Opinion: Australian organisations have four months left to produce a plan for their transition to post-quantum cryptography.
That is the first checkpoint in the Australian Signals Directorate’s published timeline: a refined transition plan by 2026, migration of critical systems underway by 2028, and traditional public-key cryptography to be retired by 2030.
Sadly, most of the defence supply chain will miss it. Global research published in July found that 87 per cent of organisations are planning, testing or implementing PQC, but only 7 per cent have deployed it across most of their digital certificates.
The problem with being stuck in the “planning phase” is that adversaries do not need a working quantum computer today to create a problem.
They can collect encrypted data now, store it, and decrypt it later. For defence, intelligence and critical infrastructure, information often stays sensitive for decades, so traffic intercepted this year is still a live exposure in 2040.
Meanwhile, defence networks contain long-lived equipment, complex dependencies and systems that must keep operating while their cryptography is replaced. Discovering where encryption is actually used, testing new algorithms, managing interoperability with allies and updating hardware across an entire estate cannot be compressed into the final months before a deadline.
Command instructions, intelligence feeds, targeting information, sensor data, logistics records and the telemetry exchanged by uncrewed systems all need to move across our networks for modern defence to function. If those flows are intercepted, manipulated or disrupted, a technologically advanced force can lose its advantage very quickly.
An asset may remain physically intact while its usefulness is destroyed because the data it depends on can no longer be trusted.
That is particularly important as the Australian Defence Force becomes more connected and more reliant on autonomous and remotely operated systems.
An uncrewed aircraft or vessel may transmit high-volume video, sonar and positional data from a contested environment. It may also be lost, captured or tampered with. The communications link, the keys protecting it and the ability to erase sensitive material can therefore matter as much as the vehicle itself.
Australia’s first Virginia Class submarine is scheduled to transfer in 2032, with the first Australian-built SSN-AUKUS boats to follow from the early 2040s, and those hulls will still be in service well into the 2060s.
Any cryptography specified for them today will need to be replaced several times before they leave the fleet. Designing for that replacement is an operational requirement, not an upgrade path to be worked out later.
Encryption and control
Sovereign encryption does not mean Australia should isolate itself from its allies or reject international technology. The real test is control.
Who holds the cryptographic keys? Who can inspect, modify and update the technology? Can it be maintained in Australia if international supply chains are disrupted?
Can the nation continue operating if a foreign vendor changes its priorities, a licensing arrangement shifts or an overseas government restricts access?
That last question is not hypothetical. Reuters reported in July 2025 that Starlink coverage over the Beryslav area was deactivated during Ukraine’s 2022 Kherson counteroffensive, leaving front-line units without connectivity, disabling drones and disrupting artillery coordination.
SpaceX has not confirmed the account and Musk has denied ordering shutdowns. The point does not rest on one report or one company.
A commercial operator sitting outside the chain of command, and outside Australian jurisdiction, was in a position to make a decision with immediate consequences in the field. More than any regulation, it is this reality that is driving demand for sovereign encryption solutions overseas.
Defence organisations therefore need independent assurance that encryption has been rigorously evaluated and can interoperate with trusted partners. Recognised certification and allied accreditation help establish that baseline.
Yet certification alone is not enough for something this important. Australia also needs local expertise, access to design knowledge and the capacity to sustain and adapt critical systems through their operational life. That capability also needs to be internationally competitive.
Final thoughts
Senetas’ recent recognition as the 2026 Governor of Victoria Export Awards winner for digital and smart technologies is one indication that Australian-developed cyber security capability can compete internationally. None of that comes for free.
Sovereign capability usually costs more per unit than buying at global scale. Locally developed technology can be harder to interoperate with allied systems if it is not built to the same certifications and standards.
There are capabilities where buying from a trusted ally is plainly the right decision. The question is not whether Australia should ever buy from its allies. It is whether the country knows which capabilities it cannot afford to lose control of and has decided those cases deliberately rather than by default.
Nobody is suggesting we deliberately lose control of encryption, it is a very important foundation of our security. But we can get the same result over time just from a general lack of expertise.
For anyone assessing capability on the procurement side, “quantum-safe” on a datasheet is not the assurance it appears to be. Three technical failure modes are worth testing for specifically – hybrid configurations, lack of upgrade path and expiring parameters.
The durable requirement underneath all three is cryptographic agility: the ability to change algorithms and keys in the field as standards develop, vulnerabilities emerge and threat assessments evolve. No one can guarantee that today’s preferred approach will remain suitable for the full life of a defence platform.
Australia cannot claim sovereign control over a defence capability if it does not control the trust on which that capability depends. Encryption sits at the centre of that trust. There are difficult decisions ahead, and the first checkpoint is four months away.
Andrew Wilson is the chief executive officer of Senetas.
Want to see more stories from trusted news sources?
Make Defence Connect a preferred news source on Google.
Click here to add Defence Connect as a preferred news source.