In This Article
- Executive Summary
- Why Pharma Cannot Wait for Q-Day
- The NIST Standards and the CNSA 2.0 Timeline
- GxP System Implications: Validation, Change Control, and Data Integrity
- CMO, CDMO, and Regulatory Exchange Encryption
- Legacy Devices, Instruments, and Embedded Systems
- A PQC Readiness Assessment for Pharma
- A Five-Phase Migration Roadmap
- The Vendor Question Checklist
- Conclusion
- References & Sources
Executive Summary
The cryptography protecting today’s clinical trial dossiers, manufacturing records, submissions, and adverse event data was designed for a world in which factoring large numbers was hard. Quantum computing is on a path to remove that assumption. Cryptographically relevant quantum computers are broadly forecast to arrive somewhere between 2030 and 2035, and adversaries are already collecting encrypted pharma data under a “harvest now, decrypt later” strategy that turns the future threat into a present-day risk.1 2
For life sciences leaders, the migration to post-quantum cryptography (PQC) is not just another cybersecurity project. It is a validation project, a supplier project, an instrument-refresh project, and a submissions project at the same time. NIST has finalized three standards — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) — and the NSA’s CNSA 2.0 timeline places new-deployment expectations at January 2027 with full transition by 2035.3 4 The realistic enterprise timeline for migration is 42 to 54 months, which means pharma organizations that have not started an inventory in 2026 are already late.
This article lays out why the twenty-year data retention profile of clinical and manufacturing data makes pharma uniquely exposed, what the NIST standards and CNSA 2.0 mandates actually require, how PQC intersects with GxP validation and CMO/CDMO data exchange, and how to build a defensible readiness assessment, migration roadmap, and vendor-question checklist. The goal is to give quality, IT, and regulatory leaders a shared vocabulary for a program that will run through the end of this decade.
Why Pharma Cannot Wait for Q-Day
The phrase “post-quantum cryptography” invites a comforting mental shortcut: this is a future problem, and future problems can be scheduled around near-term priorities. For most industries that shortcut is defensible. For pharmaceutical and biotech organizations, it is not.
Two features of pharma data make the threat immediate rather than eventual. The first is retention. FDA regulations under 21 CFR 312.62(c) require investigator retention of clinical study records for at least two years after marketing application approval, and ICH GCP effectively extends that to a minimum of fifteen years in many cases. Sponsors routinely contract for twenty-year retention on pivotal trials, and manufacturing batch records and quality events sit on similar horizons.5 Any encrypted material that leaves a pharma network today is expected to remain confidential well past 2040.
The second feature is adversarial. Nation-state and financially motivated groups have targeted pharmaceutical intellectual property for more than a decade, from MenuPass and APT41 campaigns aimed at drug research and clinical trial data to coordinated attacks on COVID-19 vaccine cold chains and infrastructure.6 These actors have the patience and storage capacity to run “harvest now, decrypt later” campaigns: intercept encrypted transmissions or exfiltrate encrypted archives today, park them, and decrypt them once a cryptographically relevant quantum computer becomes available.7
The math is uncomfortable. A clinical dossier transmitted in 2026, protected by RSA-2048 or ECC over TLS, will still be under retention obligation when the expert consensus predicts those algorithms will be breakable. The intellectual property in a preclinical filing today may still be commercially relevant when a determined adversary can decrypt what they harvested a decade earlier. The World Economic Forum framed this bluntly in September 2025: for pharma and life sciences, “a decade-long clinical trial overlaps with projected CRQC timelines, putting sensitive results within reach of adversaries.”1
The SD read: The unit of analysis for pharma is not “when will Q-Day arrive” but “which data sets are still under retention when it arrives, and how do we protect those in transit and at rest before then.” Everything harvested before migration completes remains exposed forever.
The NIST Standards and the CNSA 2.0 Timeline
The good news is that the algorithms are no longer a moving target. After an eight-year evaluation process that began in 2016, NIST finalized three post-quantum cryptography standards in August 2024. These give pharma organizations concrete targets to migrate toward rather than theoretical constructs to argue about.3
The three finalized NIST standards
ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism)
Derived from CRYSTALS-Kyber. The primary standard for establishing shared secrets over untrusted channels. Replaces RSA and ECDH key exchange in TLS and VPN handshakes. Rests on the Module Learning With Errors problem.
