VYPR
advisoryPublished Aug 11, 2026· 1 source

Post-Quantum Deadlines Clash With Operational Technology Realities

Critical infrastructure sectors face significant hurdles in adopting post-quantum cryptography due to outdated operational technology, potentially leaving them vulnerable to future threats.

National Institute of Standards and Technology (NIST) finalized post-quantum cryptography standards in August 2024, setting the stage for a global transition away from current encryption methods like RSA and elliptic-curve cryptography. Governments worldwide have imposed strict deadlines, generally between 2028 and 2030, for critical infrastructure operators to implement these new quantum-safe algorithms. However, a significant challenge looms: the vast majority of critical infrastructure, including power grids, water systems, and transportation networks, relies on operational technology (OT) systems that are often decades old.

These legacy systems frequently incorporate outdated remote terminal units (RTUs), SCADA platforms, and programmable logic controllers (PLCs) that were not designed with robust cryptographic capabilities in mind. While the new post-quantum algorithms themselves are designed to be compatible with OT environments, the surrounding ecosystem – including communication protocols, hardware limitations, vendor supply chains, and certification processes – is far from ready. Marin Ivezic, CEO of Applied Quantum, highlights that for large segments of OT, the infrastructure simply cannot support these advancements.

The migration from current cryptographic algorithms to post-quantum ones is often framed as a simple swap. However, in many OT operations, this analogy breaks down. The fundamental protocols used to transmit data between control centers and field devices were often developed without any meaningful cryptography. A.B. Sengupta, alternate CISO at Grid Controller of India, categorizes OT environments into two tiers: the IT-heavy layer, which includes elements like public key infrastructure (PKI) and VPNs, is more amenable to post-quantum migration. The critical field-level protocols, however, which manage commands and telemetry to RTUs and protection relays, and the inter-control center communication protocols, possess minimal cryptographic integration.

Maria Christofi of the European Union Agency for Cybersecurity (ENISA) notes that the migration process itself presents a substantial challenge. A key hurdle is the assumption that all systems can be upgraded to versions supporting post-quantum cryptography (PQC). This upgrade step can be exceptionally difficult and time-consuming for many organizations. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) echoed these concerns in October 2024, warning that OT environments often feature a significant proportion of out-of-date operating systems and software, including end-of-life platforms like Windows XP. CISA anticipates that OT systems may be among the last to achieve PQC standards due to lengthy patching cycles, hardware replacement timelines, and stringent operational governance.

A more immediate challenge for many organizations is the lack of a comprehensive inventory of the cryptography currently embedded within their OT environments. Cryptographic implementations in OT tend to be tracked with far less rigor than other security concerns. Christofi points out that cryptographic vulnerabilities are rarely prioritized at the same level as conventional security issues. Consequently, before any migration can be planned, organizations often must first undertake the arduous task of discovering what cryptography, if any, is already in use.

Even in OT protocols that do incorporate cryptography, replacing it with post-quantum alternatives is not straightforward. Research indicates that post-quantum signatures are larger and more memory-intensive than their predecessors. Many older field controllers lack the necessary memory capacity to accommodate these new, more demanding algorithms. Furthermore, Sengupta notes that numerous OEM-specific products and proprietary algorithms running in OT networks were never designed for key rotation, let alone for handling larger, more complex signature programs.

Field engineers often describe patching OT systems, including real-time control systems, as inherently riskier than patching IT servers. The potential for downtime is unacceptable in these critical environments. Updates must be rigorously tested on detailed clones of the live environment, a process that is not universally supported by common OT practices. The vendor landscape also presents a fragmented picture, with software-focused vendors progressing more rapidly on PQC support compared to hardware vendors supplying the foundational components like intelligent electronic devices, RTUs, and PLCs, down to the firmware and chip level.

Synthesized by Vypr AI