India's Roadmap for Quantum Resiliency
A strategic timeline for building quantum resiliency across India's enterprises and Critical Information Infrastructure.
Strategic Imperative
The "Harvest Now, Decrypt Later" (HNDL) strategy deployed by global adversaries has fundamentally altered the cybersecurity risk horizon. Data encrypted today with classical algorithms (RSA, ECC) is already vulnerable to retroactive decryption by future quantum computers.
Recognising this threat, the National Quantum Mission (NQM) has released a strategic roadmap defining a rigid timeline for India's transition to Post-Quantum Cryptography (PQC), treating it as a non-negotiable aspect of national security and economic resilience.
Overview & Key Stats
The report lays out India's first consolidated strategic roadmap for transitioning the nation's digital infrastructure to quantum-resistant cryptography. It covers all sectors: defence, power, telecom, banking, healthcare, education, and general IT.
The Task Force was constituted under the National Quantum Mission (NQM), approved by the cabinet in April 2023 with a budget of ₹6,003.65 crore (~$700 million) through 2031. The NQM operates through four Thematic Hubs at IISc Bengaluru, IIT Madras with C-DOT, IIT Bombay, and IIT Delhi, collectively involving 152 researchers from 43 institutions across 17 states.
India adopts NIST-selected algorithms (ML-KEM, ML-DSA, SLH-DSA) as the foundation for quantum-safe cryptography. While QKD research continues for specialised applications, PQC is the preferred approach for broad enterprise and government deployments due to its software-based nature and compatibility with existing infrastructure.
Global PQC Migration Timelines
India's roadmap is benchmarked against global peers. Below is a comparative view of published PQC migration timelines by country, showing budget allocations and transition targets.
Australia
Asia-PacificSource: DST Task Force Report (Feb 2026) Section 4.0. The U.S. estimates $7.1 billion for federal PQC migration alone over 2025–2035.
Steps towards Quantum Resiliency
The report defines a two-track, three-milestone migration framework. Critical Information Infrastructure (CII): defence, power, telecom, ISRO, DRDO, ONGC follows an accelerated timeline. All other government and private enterprises follow a standard track.
CII Track: 2027 to 2029
Lay the foundation encompassing leadership, crypto inventory, Quantum Risk Analysis and prioritisation. Start migration of high-priority systems.
Governance and Strategy
- Build Quantum Function and allocate resources
- Unite cross-functional teams for quarterly visibility
- Create roadmap based on assessed risks
- Develop contingency planning for crypto eventualities
Discovery and Inventory
- Identify and classify all cryptographic assets
- Request CBOM disclosure from suppliers
- Map dependencies to business systems and vendors
Quantum Risk Analysis
- Conduct quantum risk assessments and evaluate exposure
- Identify cryptographic components at risk
- Apply Mosca's Theorem for prioritisation
Adopting Crypto Agility
- Establish crypto agility as a core principle
- Plan for repeated algorithmic transitions
- Mandate crypto agile design for new products
PoCs for High Priority Systems
- Start pilots in sandbox environments
- Align vendors and partners early in migration
- Validate costs and feasibility
Migration of High-Risk Systems
- Post pilots, begin early transitions
- Explore interim quantum safe solutions
- Establish repeatable practices
Assurance and Oversight
- Ensure third-party validation
- Select quantum-resilience strategy (PQC or QKD)
- Confirm transitions meet standards
Complete building quantum-resiliency for high-priority systems and products, institutionalise crypto-agility and mandate CBOM from vendors.
Governance and Strategy
- Scale pilot learnings into funded programmes
- Mandate "no new classical-only deployments"
- Continuously monitor PQC and QKD developments
Supplier Enforcement
- Require CBOMs and migration roadmaps from suppliers
- Enforce PQC/Hybrid cryptography and crypto-agility
- Upgrade commitments via procurements
Migration of High Priority Systems
- Transition systems identified through risk assessment
- Implement PKI with PQC/hybrid certificates
- Mandate PQC-capable signatures for new software
Infrastructure Readiness
- Upgrade HSMs, KMS, and crypto libraries
- Benchmark performance of Quantum Resiliency solutions
- Align infrastructure and ESG goals
Assurance and Oversight
- Engage third-party audits for compliance
- Implement telemetry for migration metrics
- Develop response playbooks for updates
Workforce and Cultural Readiness
- Embed PQC in cybersecurity and DevOps training
- Document migration learnings and reference guides
- Provide quantum readiness training for teams
Achieve full Quantum Resiliency, establish resiliency as the whole of enterprise approach, and sustain continuous assurance and continual agility.