ML-DSA (Module-Lattice-Based Digital Signature Algorithm)
Derived from CRYSTALS-Dilithium. The primary digital-signature standard, intended to replace RSA and ECDSA signatures for code signing, document signing, and certificate signing. Also lattice-based.
SLH-DSA (Stateless Hash-Based Digital Signature Algorithm)
Derived from SPHINCS+. A conservative backup signature scheme built entirely on hash functions, with no structural mathematical assumptions beyond hash security. Larger signatures, but a hedge against any future lattice cryptanalysis breakthrough.
Ongoing standardization
NIST is standardizing HQC (a code-based KEM) as a diversity hedge for ML-KEM, and continuing evaluation of additional signature schemes. The core three are frozen; expect the portfolio to grow, not shrink.
The engineering consequences are practical. ML-KEM-768 transmits roughly 1,184 bytes of public key and 1,088 bytes of ciphertext, and ML-DSA-65 signatures are about 3,309 bytes compared to 64 bytes for ECDSA P-256. Certificate sizes grow from roughly 1 KB to 4-5 KB, and TLS handshakes carry an additional ~2.27 KB of overhead compared to X25519. The CPU cost is negligible in most cases, but any protocol, appliance, or embedded system with tight bandwidth or record-size assumptions needs to be tested.9
CNSA 2.0: the federal timeline that shapes everything else
The NSA’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) is not directly binding on pharmaceutical companies, but its schedule shapes the federal procurement, cloud services, and TLS ecosystem that pharma depends on. The key milestones:4 10
| Date | CNSA 2.0 Milestone | Pharma Relevance |
|---|---|---|
| January 2027 | New deployments expected to be CNSA 2.0-compliant. Exclusive-use requirement for software and firmware signing. | Any new instrument, cloud service, or SaaS validated after this point will be marketed as PQC-capable. Contracts should require it. |
| By 2030 | Networking equipment must move to exclusive use of CNSA 2.0. Legacy equipment unable to support it must be retired. | Pharma VPN concentrators, load balancers, and CMO/CDMO exchange gateways face refresh pressure. Same window matches CRQC forecasts. |
| By 2031 | CNSA 2.0 becomes mandatory across covered categories unless explicitly excepted. | Federal customers of pharma (VA, DoD, BARDA contracts, HHS) will require PQC-capable supplier ecosystems. |
| By 2033 | Operating systems, custom applications, and cloud services reach exclusive use of CNSA 2.0. | Cloud-based clinical, safety, and quality platforms (Veeva, Benchling, Salesforce Life Sciences) will complete PQC migration in this window. |
| By 2035 | Full quantum resistance required across all National Security Systems (per NSM-10). | The de facto end state that every long-lived pharma data asset must reach. |
Executive Order 14144, signed in January 2025 and substantially amended by EO 14306 in June 2025, preserved the PQC urgency of the earlier framework while streamlining agency oversight to NSA and OMB. CISA published its list of quantum-safe product categories on January 23, 2026, classifying commercial technology into “Widely Available” and “Transitioning” tiers.11 The signal to industry is clear: PQC is not experimental, and procurement conversations from 2027 forward should assume PQC capability as a baseline expectation, not an optional feature.
What this means for pharma: Pharma is not a federal agency, but the pharma technology stack — cloud platforms, VPN appliances, HSMs, certificate authorities, code-signing services — is shared with federal customers. When those vendors migrate on the CNSA 2.0 schedule, pharma inherits both the capability and the change-control burden. The last companies to hold vendors accountable to these dates will pay for the migration twice: once for the vendor’s PQC upgrade, and once again in emergency re-validation.
GxP System Implications: Validation, Change Control, and Data Integrity
Every cryptographic algorithm change touches a GxP validated system somewhere in the pharma stack. TLS certificates protect LIMS-to-instrument connections. Digital signatures underpin 21 CFR Part 11 electronic records. HSM-backed keys sign batch release records. Cloud-provider TLS terminates on data-integrity-critical ingestion paths. The migration to PQC is therefore, unavoidably, a computer system validation event — but a diffuse one that traverses hundreds of systems rather than one big-bang project.
