Analysis

KPMG urges clients to start post-quantum migration now

KPMG is telling clients to inventory RSA and ECDSA now as a 2035 cutoff looms. NIST's finalized standards and Q-PREP are turning quantum risk into a migration clock.

Marcus Chen··2 min read
Published
Listen to this article0:00 min
KPMG urges clients to start post-quantum migration now
AI-generated illustration

KPMG is warning clients to begin moving away from RSA and ECDSA now, saying those legacy public-key systems will be disallowed by 2035 as quantum computing advances. The firm is pairing that warning with Q-PREP, its post-quantum readiness offering, and pushing organizations to map every place those algorithms still sit across large IT environments before replacement work gets more expensive.

The countdown has sharpened since NIST finalized the first three post-quantum encryption standards on Aug. 13, 2024. NIST then published an initial public draft of Transition to Post-Quantum Cryptography Standards on Nov. 12, 2024 and kept the comment period open through Jan. 10, 2025. Those steps gave CIOs, audit leaders and security teams concrete standards to plan around instead of waiting for a vague future Q-Day.

AI-generated illustration
AI-generated illustration

KPMG's timeline also matches the direction of major technology companies. Google, Microsoft and Cloudflare have each set post-quantum readiness targets around 2029 or 2030, leaving only a few planning cycles before the 2035 deadline KPMG is flagging to clients. In a business where technology refreshes, vendor contracts and control testing often move on multiyear schedules, that gap is already short enough to affect annual budgets and client planning.

The hardest transitions are likely to land in financial services, where the G7 Cyber Expert Group issued a January 2026 roadmap for a coordinated migration to quantum-resistant cryptography in the financial sector. The policy push reflects a broader reality that public-sector and standards bodies are urging earlier preparation rather than waiting for the moment quantum computers become powerful enough to break current systems.

KPMG's own quantum materials say the threat is no longer theoretical and that waiting could cost more than acting. KPMG US also frames quantum risk as both a strategic risk and a competitive advantage, language that gives partners and managers a way to turn a distant technology issue into a near-term transformation discussion about inventories, migration planning and client roadmaps. For consultants, auditors and cyber advisers, that makes quantum one more topic moving from the back burner into the next client review and the next promotion-cycle conversation.

This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.

Did this article answer your question?

Discussion

More KPMG News