Key takeaway: In September 2025, the Australian Signals Directorate (ASD) updated its guidance on planning for post-quantum cryptography (PQC), first published in 2022. The update sharpens the timeline and gives organisations a concrete sequence to follow. It is written for security and IT teams, and it is excellent technical guidance.
But the legal exposure sits one level up from the technical fix, and that is what this article addresses: what the ASD timeline means for contracts, director accountability, data retention obligations, and the advice your clients will start asking for.
The gap is visible in the documents. In the supplier and cloud agreements I have reviewed since the guidance was updated, cryptographic standards are almost always not expressly covered and only touched on with a general reference to industry best practice or to the vendor’s own security policy. This is language that shifts with the vendor’s position rather than holding it. Very few contain a migration commitment, a date, or any allocation of the cost of transition.
The Problem in Plain Terms
A sufficiently powerful quantum computer (what ASD calls a cryptographically relevant quantum computer, or CRQC) would be able to break the asymmetric encryption that currently protects most digital communications and authentication: RSA, Diffie-Hellman, and their elliptic-curve variants. These are the algorithms behind the protocol that secures web traffic, VPNs, digital signatures, and much of the authentication infrastructure businesses rely on without thinking about it.
No such computer exists yet, and estimates of when one will vary. But the risk is not confined to the future. Encrypted data that is intercepted and stored today (a tactic commonly described as “harvest now, decrypt later”) can simply be decrypted once a CRQC becomes available. For information with a long confidentiality life (trade secrets, government and defence data, health records, anything that still needs to be secret in ten or fifteen years), the threat is live now, even though the computer that exploits it is not.
The Timeline Your Clients Need to Plan Around
ASD has set a firm outer boundary: organisations should stop using traditional asymmetric cryptography by the end of 2030. Three milestones sit inside that boundary:
- End of 2026: a documented, board-endorsed transition plan should be in place, reflecting your organisation’s risk tolerance, dependencies and the sensitivity of its data.
- End of 2028: transition should be underway, prioritising critical systems and the most sensitive or long-lived data first.
- End of 2030: the transition should be complete, with ongoing monitoring from that point.
That gives organisations until the end of this year to have a plan in place. For a board or a compliance committee, that is a much closer deadline than “sometime before 2030” suggests.
One further point for clients with offshore operations or US-facing supply chains: 2030 is not the only date in play. NIST deprecates RSA, ECDH and ECDSA from 2030 and disallows them from 2035; the US National Security Agency requires new national security system acquisitions to support post-quantum cryptography from 1 January 2027; and major platform vendors have set their own earlier internal deadlines. The practical consequence is that a client may be pulled forward by a counterparty’s or a platform’s timetable well before ASD’s, which is a reason to know what is in the supply contract now rather than in 2029.
Why This Is a Legal Question, Not Only a Technical One
Four issues make this squarely relevant to legal and compliance functions, not just IT:
1. Directors’ duties and foreseeable risk
ASD’s guidance is public, specific, and dated. Once a risk is this clearly signposted by a national authority, a board that has done nothing by the 2026 milestone will find it harder to argue the exposure was not reasonably foreseeable. The duty of care and diligence in section 180(1) of the Corporations Act 2001 (Cth) is measured against what a reasonable person would do in that position, in that company, and published, dated guidance from a national technical authority is precisely the kind of material that shapes what “reasonable” looks like at a given point in time. The relevant question at a 2027 board meeting will not be whether the company had finished migrating; it will be whether anyone put the 2026 milestone in front of the board at all. Directors do not need to understand the cryptography; they do need to be able to show that they asked the right questions and required a plan.
2. Contractual exposure: yours and your vendors’
Most organisations do not control their own cryptography; it is embedded in software, cloud services, and vendor platforms. That makes this a procurement and contract-management issue as much as a technical one. Contracts with vendors, especially those handling sensitive or long-lived data, should start to address migration timelines, support for post-quantum algorithms, and who bears the cost and risk of a vendor that lags. Standard-form supplier terms rarely deal with this today; that gap is worth flagging in any contract under negotiation or renewal from now on.
ASD has made this easier to operationalise. Its companion publication, Post-quantum questions to ask your vendors, sets out a structured question set mapped to the LATICE phases, and ASD’s own view is that vendor readiness may be one of the biggest factors determining whether an organisation meets the recommended timeframes. For legal teams, that document is effectively a ready-made due diligence schedule: it can be attached to a request for tender, worked into a vendor assurance questionnaire, or used to frame a warranty. One item in it is worth particular attention: whether the vendor maintains a Cryptographic Bill of Materials (CBOM), the cryptographic equivalent of a software bill of materials. A CBOM is a contractible deliverable in a way that “quantum readiness” is not.