The 21 CFR Part 11 dimension
21 CFR Part 11 sets the criteria under which electronic records and electronic signatures are considered equivalent to paper. The regulation itself does not mandate any specific cryptographic algorithm; what it requires is that systems demonstrably preserve authenticity, integrity, and non-repudiation across the record lifecycle.12 Digital signatures based on RSA or ECDSA satisfy the intent today. Once quantum computers can forge those signatures, the same systems will no longer satisfy the same intent — with respect to any record that must remain legally defensible after Q-Day.
The uncomfortable question, then, is not whether Part 11 requires PQC (it does not, explicitly) but whether Part 11 is satisfiable indefinitely by pre-quantum signatures on records that must survive into a post-quantum world. Regulators have not answered this in writing yet. Prudent quality organizations should assume the answer is no.
GAMP 5 change control
Under GAMP 5, changes to a validated system are assessed, approved, tested, and documented before implementation. GAMP 5 explicitly favors ongoing control based on risk over calendar-based revalidation, so the modern expectation is not to revalidate every system on a schedule but to reassess risk whenever functionality, configuration, data flow, or supplier responsibility changes.13
A cryptographic algorithm change is, in almost all cases, a supplier or configuration change. Whether it triggers full revalidation depends on where the change lands:
- TLS versions and cipher suites: generally infrastructure changes handled through the qualification of the infrastructure layer. A vendor moving from ECDHE-only to hybrid ML-KEM handshakes is normally not a Part 11 revalidation event.
- Digital signature algorithm in an e-signature workflow: higher risk. If the signature algorithm in a Part 11 signing chain changes, the audit trail, key-management, and non-repudiation controls all warrant reassessment.
- Code-signing chain on device firmware: requires coordinated updates across engineering, quality, and cybersecurity — and, for connected medical devices, alignment with FDA premarket cybersecurity guidance.14
- HSM and KMS root-of-trust migration: touches every downstream key, certificate, and encrypted archive. Effectively a program-level change.
Watch out: The temptation to defer PQC migration on GxP-validated systems until “the vendor forces us” is a trap. When a vendor pushes a major PQC update onto its schedule, the quality organization loses the ability to sequence the change control against release windows and audit calendars. Programs that plan the migration proactively can spread work across quiet quarters. Programs that react will collide it with their busiest release windows.
Long-term data integrity: signatures on archived records
There is a subtler GxP problem than “how do we validate the new algorithm.” It is: how do we preserve the evidentiary value of records that were signed with pre-quantum algorithms, once those algorithms are broken? A batch release record signed with RSA-2048 in 2027 will still be under retention in 2040, when RSA-2048 may be forgeable. The signature will not automatically become invalid, but its evidentiary weight in a regulatory inspection or product-liability dispute is another matter.
The pragmatic answer, borrowed from long-term archival practice in other regulated industries, is to consider timestamped re-signing of critical archived records as part of a PQC transition. The originating signature remains as historical fact; a co-signature, using a PQC algorithm and a trusted timestamp, attests that the record existed and was accepted before Q-Day. This is not required by any current regulation, but it may be prudent for records with the highest evidentiary stakes — pivotal trial datasets, batch release records for approved products, safety database submissions.
CMO, CDMO, and Regulatory Exchange Encryption
Modern pharma is a network of encrypted exchanges. Sponsors send master batch records to CMOs. CDMOs return in-process and release data. CROs return case report forms, adverse event data, and imaging. Regulatory affairs teams push submissions through the FDA Electronic Submissions Gateway and the EMA CESSP portal. Almost none of this data goes over the open internet without TLS; almost all of it involves digital certificates from either commercial or FDA-issued certificate authorities.
According to industry reporting, 28% of life science organizations use five or more separate systems to exchange sensitive data with partners, and 68% of data breaches involve third-party vulnerabilities.15 Every one of those exchange points is a candidate for “harvest now, decrypt later” attack — often outside the sponsor’s direct control.
Where the exchange encryption lives
MPI/BOM exchange, batch records, deviations
Typically SFTP or portal-based, terminated on either party’s edge appliances. Certificates often issued by commercial CAs on rotation schedules of one to three years. Migration lever: certificate renewal windows through 2028–2030.
EDC, IWRS, imaging, safety database exchange
Vendor-hosted platforms (Medidata, Veeva, Oracle Health Sciences, IQVIA) terminate TLS on cloud infrastructure. Sponsors have visibility but limited direct control — pressure applies through master service agreements and RFP requirements.
