QuantumGate says enterprises have roughly 30 months before today's encryption starts to expire
The window for organisations to move off the encryption protecting the world's financial transactions, medical records and government communications has narrowed to about two and a half years, according to QuantumGate, the post-quantum cryptography venture built inside Abu Dhabi's Advanced Technology Research Council.
"Begin today, there is no longer a timeline. We are in the timeline," said Adnan Fakhouri, Customer Success Lead, Delivery at QuantumGate, speaking to The Source Code. "No more discussing and developing timelines. We're already part of step one right now, which is the discovery phase for the transition to post-quantum cryptography, and it's coming. It may come quicker than we expect."
QuantumGate sits under VentureOne, ATRC's commercialisation arm, and builds on cryptographic work from the Technology Innovation Institute's Cryptography Research Centre. Its products are sold into both public and private markets in the UAE and internationally.
The company's proposition rests on a threat that does not require a working quantum computer to be dangerous today: an adversary can collect encrypted traffic now and hold it until quantum hardware becomes capable enough to open it.
That risk has a name in the industry, and Fakhouri argued its status has changed. "Harvest now, decrypt later was always a bullet point or a side point, one of the threats of quantum computers. This is changing rapidly, tt's now becoming a board-level conversation," he said. "The 10 to 15 years five years ago is now five to 10 years, and in five to 10 years it's going to become a now problem. So harvest now, decrypt later is going to be harvest now, decrypt now."
The migration starts with an inventory, not an algorithm swap
The most common error Fakhouri encounters is a misunderstanding of what the work actually involves. Organisations assume post-quantum migration means replacing their cryptographic algorithms, and budget accordingly.
"A big misconception we get from clients, from partners, from trade shows and events is that the migration is only replacing the cryptography, and that's really near the end of the migration," he said. "The first steps of the migration start with understanding what you have and building a phased roadmap to begin this transition."
That means discovery first: mapping where cryptography sits inside an environment, which systems depend on it, and what vendors have committed to in their own roadmaps. The inventory then produces a risk-based order of operations, with the most sensitive and longest-lived data moved first, since that data remains exposed for the next decade or more regardless of when quantum machines mature.
A second misconception concerns hardware. "Another misconception is that you require a quantum computer to run these algorithms. That's not the case," Fakhouri said. "They are designed to run on classical computers that are already operational."
Most organisations take a hybrid approach, running established algorithms such as RSA or Diffie-Hellman alongside the newer post-quantum algorithms standardised by the US National Institute of Standards and Technology. The design principle Fakhouri returns to is crypto agility. "Instead of needing to replace the technology as cryptography evolves, we simply replace the cryptographic stack," he said.
The sharpest change over the past year, in Fakhouri's account, is on the regulatory side. Until recently the public-sector conversation was about awareness. Now it is about procurement and compliance.
QuantumGate is working with the UAE Cyber Security Council on the national Crypto Discovery Tool, an Abu Dhabi-built system for cryptographic discovery, inventory management and continuous monitoring across national infrastructure, customised to requirements set by the National Cryptography Center. "It ensures that compliance for any entities that fall under the Cybersecurity Council is given with the adoption of the tool," Fakhouri said.
The pattern is not confined to one country. Regulators across multiple jurisdictions are now contracting directly with post-quantum providers rather than publishing guidance and waiting. "Regulatory bodies are partnering with PQC-ready companies and PQC providers to help these sensitive industries move towards compliance," he said, adding that expectations will keep rising. "Preparation is moving from just strategising to now executing."
The practical consequence for security teams is that ignorance stops being a defensible position. "There's no longer an excuse for 'I didn't know where my crypto is', or 'I didn't know I had this type of cryptography, I didn't know what dependencies I have'," Fakhouri said. Full visibility of the cryptographic estate, he argued, becomes a compliance requirement rather than good practice.
Quantum and AI are compressing the same timeline from opposite ends
Fakhouri used a piece of internet culture to make a point about the pace of quantum research. Three years ago, an AI-generated video of Will Smith eating spaghetti was a broken, crumbling mess, and today the same prompt produces something close to indistinguishable from footage. The equivalent curve in quantum computing concerns the number of logical qubits required to threaten current encryption, and that number keeps falling.
"You need less computational power to begin breaking these algorithms that exist today," he said. "Both of these industries, whether we see it or not, are advancing in parallel. Quantum affects how the cryptography itself is going to be safeguarded, and then AI is going to change how attacks and defence operations take place day to day."
The two technologies also depend on each other - AI already helps security teams detect attacks, triage alerts and automate routine operations, freeing analysts for harder judgement calls, and Fakhouri sees it supporting cryptographic discovery in environments too large to map by hand. AI models, meanwhile, are built on exactly the kind of data post-quantum cryptography exists to protect. "The long-lived data that AI relies on to power these models is the exact area where PQC and post-quantum protection is meant to cover," he said.
The sectors Fakhouri expects to deploy first are the ones where the data has a human name attached to it: banking, where customer records and transaction data move continuously between institution and account holder, and healthcare, where patient files retain their sensitivity for a lifetime.
Sovereignty has become a continuity question
Fakhouri's argument for sovereign cryptographic capability rests less on national pride than on supply risk. Sanctions, geopolitical disruption and attacks on foreign vendors can all sever access to a security product with no warning and no relationship to the customer's own conduct.
"Having that kind of sovereignty aspect built into your technology will prove vital when attacks on foreign vendors, or sanctions, or uncontrollable regional events start to happen," he said. "Sometimes there are factors that are not in our control. It could be something completely unrelated that's affecting the use of a technology, and then you're left maybe stranded if you didn't work with a sovereign vendor."
He expects more governments and enterprises to build or buy domestically for this class of technology, and the collaboration model to shift with it. Research, commercialisation and compliance functions that once worked separately are now operating together. What survives all of it, Fakhouri said, is unglamorous. "A strong cryptographic foundation that is visible to you, that is agile, will remain paramount to our success as we move to a digital age."
The clock he keeps returning to is a specific one. Current algorithms are scheduled for deprecation in 2029. "That's about 30 months we're looking at," he said. "Putting that in perspective, it's really not as much time as people would think."