The conversation is rapidly moving away from whether quantum computing will become powerful enough to break today’s public-key encryption methods, because it will. This specific point in time—known as Q-Day—looms upon the horizon. More importantly, it gives rise to a more practical question: who will be ready when it does?
In the United States, the White House solidified this urgency by issuing a National Security Memorandum in June 2026 that set a firm migration timeline for government agencies and critical infrastructure. In Malaysia, the regulatory landscape is still evolving, but the direction is clear. The development of a national PQC Migration Framework signals a commitment to quantum-safe security. This is further reinforced with the launch of the National PQC Migration Plan 2025-2030 and a sandbox programme in November 2025, making Malaysia the first nation in Southeast Asia to publish a structured national framework for the transition.
The organisations most exposed to quantum risk are those that can least afford to lose trust: financial institutions, telecommunications providers, and healthcare organisations, amongst others. And as digital banking, cloud adoption and 5G connectivity continue to expand, organisations must take proactive steps to protect critical infrastructure and sensitive data.
Business leaders and boards will need to ask the right questions now and develop a clear roadmap for the transition. The organisations that act early will be better positioned to maintain trust, manage emerging risks, and shape a more secure digital future for Malaysia.
What Q-Day means for business
Read the global article