Looking for a quick answer? Jump To Quantum Computing FAQs
Encryption is built into far more of a manufacturing, wholesale, or distribution operation than most executives ever need to think about. It helps protect ERP connections, remote access, cloud applications, customer and supplier portals, websites, email, VPNs, digital certificates, software updates, warehouse systems, and communications between applications. In some environments, it may also be embedded in specialized equipment and systems that are expected to remain in service for many years.
For decades, businesses have been able to make a reasonable assumption about much of that encryption: when modern cryptography is implemented properly, defeating it through computing power alone is extraordinarily difficult. Quantum computing introduces a problem with that assumption because a sufficiently capable quantum computer could eventually break several forms of public-key cryptography that are widely used today.
There is no quantum computer currently capable of doing this at the scale required to threaten the cryptography used throughout ordinary business systems, and nobody can say with certainty when such a computer will exist. What has changed is the response to that future risk. In 2024, the National Institute of Standards and Technology finalized its first three post-quantum cryptography standards, providing technology companies and organizations with standardized replacements designed to withstand attacks from both conventional and future quantum computers. NIST is now encouraging organizations to begin planning for the transition rather than waiting for quantum computing to become an immediate threat.
For manufacturers, wholesalers, and distributors, this does not mean buying quantum technology or launching a special quantum-computing initiative. The more practical issue is understanding which systems the business expects to depend on for many years, where those systems rely on cryptography that will eventually have to change, and whether the vendors responsible for them have a credible path forward.
WHY A 2035 TIMELINE ISN'T AS FAR AWAY AS IT SOUNDS
NIST's current transition planning calls for quantum-vulnerable algorithms to be phased out of federal cryptographic standards, with a target of removing them by 2035 and earlier transitions for higher-risk uses. For an organization accustomed to replacing office computers every several years, 2035 may sound comfortably distant. For a manufacturer or distributor, the timeline looks different.
Consider technology being purchased today. An ERP platform may remain part of the business through several server generations. A warehouse management system may be used for a decade or longer. Industrial equipment can remain productive for 15 or 20 years, and specialized applications often survive because replacing them would require changes to equipment, integrations, workflows, or production processes. EDI relationships with customers and suppliers can also remain in place for years because they work reliably and both parties have little reason to disturb them.
A system purchased in 2026 with a 10- or 15-year expected life will operate directly through the period in which cryptographic standards are expected to change. That makes post-quantum readiness less of a futuristic cybersecurity topic and more of a technology-lifecycle issue.
In many cases, the company will not directly control the cryptography involved. The ERP vendor may control it in one system, while a firewall manufacturer, cloud provider, warehouse-software company, certificate authority, equipment manufacturer, or remote-access vendor controls it somewhere else. The business is therefore unlikely to perform most of the cryptographic migration itself, but it still needs to know whether important vendors intend to support the transition and whether existing products will be capable of receiving the necessary upgrades.
This becomes particularly important when evaluating technology expected to remain in service for a long time. Purchasing departments do not need to turn equipment proposals into cryptography examinations, but supportability, security updates, certificate management, upgradeability, and the vendor's long-term security roadmap increasingly deserve consideration. A piece of technology that performs perfectly today but cannot accommodate changing security standards may create an expensive problem years before its mechanical or operational usefulness has ended.
BEFORE A COMPANY CAN MIGRATE, IT HAS TO KNOW WHAT IT HAS
One of the difficulties with preparing for changes in cryptography is that most organizations do not have an inventory showing every place public-key encryption is being used. There is rarely a server or application conveniently labeled "quantum-vulnerable system." Cryptography is a component buried inside technologies the company purchased for entirely different reasons.
In a manufacturing or distribution environment, those technologies can include ERP and financial systems, EDI connections, customer and supplier portals, warehouse management systems, cloud applications, VPNs, firewalls, remote-access platforms, email security, digital certificates, backup systems, network equipment, software integrations, and specialized production-related systems. Some may be relatively new and actively maintained. Others may have been installed years ago and receive little attention because they continue to perform their intended function.
NIST's post-quantum migration work places considerable emphasis on cryptographic discovery for this reason. An organization cannot develop a realistic migration plan until it understands where vulnerable algorithms are being used, what business processes depend on them, and who is responsible for updating them.
For a mid-sized manufacturer, wholesaler, or distributor, that discovery does not necessarily require an immediate enterprise-wide cryptographic inventory project. It can begin as part of ordinary technology management. When systems are reviewed, upgraded, renewed, or replaced, the company can identify the technologies that depend on public-key cryptography and begin documenting which vendors have announced support for post-quantum standards. Older systems that are difficult to patch or no longer supported deserve particular attention because they are the most likely to become obstacles later.
