India's Roadmap for Quantum Resiliency

A strategic timeline for building quantum resiliency across India's enterprises and Critical Information Infrastructure.

Critical Information Infrastructure
2027Preparation
2028High Priority
2029Full Resiliency
Regular Enterprises
2028Preparation
2030High Priority
2033Full Resiliency

Strategic Imperative

The "Harvest Now, Decrypt Later" (HNDL) strategy deployed by global adversaries has fundamentally altered the cybersecurity risk horizon. Data encrypted today with classical algorithms (RSA, ECC) is already vulnerable to retroactive decryption by future quantum computers.

Recognising this threat, the National Quantum Mission (NQM) has released a strategic roadmap defining a rigid timeline for India's transition to Post-Quantum Cryptography (PQC), treating it as a non-negotiable aspect of national security and economic resilience.

Key Insight for Leadership: The question is not whether to migrate, but how quickly your organisation can complete the transition. Organisations that begin now will complete migration within normal planning and budget cycles. Those that delay will face compressed timelines, higher costs, and potential compliance violations.

Overview & Key Stats

The report lays out India's first consolidated strategic roadmap for transitioning the nation's digital infrastructure to quantum-resistant cryptography. It covers all sectors: defence, power, telecom, banking, healthcare, education, and general IT.

The Task Force was constituted under the National Quantum Mission (NQM), approved by the cabinet in April 2023 with a budget of ₹6,003.65 crore (~$700 million) through 2031. The NQM operates through four Thematic Hubs at IISc Bengaluru, IIT Madras with C-DOT, IIT Bombay, and IIT Delhi, collectively involving 152 researchers from 43 institutions across 17 states.

India adopts NIST-selected algorithms (ML-KEM, ML-DSA, SLH-DSA) as the foundation for quantum-safe cryptography. While QKD research continues for specialised applications, PQC is the preferred approach for broad enterprise and government deployments due to its software-based nature and compatibility with existing infrastructure.

Key Operating Principle: The report adopts an "assume breach" mindset, recognising that adversaries are already harvesting encrypted data for future decryption. Retrospective protection is impossible. Migration must begin now.
₹6,003 CrTotal NQM Budget2023–2031
4Thematic HubsComputing, Communication, Sensing, Materials
2027–29CII TargetCritical Information Infrastructure
2028–33Enterprise TargetGovernment & Private Sector
31Quantum LabsFunded across India
4NIST StandardsFIPS 203, 204, 205, 206

Global PQC Migration Timelines

India's roadmap is benchmarked against global peers. Below is a comparative view of published PQC migration timelines by country, showing budget allocations and transition targets.

Australia

Australia

Asia-Pacific
A$1B~$702M
2026 Plan2028 Start PQC Transition2030 Finish Migration
PQC Only⚠️ QKD
View details →
Canada

Canada

North America
C$360M~$263M
2026 Prep2031 High Priority2035 Full
PQC Only
View details →
China

China

Asia-Pacific
$15B+
Active Roadmap
Hybrid (PQC + QKD)
View details →
European Union

European Union

Europe
€1B+~$1.2B
2026 Prep2030 High Priority2035 Full
PQC Only⚠️ QKD
View details →
France

France

Europe
€1.8B~$2.1B
2024 Roadmap2030 NGCC
PQC Only⚠️ QKD
View details →
Germany

Germany

Europe
€3B~$3.5B
Ongoing Plan2035+ Full
PQC Only⚠️ QKD
View details →
India

India

Asia-Pacific
₹6,000 Cr~$720M
Dec 2027 CIIDec 2028 Enterprise
Hybrid (PQC + QKD)
View details →
Israel

Israel

Middle East
₪1.25B~$340M
Active Planning
PQC Only
View details →
Japan

Japan

Asia-Pacific
¥30B~$4.3B
2025 Plan
PQC Only
View details →
Singapore

Singapore

Asia-Pacific
S$300M~$235M
Active Plan
Hybrid (PQC + QKD)
View details →
South Korea

South Korea

Asia-Pacific
₩3T~$2.0B
2035 Roadmap
Hybrid (PQC + QKD)
View details →
United Kingdom

United Kingdom

Europe
£2.5B~$3.3B
2028 Discovery2031 High Priority2035 Full
PQC Only⚠️ QKD
View details →
United States

United States

North America
$3.75B+
2030 Deprecation2033 High Priority2035 Full
PQC Only⚠️ QKD
View details →

Source: DST Task Force Report (Feb 2026) Section 4.0. The U.S. estimates $7.1 billion for federal PQC migration alone over 2025–2035.

