Michele Mosca (EvolutionQ): Why quantum-safe migration takes longer than most companies think

Key takeaways

  • Migrating to quantum-safe cryptography is not a software patch, it requires inventorying every cryptographic dependency across an organization, which most companies have never done
  • Mosca's inequality frames the risk: if the time to migrate plus the shelf-life of sensitive data exceeds the time until a cryptographically relevant quantum computer exists, the data is already exposed
  • Quantum key distribution and post-quantum cryptography solve different problems and are not interchangeable, so treating QKD as a full substitute for PQC misses the point
  • Finalized NIST standards are just the starting line, testing, integration, and supply chain coordination across vendors is the part that actually stretches migration timelines

Summary

Michele Mosca, founder, President, and CEO of EvolutionQ, a quantum-safe cybersecurity company is interviewed by Yuval Boger. They talk about Post-quantum cryptography and quantum key distributions, the timeline for hardening a company’s infrastructure, standards organizations, and much more.