This also provides a reason to look beyond the company's four walls. Manufacturers and distributors exchange information continuously with customers, suppliers, logistics providers, banks, outside service companies, and other trading partners. Those exchanges may rely on EDI, APIs, secure portals, VPNs, digital certificates, encrypted file transfers, or other forms of authenticated communication. A cryptographic transition on one side of that relationship can create a compatibility problem on the other.
The eventual migration will therefore have to account for interoperability as well as security. A supplier connection that has operated reliably for years cannot simply stop working because one organization changed its cryptographic requirements before the other was ready. Planning provides time to identify those dependencies, coordinate with vendors and trading partners, and test changes without unnecessarily disrupting ordering, production, warehousing, or shipping.
HOW LONG DOES THE INFORMATION NEED TO REMAIN SECRET?
The uncertainty surrounding quantum computing creates another issue that varies considerably from one company to another: the useful life of the information being protected.
A routine shipment notification or purchase-order acknowledgment may have little value to an attacker a decade from now. Engineering drawings, proprietary manufacturing processes, formulations, strategic sourcing information, customer data, private-label product specifications, intellectual property, and certain contractual information can retain value for considerably longer.
That difference matters because of a threat commonly described as "harvest now, decrypt later." The concern is that an adversary could obtain encrypted information today, retain it, and attempt to decrypt it in the future when more capable computing technology becomes available. The attacker does not need a cryptographically relevant quantum computer at the time the information is stolen if the information remains valuable long enough for such a computer to arrive later.
This does not mean every manufacturer should assume foreign intelligence services are collecting its encrypted network traffic. It means the useful life of information should be part of the company's risk assessment. An organization whose most sensitive intellectual property needs to remain confidential for 15 or 20 years has a different planning horizon from a business whose sensitive information loses most of its value within a few months.
That is one reason waiting for a definitive announcement that quantum computers can break today's encryption is not a sound migration strategy. For information requiring long-term confidentiality, the relevant risk period can begin before the quantum computer exists.
MANUFACTURING'S MIXED-AGE TECHNOLOGY ENVIRONMENT COMPLICATES THE TRANSITION
A modern office laptop may be replaced every three or four years. A production machine may not be. Between those two extremes are servers, industrial PCs, warehouse systems, network appliances, engineering workstations, controllers, remote-support devices, and specialized applications installed at different times and supported under very different arrangements.
This mixed-age technology environment is common in manufacturing and is one of the reasons broad technology transitions can be difficult. Some systems will adopt new cryptographic standards through routine software updates. Others may require firmware changes, new certificates, vendor involvement, testing, or hardware replacement. A few may be tied to applications or equipment for which meaningful vendor support no longer exists.
Replacing an aging office application is one thing. Replacing software or hardware that participates directly in production, warehouse operations, labeling, shipping, quality, or customer transactions is another. Changes may have to be scheduled, tested, coordinated with vendors, and evaluated for their effect on surrounding systems.
For that reason, post-quantum migration should fit into the same lifecycle planning businesses already use for other technology risks. When an unsupported system is identified today, quantum readiness may be only one item on a much longer list of concerns. The same system may also have operating-system vulnerabilities, limited patch support, obsolete protocols, unsupported hardware, or dependencies that make recovery difficult. Quantum computing does not suddenly make replacement urgent, but it adds another reason not to allow obsolete technology to become permanent infrastructure simply because it continues to run.
This is also where the concept of cryptographic agility becomes relevant. Despite the technical name, the management idea is straightforward: a system should be capable of changing the cryptographic methods it uses without requiring everything around it to be rebuilt. Technology designed with that flexibility will be easier to migrate as standards evolve. Systems tightly dependent on a particular algorithm, certificate structure, unsupported application, or fixed hardware platform may be considerably more difficult.
MOST BUSINESSES DO NOT NEED "QUANTUM" PRODUCTS
The terminology surrounding this subject can make the solution sound more exotic than it actually is. Post-quantum cryptography does not require a quantum computer. The standards NIST has finalized are mathematical algorithms designed to operate on conventional computing systems while resisting attacks from both conventional and future quantum computers.
That is different from quantum key distribution, or QKD, which uses specialized technology and principles of quantum mechanics to distribute cryptographic keys. QKD has legitimate applications, but it should not be presented as an ordinary next step for a mid-sized manufacturer, wholesaler, or distributor. The National Security Agency has stated that post-quantum cryptography offers a more cost-effective and maintainable approach than QKD for protecting National Security Systems and does not recommend QKD for those systems unless significant technical limitations are overcome.
