
EigenQ’s QMA PCIe x4 QRNG acceleration board is designed to supply photon-based quantum entropy to servers, data centers and other cryptographic infrastructure. Credit: EigenQ
No one knows for sure when quantum computers will be able to crack widely used public-key encryption methods, but the anxieties are on the rise that the threshold may be in the relatively near term. The probability of a cryptographically relevant quantum computer is in the ballpark of 28% to 49% within 10 years and 51% to 70% within 15 years, according to the 2026 Global Risk Institute/evolutionQ survey of 26 quantum experts published in March. Google, meanwhile, estimated in February that the quantum resources needed to break the public-key asymmetric encryption standard RSA-2048 have fallen by orders of magnitude over the past decade.

José Rosas-Bustos
The shifting landscape is causing organizations in industries ranging from Big Pharma firms to government organizations with sensitive data worry. “The question,” says José Rosas-Bustos, CEO of EigenQ, is “about the time frame.” Many organizations are asking when they need to prepare. “Is it now? Is it in three years? Is it in five years? Is it in 15 years?”
Meanwhile, anxieties are also growing about so-called “Harvest now, decrypt later” (HNDL) cyberattacks, a strategy where adversaries intercept and store encrypted data with the aim of using a quantum computer in the future to decrypt it. The National Institute of Standards and Technology (NIST) lists the threat to long-lived secrets as a prime reason organizations should begin adopting post-quantum encryption techniques now. Rosas-Bustos echoes that perspective noting risks for both individuals and organizations. “Many people are not comfortable with their financial information being public, and financial information is one of the things that actually has a data retention that goes from 10 years to 15 years,” he said. “As a person, I would say, well, in five years a quantum computer could reveal my financial history from five years ago. Do I care about that?” he asked. Rosas-Bustos said the stakes can be even higher for organizations safeguarding long-lived corporate and drug-discovery data, as well as for national security, defense and intelligence agencies. “For those kinds of folks, it becomes very relevant if in five years somebody has harvested information and the decrypted information actually becomes relevant for certain cases,” he said.
The shifting risk estimates are already prompting governments and major technology users to prepare. NIST’s National Cybersecurity Center of Excellence has organized a Migration to Post-Quantum Cryptography consortium of 60-plus organizations. Members include AWS, Google and IBM as well as CVS Health, HSBC and SWIFT. In January, CISA published its first list of product categories that support PQC standards, developed with the NSA under Executive Order 14306.
Rosas-Bustos points to national security, defense and intelligence organizations as the typical early adopters of new cryptographic standards and quantum-resistant security technologies, “for obvious reasons,” he said. “But then you have followers. You have industries that cannot afford not to be using the best that is available in the market, and in that sense you have the financial sector, you have healthcare, and you have anything related to IT.”
The private sector echoes the increasing interest. Cloudflare has stated that it aims to implement full post-quantum security by 2029, while also noting that the share of human web traffic reaching its network with post-quantum encryption more than hit 65% around April 2026.
Most of the traffic figure reflects browsers and content delivery networks enabling hybrid key exchange by default. Crypto-agility is a more challenging affair when it comes to long-lived servers and other hardware that may remain deployed for a decade or even as about a quarter-century. “So what are the chances that the ciphers may change in that period of time?” Rosas-Bustos said. “Imagine, from now on, you have 20 more years. Are we going to have a new version of ciphers?”
Rosas-Bustos frames crypto agility as something that has long been neglected in cybersecurity. “It has often been a second priority because there is always an emergency happening in cybersecurity,” he said. “My opinion is that crypto agility is a must-have, not a nice-to-have anymore.”
For its own part, EigenQ is aiming the crypto-agility argument at hardware. The company sells a PCIe quantum-entropy card as part of a broader hardware and software stack designed to add post-quantum security to existing server infrastructure. HPE ProLiant systems are one documented target: EigenQ and contract manufacturer WNC announced a production collaboration in July 2025 covering PCIe, M.2 and 1U modules, with plans to validate PQU-enabled Gen11 ProLiant servers for public-sector and defense workloads. In June, EigenQ announced work with TD SYNNEX and AMD aimed at assessing post-quantum readiness and adding quantum-safe capabilities to AMD EPYC-based server environments.
Outside of its work with hardware vendors and channel partners, Rosas-Bustos said EigenQ has also discussed quantum risk with insurance companies, where the conversation turns quickly to corporate duty of care. In this context, duty of care refers to an organization’s responsibility to take reasonable steps to protect against foreseeable risks. That framing puts pressure on security leaders to justify decisions to defer stronger protections. Duty of care is “something that every CISO will have in their mind, that they will have to make a justification for the board,” Rosas-Bustos said.




Tell Us What You Think!
You must be logged in to post a comment.