ESG NextGen, CESSP, eCTD submissions
Regulator-defined protocols. FDA ESG NextGen currently accepts 1024/2048/3072-bit key lengths on AS2 gateway submissions. When FDA and EMA specify PQC-capable submission channels, sponsors will follow — but the schedule is driven by the regulators, not the sponsor.16
Co-development and license agreements
Often the least mature exchange channels. Data rooms, shared drives, and ad-hoc encrypted email dominate. This is where “harvest now, decrypt later” campaigns find the easiest targets, because encryption practices are inconsistent between two organizations that never fully integrated.
The contract layer: PQC obligations in supplier agreements
The most practical near-term lever is contractual. New and renewed master service agreements with CMOs, CDMOs, CROs, and IT vendors from 2026 forward should include specific PQC obligations: a commitment to inventory cryptographic assets, a migration roadmap aligned with CNSA 2.0 milestones, and audit rights to verify progress. This is not a technical control — it is a governance control. And it costs almost nothing to add in negotiation windows that are already open.
An underused governance move: When a CMO or CDMO contract is up for renewal in the next 18 months, add a schedule that requires a Cryptographic Bill of Materials (CBOM) for any system that handles the sponsor’s GxP data, plus a documented PQC migration plan by January 2028. Suppliers that push back should be scored accordingly in the RFP matrix. Suppliers that embrace it should be treated as strategic partners.
Legacy Devices, Instruments, and Embedded Systems
The hardest layer of the pharma cryptographic stack is not the cloud or the network — it is the equipment on the plant floor and in the lab. HPLCs, mass spectrometers, autoclaves, filling lines, environmental monitoring systems, PLCs, historian databases, medical-device manufacturing equipment, and QC instruments frequently run embedded operating systems and cryptographic libraries that were validated once, ten years ago, and have not been meaningfully touched since.
These systems share a set of properties that make PQC migration genuinely hard:
- Long operational lifespans. Many pharma manufacturing systems have 15-20 year lifespans. A device commissioned in 2018 may still be in production in 2033, straddling the entire CRQC risk window.17
- Constrained cryptographic environments. Embedded chips often lack the RAM or flash to accommodate ML-DSA signature verification code and expanded certificate chains. Vendors may need firmware updates, or in some cases hardware replacement.
- Validation lock-in. The system is validated as a unit. Swapping out a TLS stack triggers a formal change control, not a routine patch — and change control on a validated instrument is not a two-week exercise.
- Vendor lifecycle asymmetry. Some vendors will treat PQC as a paid feature upgrade. Others will treat it as a reason to end-of-life older instruments. Sponsors need to know which is which before their compliance windows close.
The connected medical device sub-problem: For sponsors that also manufacture connected medical devices (drug-device combinations, digital therapeutics, connected inhalers, injection devices), FDA’s premarket cybersecurity guidance now requires reasonable assurance of protection throughout the device lifecycle. A submission after 2027 that relies on deprecated cryptographic algorithms is at real risk of a refuse-to-accept response.14
The hybrid transition pattern
The consensus deployment pattern for enterprise PQC in 2026 is hybrid: run classical and post-quantum algorithms in parallel, so a session is protected by both ECDH and ML-KEM simultaneously. An attacker needs to break both to compromise the connection.18 Hybrid deployment gives three things at once: safety if either algorithm has interoperability trouble, backward compatibility with legacy clients, and telemetry on handshake size, performance impact, and failure modes before pure PQC rollout.
For validated instruments and legacy systems that cannot immediately support pure PQC, the hybrid approach is the safest transition. It buys years of migration runway without leaving harvested traffic decryptable. It also lets quality organizations spread the validation work across multiple change-control cycles rather than a single high-risk cutover.
A PQC Readiness Assessment for Pharma
The most useful thing a pharma organization can do in the next twelve months is not to pick an algorithm or a vendor. It is to know where its cryptography actually lives. Most enterprises cannot answer that question because cryptography was implemented ad hoc across decades of system development and acquisitions.19 A PQC readiness assessment is fundamentally an inventory exercise, layered over a risk exercise.