Two drafting traps are worth knowing about. First, a vendor may describe a product as quantum-safe on the basis of a hybrid post-quantum/traditional scheme; ASD does not prohibit hybrid schemes but does not recommend them, because the traditional element becomes obsolete once a CRQC exists, so a hybrid deployment commits the client to a second transition later. Second, ASD does not support quantum key distribution for secure communications, citing practical limitations. A warranty drafted as compliance with ASD-approved post-quantum algorithms under the Information Security Manual is materially narrower, and more useful, than one drafted as “quantum-safe”.
3. Data retention and the Privacy Act
Organisations holding client or personal data with a long confidentiality tail (identity documents, health information, trust and estate records) are the ones most exposed to harvest-now-decrypt-later risk. This connects directly to Australian Privacy Principle 11, and to both of its limbs. APP 11.1 requires reasonable steps to protect personal information from unauthorised access, and what is reasonable is not static, so an encryption standard with a published expiry date will not indefinitely satisfy it. APP 11.2 is the limb more often overlooked here: it requires destruction or de-identification of personal information no longer needed for a permitted purpose. A business holding sensitive data it no longer needs, under encryption known to have a use-by date, is carrying a foreseeable future breach it had an existing obligation to avoid. Data minimisation and retention review are as relevant to PQC planning as they are to any other privacy audit.
4. Regulated sectors and long-lived confidentiality
Government, defence and defence industry suppliers, financial services, healthcare, resources, and the managed service providers holding data on their behalf typically carry information with the longest confidentiality requirements and therefore the greatest current exposure. For many of these clients, the obligation is not merely analogous: it is already in place. APRA-regulated entities are subject to CPS 234, which requires information security capability commensurate with the size and extent of threats to information assets. Responsible entities for critical infrastructure assets must maintain a critical infrastructure risk management program under the Security of Critical Infrastructure Act 2018 (Cth), and a signposted cryptographic threat with a published timetable is difficult to leave out of one. For non-corporate Commonwealth entities, the Information Security Manual applies through the Protective Security Policy Framework, which makes the 2030 date closer to an obligation than a recommendation. And a defence industry supplier holds technical data and program information whose sensitivity outlasts any single contract, while a managed service provider inherits the confidentiality expectations of every client whose systems it touches. Clients in these sectors should be treating a PQC transition plan as mandatory risk management, not a discretionary IT upgrade.
A Practical Sequence for Legal and Compliance Teams
ASD’s own framework for the technical transition is known as LATICE: locate, assess, triage, implement, communicate and educate. The legal and governance equivalent runs alongside it:
- Ask what encryption protects your organisation’s most sensitive and longest-lived data, and who is accountable for that answer. This is the legal equivalent of ASD’s “locate” phase.
- Have that inventory assessed against your regulatory obligations (Privacy Act, sector-specific retention rules, privilege) so risk is ranked by legal consequence, not only technical difficulty.
- Review vendor and supplier contracts for cryptography and security clauses, and start building PQC-migration expectations into new contracts and renewals.
- Confirm the board has formally considered and endorsed a transition plan before the end of 2026 and that this is minuted.
- Revisit data retention practices so that information without a genuine ongoing purpose is not sitting in long-term storage under an encryption standard with a known expiry.
None of this requires the board or the general counsel to understand quantum computing. It requires the same discipline applied to any other foreseeable, timetabled regulatory risk: assign ownership, document the decision, and revisit it on a schedule that matches the milestones the regulator has already published.
Disclaimer
This article is general information only and is not legal advice. It draws on the Australian Signals Directorate’s Planning for post-quantum cryptography guidance (September 2025) but does not reproduce that guidance in full, and organisations should refer to the original publication and the ASD Information Security Manual for complete technical detail. Whether and how these issues apply to your organisation depends on your specific circumstances, contracts and regulatory position. Obtain advice specific to your organisation before acting.
Sources: Australian Signals Directorate, Planning for post-quantum cryptography, https://www.cyber.gov.au/business-government/secure-design/quantum/planning-for-post-quantum-cryptography; Australian Signals Directorate, Post-quantum questions to ask your vendors, https://www.cyber.gov.au/business-government/secure-design/quantum/post-quantum-questions-to-ask-your-vendors.
