatures used across legal, financial and identity systems can be forged retroactively once quantum capability arrives. For data with a shelf life of ten years or more, the threat is active now.
What India’s government has mandated
The Government of India, through the National Quantum Mission (NQM) under the Department of Science and Technology (DST), constituted a Task Force for Implementation of a Quantum Safe Ecosystem in India. The Task Force released its comprehensive roadmap in May 2026, setting the first formal national timelines for PQC migration.
The National Quantum Mission framework
The NQM, approved by the Cabinet in April 2023 with a budget of Rs 6,003.65 crore through 2030–31, established four Thematic Hubs at premier institutions across IISc Bengaluru, IIT Madras, IIT Bombay and IIT Delhi. These hubs cover quantum computing, quantum communication, quantum sensing and quantum materials respectively.
Quantum-safe security sits centrally in this mission. The Task Force brings together stakeholders from academia, R&D labs, government departments and industry, with Terms of Reference that include overseeing and formulating guidelines for phased PQC transition, advising on Indian standards for PQC adoption and suggesting measures for PQC migration.
Binding deadlines by sector
The Task Force report draws a clear line between Critical Information Infrastructure (CII) sectors and general enterprises:
CII sectors which include BFSI, defence, power, telecom and transport follow an accelerated three-milestone track:
- Foundations (governance, cryptographic inventory, pilot projects): by December 2027
- High-priority system migration (PKI, HSMs, key management): by December 2028
- Full PQC adoption across all systems: by December 2029
General enterprises follow a parallel but extended track:
- Foundations: by 2028
- High-priority migration: by 2030
- Full PQC adoption: by 2033
The report communicates these timelines directly to regulators including SEBI and RBI, with an instruction to initiate sector-specific guidance and legal frameworks for compliance.
Immediate actions already underway
The Task Force has recommended several short-term actions with a 2027 deadline for CII. These include launching PQC and hybrid (classical plus PQC) pilots in high-priority systems such as banking and finance, establishing a National PQC Testing and Certification Programme under TEC, STQC and BIS, mandating PQC-compliant assets and compulsory Bill of Materials (BOM) in all government procurement, and mandating CBOM submissions from vendors starting FY 2027-28.
Which sectors face the earliest pressure
1. BFSI: the highest-urgency sector
BFSI is explicitly named as a CII sector under the Task Force roadmap. RBI and SEBI have both been directed to initiate sector-specific guidance. SEBI’s CSCRF framework, updated in 2025, already introduced an expectation that regulated entities inventory cryptographic assets and prioritise PQC migration based on risk and data sensitivity.
For banks and financial institutions, the risk is particularly acute. Payment systems, certificate authorities, digital signatures on contracts, HSMs protecting key material – all of these rely on algorithms that quantum computing will break. And the data protected by these systems – customer records, transaction histories, strategic communications – has a shelf life that often exceeds a decade.
2. Telecom: backbone infrastructure
India’s telecom networks carry the signalling, authentication and key exchange that underlies digital India. The Task Force notes that microsecond-level environments in telecom face the most challenging PQC migration, as quantum-safe algorithms carry computational overhead that can degrade performance at high transaction speeds.
3. Healthcare and government
Healthcare records and government communications carry some of the highest data longevity of any sector. Medical data, legal records and identity documents routinely require confidentiality over decades. Under the HNDL model, these records are already at risk. The Task Force explicitly includes healthcare in the L3 (enterprise-grade) assurance framework.
Starting your PQC migration: what to do first
The Task Force is clear that the first step for any enterprise is building foundations – and foundations begin with a cryptographic asset inventory. You cannot migrate what you cannot see.
A Cryptographic Bill of Materials (CBOM) gives your team a structured, machine-readable inventory of every algorithm, key, certificate and protocol in use across your systems. SEBI CSCRF already signals this expectation for regulated entities. The NQM Task Force mandates CBOM submissions from vendors starting FY 2027–28.
At CyberNX, our PQC readiness solutions will help BFSI, and enterprise organisations build that inventory, identifying quantum-vulnerable cryptographic assets, generating migration-ready CBOMs and mapping your readiness against India’s regulatory timelines. If your organisation is in a CII sector, the 2027 foundations deadline is effectively now.
Talk to our team about where your cryptographic estate stands and what a phased migration programme looks like for your organisation.
PQC Migration FAQs
What is PQC migration?
PQC migration is the process of replacing cryptographic algorithms that are vulnerable to quantum computing attacks with quantum-resistant alternatives. It covers algorithms used in encryption, digital signatures and key exchange across an organisation’s full technology stack, including applications, infrastructure, HSMs and PKI.
Which Indian organisations must start PQC migration now?
Organisations classified as Critical Information Infrastructure (CII) – including those in BFSI, defence, power, telecom and transport – are required to complete foundational steps by 2027 under the May 2026 Government of India Task Force roadmap. General enterprises have a foundations deadline of 2028. Any organisation handling long-lived data or operating under RBI, SEBI, CERT-In or IRDAI oversight should treat this as an immediate planning priority.
What does “Harvest Now, Decrypt Later” mean for Indian enterprises?
HNDL refers to the practice of intercepting and storing encrypted data today, with the intent to decrypt it once quantum computers become capable of breaking current encryption. For Indian enterprises holding financial records, healthcare data, strategic communications or customer information with a shelf life of five or more years, this threat is active now – not when Q-Day arrives.




