
Adobe stock
Canada faces a narrower window than most institutions realize to protect its most sensitive digital secrets from a coming generation of quantum computers.
"The biggest and scariest threat is that we don't upgrade our public cryptography before these threats become relevant," Michael Murphy, a researcher with Queen's University's Centre for International and Defence Policy, told Vanguard.
A cryptographically relevant quantum computer (CRQC) is one that can compute fast enough, with or without full error correction, to challenge current encryption protocols like RSA. Once that threshold is crossed, Murphy said, such machines will be able to crack into data considered secret across Canada, the European Union, and other advanced democracies.
No CRQC exists yet, and estimates on when one will vary widely. That uncertainty is precisely the problem: information requiring long-term protection needs to be secured proactively, well before a working CRQC arrives, not after.
Ottawa's response: the National Quantum Strategy
The federal government has moved to get ahead of the problem.
In 2023, Innovation, Science and Economic Development Canada (ISED) released Canada's National Quantum Strategy, which the department told Vanguard is meant to "ensure the privacy and cybersecurity of Canadians in a quantum-enabled world through a national secure quantum communication network and a post-quantum cryptography initiative."
ISED said the strategy was developed through close engagement with industry, academia, and provincial governments, and has since been followed by a roadmap outlining the milestones and actions expected of all stakeholders.
The strategy and its accompanying roadmap mark Ottawa's clearest attempt yet to coordinate a national transition to quantum-safe systems, spanning not just federal departments but the private sector and provinces as well.
A readiness gap, and an ally already moving
Cryptographic watchdogs in Canada, the EU, and other advanced democracies have set 2035 as the deadline to transition public digital infrastructure. But the runway may be shorter than planned.
Google announced in March 2026 that it is moving up its own internal deadline for migrating to post-quantum cryptography to 2029, citing faster-than-expected progress in quantum hardware, error correction, and factoring resource estimates. The company said the accelerated timeline was meant to "provide the clarity and urgency needed to accelerate digital transitions not only for Google, but also across the industry."
Murphy pointed to a significant readiness problem even against the 2035 target. Canada aims to have its quantum risk auditing complete by then, but many private institutions will not meet it, in large part because there simply are not enough trained people to conduct the audits or build transition plans across every public and private institution that needs one.
The gap is not purely a resourcing problem.
"It seems like a fuzzy threat," Murphy said, describing conversations with private sector colleagues who advise on cryptographic transitions. "Boards of directors are reticent to devote major resources to auditing quantum risks and launching a cryptographic transition for a threat that might be three years away, or might be 10 or 15."
Washington has already moved to close that gap for its own national security systems. In 2022, the National Security Agency released an updated set of quantum-resistant algorithm requirements, known as CNSA 2.0, for systems handling classified and mission-critical information.
"This transition to quantum-resistant technology in our most critical systems will require collaboration between government, National Security System owners and operators, and industry," Rob Joyce, director of NSA Cybersecurity, said at the time.
Harvest now, decrypt later
A second, related threat compounds the first. Murphy described what security researchers call "harvest now, decrypt later," or HNDL: adversaries, mostly China, along with other state and non-state actors, are already collecting encrypted data they cannot yet read. That data is cheap to store and can simply wait until a CRQC comes online, at which point it becomes accessible.
Not all of that harvested data will matter by the time it can be decrypted.
"If it's an email about my plans for Saturday afternoon, that's now three years out of date. That's useless," Murphy said. "But if it's about vulnerabilities in pipelines or satellites or ports, or NORAD modernization, those long-lifespan secrets are at risk today."
He noted that data of this kind has effectively been exposed for years already, simply sitting in storage until decryption becomes possible.
Beyond data theft: digital signature spoofing
Murphy flagged a further risk that extends past stolen secrets into active manipulation: digital signature spoofing. Anything that currently relies on digital signatures for security, from bank account access to services like DocuSign, becomes vulnerable once quantum computers can forge them. So does the trusted-signal infrastructure behind smart city systems, including traffic light networks.
He offered a hypothetical to illustrate the scale of the risk: a quantum-capable actor spoofing every traffic light in a city to turn green, or red, simultaneously, compounding existing prepositioned cyberattack techniques already associated with China, Iran, and North Korea, in which malware is planted in critical systems, such as cooling infrastructure at nuclear plants or hydroelectric dam controls, and left dormant until an adversary chooses to activate it.
"The ceiling of the threat is our imagination," Murphy said, "and perhaps higher."
An open question on offence
Asked whether Canada and its allies are running comparable offensive operations, Murphy said it is difficult to know with any precision.
He pointed to a shift in American cyber doctrine toward what is known as persistent engagement: rather than holding a threat in reserve as deterrence, the approach favours continuously testing and probing an opponent's cyber defences to signal capability and presence.
Details of these operations remain highly classified, and Murphy said the public will likely only get a clearer picture if and when insiders eventually speak publicly.
“Until someone goes on a podcast and reveals all the secrets,” he said, “it can be hard to know what’s going on.”