Steps towards Quantum Resiliency

The report defines a two-track, three-milestone migration framework. Critical Information Infrastructure (CII): defence, power, telecom, ISRO, DRDO, ONGC follows an accelerated timeline. All other government and private enterprises follow a standard track.

CII Track: 2027 to 2029

Inventorisation, QRA, PilotsCII: 2027

Lay the foundation encompassing leadership, crypto inventory, Quantum Risk Analysis and prioritisation. Start migration of high-priority systems.

Governance and Strategy

  • Build Quantum Function and allocate resources
  • Unite cross-functional teams for quarterly visibility
  • Create roadmap based on assessed risks
  • Develop contingency planning for crypto eventualities

Discovery and Inventory

  • Identify and classify all cryptographic assets
  • Request CBOM disclosure from suppliers
  • Map dependencies to business systems and vendors

Quantum Risk Analysis

  • Conduct quantum risk assessments and evaluate exposure
  • Identify cryptographic components at risk
  • Apply Mosca's Theorem for prioritisation

Adopting Crypto Agility

  • Establish crypto agility as a core principle
  • Plan for repeated algorithmic transitions
  • Mandate crypto agile design for new products

PoCs for High Priority Systems

  • Start pilots in sandbox environments
  • Align vendors and partners early in migration
  • Validate costs and feasibility

Migration of High-Risk Systems

  • Post pilots, begin early transitions
  • Explore interim quantum safe solutions
  • Establish repeatable practices

Assurance and Oversight

  • Ensure third-party validation
  • Select quantum-resilience strategy (PQC or QKD)
  • Confirm transitions meet standards
Complete Resiliency for High Priority SystemsCII: 2028

Complete building quantum-resiliency for high-priority systems and products, institutionalise crypto-agility and mandate CBOM from vendors.

Governance and Strategy

  • Scale pilot learnings into funded programmes
  • Mandate "no new classical-only deployments"
  • Continuously monitor PQC and QKD developments

Supplier Enforcement

  • Require CBOMs and migration roadmaps from suppliers
  • Enforce PQC/Hybrid cryptography and crypto-agility
  • Upgrade commitments via procurements

Migration of High Priority Systems

  • Transition systems identified through risk assessment
  • Implement PKI with PQC/hybrid certificates
  • Mandate PQC-capable signatures for new software

Infrastructure Readiness

  • Upgrade HSMs, KMS, and crypto libraries
  • Benchmark performance of Quantum Resiliency solutions
  • Align infrastructure and ESG goals

Assurance and Oversight

  • Engage third-party audits for compliance
  • Implement telemetry for migration metrics
  • Develop response playbooks for updates

Workforce and Cultural Readiness

  • Embed PQC in cybersecurity and DevOps training
  • Document migration learnings and reference guides
  • Provide quantum readiness training for teams
Complete Quantum ResiliencyCII: 2029

Achieve full Quantum Resiliency, establish resiliency as the whole of enterprise approach, and sustain continuous assurance and continual agility.

Governance and Strategy

  • Make PQC/Hybrid the organisational standard
  • Periodically review algorithms as part of crypto lifecycle

Enterprise-wide Migration

  • Transition all infrastructure to PQC/Hybrid
  • Use layered controls for legacy systems
  • Run PQC-only trust chains internally
  • Shift all digital signatures to PQC-based algorithms

Supply Chain Stabilisation

  • Require all vendors to prove crypto-agility
  • Maintain clear register tracking vendor algorithms
  • Establish long-term certification and audit checks

Assurance and Oversight

  • Implement independent third-party validation
  • Confirm PQC/Hybrid protocols are correctly deployed

Continuing Momentum

  • Continuously monitor evolving standards
  • Use sandbox testbeds for new PQC primitives
  • Rapidly update through crypto-agile controls

Enterprise Track: 2028 to 2033

Inventorisation, QRA, PilotsEnterprise: 2028

Lay the foundation encompassing leadership, crypto inventory, Quantum Risk Analysis and prioritisation. Start migration of high-priority systems.