Governance and Strategy
- Make PQC/Hybrid the organisational standard
- Periodically review algorithms as part of crypto lifecycle
Enterprise-wide Migration
- Transition all infrastructure to PQC/Hybrid
- Use layered controls for legacy systems
- Run PQC-only trust chains internally
- Shift all digital signatures to PQC-based algorithms
Supply Chain Stabilisation
- Require all vendors to prove crypto-agility
- Maintain clear register tracking vendor algorithms
- Establish long-term certification and audit checks
Assurance and Oversight
- Implement independent third-party validation
- Confirm PQC/Hybrid protocols are correctly deployed
Continuing Momentum
- Continuously monitor evolving standards
- Use sandbox testbeds for new PQC primitives
- Rapidly update through crypto-agile controls
Enterprise Track: 2028 to 2033
Lay the foundation encompassing leadership, crypto inventory, Quantum Risk Analysis and prioritisation. Start migration of high-priority systems.
Complete building quantum-resiliency for high-priority systems and products, institutionalise crypto-agility and mandate CBOM from vendors.
Achieve full Quantum Resiliency, establish resiliency as the whole of enterprise approach, and sustain continuous assurance and continual agility.
Prioritisation Personas
Not all organisations face the same urgency. The Task Force defines four priority tiers based on data sensitivity, regulatory exposure, and national security relevance.
Urgent Adopters (CII)
CII operators handling data with the longest shelf life and operating systems with the slowest refresh cycles. Both HNDL and TNFL risks are highest. These organisations face existential threats from quantum-capable adversaries.
Defence, Power, Telecom, ISRO, DRDO, ONGC, Banking CoreRegular Adopters (Enterprise)
Enterprises with moderate risk profiles, shorter data sensitivity windows but large attack surfaces. Migration complexity is high due to diverse vendor ecosystems and regulatory requirements.
Government, Financial Services, Healthcare, Insurance, IT ServicesTechnology Vendors
Supply-side linchpin. Without PQC-ready products from this group, neither urgent nor regular adopters can migrate. CBOM submissions mandatory from FY 2027-28.
HSM vendors, Cloud providers, PKI operators, Networking equipment manufacturersNational Testing & Certification Framework
The Task Force recommends a three-tier laboratory structure for validating and certifying PQC implementations across India, ensuring that migration is not just implemented but verified.
L1 Testing
Functional correctness, standards conformance, RFC conformance (IPSec, TLS). Existing TEC/BIS labs upgraded. Operational by December 2026.
L2 Testing
Software/hardware security, vulnerability assessment, side-channel analysis. BIS, STQC, CERT-In, NCCS designated labs. Operational by December 2026.
L3 & L4 Testing
Enterprise-grade and sovereign-grade, crypto-agility, indigenous algorithm assessment. Public-Private Partnership model. Upgrade by 2028–2030.
Key Recommendations
The Task Force report outlines strategic recommendations for government, industry, and academia to accelerate India's quantum resiliency.
Launch PQC pilots
Launch PQC/hybrid pilots in high-priority systems (banking, finance, government)
Communicate report widely
Communicate report to all ministries (Railways, Finance, Power) and regulators (SEBI, RBI, CERC) for sector-specific guidance
Operationalise Labs
Operationalise Tier-1 and Tier-2 labs under TEC/STQC/BIS by December 2026
Mandate Crypto-Agile Procurement
Mandate crypto-agile, PQC-compliant procurement with compulsory BOM across all government RFPs
Preferential Consideration
Mandate preferential consideration of indigenously developed quantum-safe products
Migrate High-Priority Systems
Migrate high-priority and long-lifetime systems; validate through independent testing
Upgrade to Tier-3 Labs
Upgrade select labs to Tier-3 sovereign-grade PQC testing facilities
Develop National Testbeds
Develop PQC-ready PKI systems and national testbeds to accelerate capacity building for CISOs and DevOps professionals
Key Challenges
The report identifies key challenges in post-quantum migration and notes that the framework is advisory. Actual enforcement rests with sectoral regulators.
It recommends a coordinated, phased approach supported by vendor enablement, performance engineering, skills development, and independent assurance.
This summary is based on "Implementation of Quantum Safe Ecosystem in India: Report of the Task Force" published by the Department of Science & Technology, Government of India, February 2026. This is a neutral perspective and does not reflect official positions of any government, organisation, or entity.