Six domains to score
| Domain | Key Questions | Signal of Readiness |
|---|---|---|
| Cryptographic inventory (CBOM) | Do we have a machine-readable inventory of every algorithm, certificate, key, and protocol across our estate — including cloud, on-prem, embedded, and third-party? | A CycloneDX-format CBOM covering at least 80% of production systems, refreshed quarterly.20 |
| Data classification by lifetime | Have we tagged our data assets by retention obligation and confidentiality half-life? Do we know which data sets are still sensitive in 2040? | Data taxonomy that segments by retention year, cross-referenced against system-of-record inventory. |
| PKI and root-of-trust posture | Are our certificate authorities and HSMs on a supported roadmap to PQC? Are our code-signing chains upgradable? | Written vendor commitment on PQC support and validated firmware/software paths. |
| Application and API layer | Are our internal and external APIs, service meshes, and message queues built with cryptographic agility, or are algorithms hardcoded? | Architecture standard requiring externalized crypto configuration for new builds; documented remediation backlog for legacy. |
| Third-party and supply chain | Do our top 20 CMO/CDMO/CRO/SaaS suppliers have PQC roadmaps we can review, and contractual language that binds them to a schedule? | Signed supplier questionnaires; PQC clauses in all new or renewed master agreements from 2026 forward. |
| Governance and program | Is there a named executive owner, cross-functional steering committee, and budget line for PQC migration through 2033? | PQC program on the enterprise risk register; quarterly reporting to the audit committee. |
Organizations should score each domain on a simple maturity scale (unaware, aware, planned, in-progress, operational). The purpose is not to produce a beautiful heatmap. It is to force honest conversation with the CFO, CIO, CISO, chief quality officer, and general counsel about the fact that most of the map is currently blank.
What good looks like in mid-2026: Cryptographic inventory in-progress, covering high-value data flows (clinical, safety, submissions, manufacturing). Data classification complete for regulated records. PKI/HSM vendor roadmaps confirmed in writing. New master service agreements include PQC language. Named executive owner and quarterly steering. Budget commitment for 2027 discovery and pilot work. Board briefed once, in plain English, before the audit or ERM committee.
A Five-Phase Migration Roadmap
The migration itself is a multi-year, multi-workstream program. Framing it as five sequential phases — rather than eighty parallel projects — gives leadership a chance to sequence spend and validation load. The phases are drawn from consensus industry practice and adapted for the regulated pharma context.21
Discover and inventory (12–18 months)
Build a CBOM across cloud, on-prem, embedded, and third-party systems. Use SBOM-aware static analysis, TLS inspection, PKI auditing, and configuration scanning. Prioritize systems that handle data with retention obligations past 2035. This phase produces the “map” — everything after it is impossible without it.
Risk-score and prioritize (6–12 months, overlapping)
For each cryptographic asset, score by data sensitivity, retention obligation, exposure surface, and difficulty of migration. Prioritize the intersection of high sensitivity, long retention, and network exposure — this is where harvest-now-decrypt-later attacks pay off best. Legacy instruments with expiring vendor support belong near the top.
Governance, standards, and vendor pressure (concurrent)
Establish an internal PQC standard: which NIST algorithms are approved, which hybrid modes are acceptable, and which signature schemes are used for what. Update RFP templates, master service agreements, and vendor onboarding. Add PQC clauses to renewals. Publish the standard so architecture reviews can enforce it.
Pilot and hybrid rollout (2027–2029)
Deploy hybrid PQC on high-value data channels first: submissions gateways, sponsor-to-partner exchanges, code-signing chains for critical firmware, HSM-backed root of trust. Measure handshake sizes, latency, and failure modes. Feed results into the internal standard. Coordinate all validated-system changes through GAMP 5 change control, sequenced against release calendars.
Broad migration and legacy retirement (2029–2033)
Convert general-purpose infrastructure to hybrid or pure PQC. Retire legacy instruments that cannot be upgraded. Re-sign or timestamp long-lived archived records with PQC signatures where evidentiary risk is highest. By 2033, the enterprise operates on PQC by default; classical algorithms exist only as documented, risk-accepted exceptions.
Program economics
Realistic enterprise timelines from industry sources suggest cryptographic discovery and inventory across global infrastructure will take two to three years; risk assessment and prioritization roughly a year; governance six to twelve months; infrastructure upgrades phased over five to seven years; and application migration spanning eight to ten years.19 That range is defensible for a large pharma. For a mid-sized biotech with a focused system footprint, the top-end numbers compress meaningfully — but the discovery phase does not, because the vendor ecosystem is the same.