That distinction is worth understanding because "quantum safe" will inevitably become a marketing phrase. Businesses should be cautious about purchasing expensive products simply because a vendor has attached quantum terminology to them. For most organizations, the transition will happen through updated operating systems, browsers, network equipment, cloud platforms, security products, certificates, business applications, and other technologies they already use.
The company's responsibility is not to invent the cryptography. It is to make sure the technology environment can accept it.
WHAT SHOULD MANAGEMENT BE DOING NOW?
There is no reason for a CEO, CFO, operations executive, or plant manager to monitor advances in quantum computing from week to week. There is also little value in trying to predict the exact year in which a sufficiently powerful quantum computer will emerge. The timeline will change as the science and engineering develop.
Management can instead incorporate the issue into decisions the company already makes. Systems expected to remain in service for many years should be evaluated for supportability and upgradeability. Strategic technology vendors can be asked about their plans for post-quantum standards. Older applications and devices that cannot be patched should be identified rather than allowed to disappear into the background. Companies holding information that must remain confidential for long periods should understand where and how that information is protected.
For manufacturers, wholesalers, and distributors, particular attention should go to systems whose failure or incompatibility would affect operations. ERP, EDI, warehouse systems, customer and supplier portals, remote-access platforms, network security equipment, and specialized production technology are all more consequential than an isolated desktop utility. The objective is not to replace these systems because of quantum computing. It is to make sure that when cryptographic standards change, the company is not surprised to discover that a critical operational system cannot follow them.
There is an important difference between preparing early and acting prematurely. Replacing working technology today solely because of a future quantum threat would be difficult to justify for most businesses. Ignoring the transition until vendors begin withdrawing support for older cryptography would create the opposite problem. The sensible position lies between those extremes: understand the environment, document important dependencies, pay attention to vendor roadmaps, and incorporate post-quantum compatibility into normal technology planning.
NIST's work gives businesses the luxury of doing this deliberately. The standards are available, major technology companies have begun working toward them, and the transition period is measured in years rather than months. That time is valuable if companies use it to address difficult dependencies before they become urgent.
The arrival of a quantum computer capable of breaking today's public-key cryptography is therefore not the date manufacturers, wholesalers, and distributors should be planning around. By that point, the important migration work should already be substantially complete. The more relevant timeline is the useful life of the systems being purchased and operated today, the longevity of the information they protect, and the amount of time the company would need to replace technology that cannot make the transition.
For businesses with modern, well-supported technology environments, much of the change may ultimately occur through normal vendor updates and replacement cycles. Companies with older, specialized, or poorly documented systems may face considerably more work.
Nobody needs to predict when quantum computing will become a practical cybersecurity threat to begin separating those two situations.
The standards are already changing. The business issue now is making sure the systems that support production, inventory, ordering, warehousing, shipping, and customer relationships will be capable of changing with them.
Frequently Asked Questions About Quantum Computing and Business Security
Can quantum computers break today's encryption?
Not yet. Current quantum computers are not powerful enough to break the public-key encryption commonly used in business systems. However, sufficiently capable future quantum computers could threaten widely used cryptographic methods, which is why NIST has already established post-quantum cryptography standards and is encouraging organizations to begin planning for the transition.
What is post-quantum cryptography?
Post-quantum cryptography, or PQC, refers to cryptographic algorithms designed to resist attacks from both conventional and future quantum computers. PQC does not require a quantum computer and can be implemented on conventional computing systems.
Do manufacturers need to replace their current systems because of quantum computing?
Generally, no. Manufacturers should not replace functioning technology solely because of the future quantum threat. They should, however, identify long-lived systems that depend on cryptography and determine whether important vendors have plans to support post-quantum standards through software, firmware, hardware, or product upgrades.
Which business systems could be affected by post-quantum cryptography?
Potentially affected systems include ERP platforms, EDI connections, VPNs, remote-access systems, firewalls, digital certificates, customer and supplier portals, cloud services, network equipment, warehouse systems, and specialized operational technology. The exact exposure depends on the cryptography used by each system and its vendors.
Why should manufacturers think about this now if quantum computers cannot break encryption yet?
Manufacturers often operate technology for 10, 15, or even 20 years. Systems purchased today may still be operating as cryptographic standards change, and some sensitive business information may need to remain confidential for decades. Planning early gives companies time to coordinate with vendors and replace systems that cannot make the transition without creating unnecessary operational disruption.
Data-Link Associates is a managed services provider specializing in cybersecurity, IT support and ERP systems for manufacturers, distributors and wholesalers. Our office is located in Sugar Grove, Illinois, and we manage manufacturing IT nationwide. At your service since 1983. Contact Angela Jamerson at ajamerson@datalinkmsp.com or (630) 406-8969.

Contact Us At