India’s Quantum-Safe Roadmap: Critical Sectors to Adopt Post-Quantum Cryptography by 2029, Others by 2033

Updated October 2026.

Large quantum computers could one day break the encryption that protects today’s internet banking, VPNs and digital signatures, such as RSA and elliptic-curve cryptography. A government task force on quantum-safe migration, chaired by the CEO of C-DOT, published a roadmap in early 2026 setting out how India should move to post-quantum cryptography (PQC).

The proposed timeline

MilestoneCritical Information Infrastructure (defence, power, telecom and others)Other enterprises
Governance, inventory, pilotsBy 2027By 2028
Migrate high-priority or critical systemsBy 2028 (no new classical-only deployments)By 2030
Full PQC adoptionBy 2029By 2033

Key recommendations

  • Cryptographic inventory: know where and how encryption is used. Vendors should provide a Cryptographic Bill of Materials (CBOM).
  • Standards: adopt the NIST-standardised algorithms ML-KEM (key exchange) and ML-DSA (signatures), often in “hybrid” mode alongside classical algorithms during the transition.
  • Testing labs: set up national PQC testing and certification capacity, with assurance levels from basic to sovereign-grade.
  • Sector pilots: start in banking, finance and government. Communicate requirements to regulators such as RBI and SEBI.
  • Procurement: add quantum-safe requirements to government RFPs, with a preference for indigenous solutions where possible.

Why start now: “harvest now, decrypt later”

Attackers can steal encrypted data today and store it until a quantum computer can decrypt it. Data that must stay secret for many years is already at risk. That includes health records, defence information, long-term financial data and intellectual property.

What IT and security teams can do now

  1. Inventory certificates, protocols, libraries and hardware security modules.
  2. Build “crypto-agility”, so algorithms can be swapped without rewriting systems.
  3. Ask vendors (cloud, VPN, HSM, PKI) for their PQC roadmaps and CBOMs.
  4. Test hybrid PQC in TLS where your platforms support it.
  5. Upskill: PQC, PKI and applied cryptography skills will be in demand.

Sources

Leave a Reply

Discover more from RP Strativa Globals

Subscribe now to keep reading and get access to the full archive.

Continue reading