Complete Resiliency for High Priority SystemsEnterprise: 2030

Complete building quantum-resiliency for high-priority systems and products, institutionalise crypto-agility and mandate CBOM from vendors.

Complete Quantum ResiliencyEnterprise: 2033

Achieve full Quantum Resiliency, establish resiliency as the whole of enterprise approach, and sustain continuous assurance and continual agility.

Prioritisation Personas

Not all organisations face the same urgency. The Task Force defines four priority tiers based on data sensitivity, regulatory exposure, and national security relevance.

Urgent Adopters (CII)

CII operators handling data with the longest shelf life and operating systems with the slowest refresh cycles. Both HNDL and TNFL risks are highest. These organisations face existential threats from quantum-capable adversaries.

Defence, Power, Telecom, ISRO, DRDO, ONGC, Banking Core

Regular Adopters (Enterprise)

Enterprises with moderate risk profiles, shorter data sensitivity windows but large attack surfaces. Migration complexity is high due to diverse vendor ecosystems and regulatory requirements.

Government, Financial Services, Healthcare, Insurance, IT Services

Technology Vendors

Supply-side linchpin. Without PQC-ready products from this group, neither urgent nor regular adopters can migrate. CBOM submissions mandatory from FY 2027-28.

HSM vendors, Cloud providers, PKI operators, Networking equipment manufacturers

National Testing & Certification Framework

The Task Force recommends a three-tier laboratory structure for validating and certifying PQC implementations across India, ensuring that migration is not just implemented but verified.

L1 Testing

Functional correctness, standards conformance, RFC conformance (IPSec, TLS). Existing TEC/BIS labs upgraded. Operational by December 2026.

L2 Testing

Software/hardware security, vulnerability assessment, side-channel analysis. BIS, STQC, CERT-In, NCCS designated labs. Operational by December 2026.

L3 & L4 Testing

Enterprise-grade and sovereign-grade, crypto-agility, indigenous algorithm assessment. Public-Private Partnership model. Upgrade by 2028–2030.

Key Recommendations

The Task Force report outlines strategic recommendations for government, industry, and academia to accelerate India's quantum resiliency.

01

Launch PQC pilots

Launch PQC/hybrid pilots in high-priority systems (banking, finance, government)

02

Communicate report widely

Communicate report to all ministries (Railways, Finance, Power) and regulators (SEBI, RBI, CERC) for sector-specific guidance

03

Operationalise Labs

Operationalise Tier-1 and Tier-2 labs under TEC/STQC/BIS by December 2026

04

Mandate Crypto-Agile Procurement

Mandate crypto-agile, PQC-compliant procurement with compulsory BOM across all government RFPs

05

Preferential Consideration

Mandate preferential consideration of indigenously developed quantum-safe products

06

Migrate High-Priority Systems

Migrate high-priority and long-lifetime systems; validate through independent testing

07

Upgrade to Tier-3 Labs

Upgrade select labs to Tier-3 sovereign-grade PQC testing facilities

08

Develop National Testbeds

Develop PQC-ready PKI systems and national testbeds to accelerate capacity building for CISOs and DevOps professionals

Key Challenges

The report identifies key challenges in post-quantum migration and notes that the framework is advisory. Actual enforcement rests with sectoral regulators.

It recommends a coordinated, phased approach supported by vendor enablement, performance engineering, skills development, and independent assurance.

Conclusion: "Failure to act within the current planning window may result in irreversible compromise of confidential data, erosion of trust in digital governance, exposure of financial systems, and forced emergency migration under crisis conditions."

This summary is based on "Implementation of Quantum Safe Ecosystem in India: Report of the Task Force" published by the Department of Science & Technology, Government of India, February 2026. This is a neutral perspective and does not reflect official positions of any government, organisation, or entity.