Where the money goes: The largest cost in most PQC programs is not new licenses or algorithms. It is people and time — cryptography-fluent architects to run discovery, quality and validation staff to process change controls, and program management to coordinate across dozens of workstreams and hundreds of vendors. Budget accordingly.
The Vendor Question Checklist
Most pharma organizations will migrate to PQC through their vendors, not around them. That makes the RFP and vendor-review process the single highest-leverage governance intervention available today. The questions below can be added to any technology, cloud, or instrument RFP or annual vendor review starting immediately.
For all vendors handling GxP or regulated data
- What is your public position on NIST PQC standards (FIPS 203, 204, 205), and what is your roadmap for adopting them in the products or services we consume from you?
- Do you publish or share a Cryptographic Bill of Materials (CBOM) for the components of your product or service that handle our data? If not, when will you?
- Have you inventoried your reliance on RSA, ECC, DH, and ECDH across your product architecture, including certificate authorities, HSMs, TLS termination, code signing, and internal service-to-service communication?
- Which of your products or services currently support hybrid classical/PQC TLS handshakes (for example, X25519 + ML-KEM), and on what schedule will the remaining products?
- For digital signatures (code signing, document signing, JWT/SAML signing, e-signature workflows): what is your ML-DSA or SLH-DSA roadmap?
- How is your PKI (internal CAs, intermediate CAs, code-signing CAs) preparing for PQC? Have you tested certificate chains with ML-DSA-signed intermediates?
- What is your policy on cryptographic agility — the ability to swap algorithms without redeploying application code — and can you demonstrate it in your architecture?
- How will you handle certificates and keys that were issued under classical algorithms during our contract term? What is the plan for re-issuance?
- What is your position on CNSA 2.0 compliance, and do you commit contractually to alignment with its milestones for the categories that apply to your product?
- For our GxP-validated deployments, how will you sequence PQC changes with our change control and release calendars, and what advance notice will you commit to?
Additional questions for instrument and connected-device vendors
- What is the memory and processing headroom in the current hardware to accommodate ML-KEM/ML-DSA overhead? Will firmware updates suffice, or is hardware replacement required?
- What is your PQC upgrade path for instruments currently deployed? Is it a covered firmware update, a paid feature, or an end-of-life event?
- For long-lived embedded devices (10+ year lifespans), what is your commitment to PQC support through the end of expected operational life?
- How does your device handle firmware code signing today, and what is the migration plan to ML-DSA or SLH-DSA signing?
Additional questions for cloud and SaaS providers
- Does your public-facing TLS support hybrid PQC key exchange today, and if so, what percentage of client traffic actually negotiates it?
- What is the roadmap for internal service-to-service communication, storage encryption at rest, and backup encryption?
- Do your logs and observability tooling capture cryptographic agility signals (which algorithms are negotiated, failure rates)?
- Where you rely on third-party cryptographic libraries and HSMs, what is your subcontractor migration schedule, and how is it audited?
The SD perspective: A vendor’s answers to these questions do not need to be perfect in 2026. They need to be specific and dated. A vendor with a credible plan through 2028 is a better long-term partner than a vendor who insists PQC is not relevant to their category. The willingness to answer the questions in writing, on a call, or as an attachment to a contract is itself a data point.
Conclusion
Post-quantum cryptography is arriving on a schedule that is knowable and a threat vector that is already active. For pharma and biotech leaders, the operational reality is that the twenty-year retention profile of clinical, manufacturing, and safety data collapses the future threat into a present one: material transmitted today, protected by classical algorithms, is expected to remain confidential well past the window in which those algorithms are expected to be broken. Adversaries are aware of this, and they are collecting.
The response is not exotic. It is inventory, governance, vendor pressure, and disciplined multi-year sequencing against a set of NIST standards that are finalized and a CNSA 2.0 timeline that shapes the whole commercial ecosystem. Organizations that begin their cryptographic inventory and readiness assessment in 2026 will finish their migration on time. Organizations that wait for a regulator or a headline will finish it under duress, at higher cost, and with material amounts of legacy data left exposed.
Sakara Digital works with pharma and biotech organizations building the quality, IT, and regulatory foundations for AI-enabled and quantum-safe operations. If you are exploring how a PQC readiness assessment should be sequenced against your GxP validation calendar, your CMO/CDMO contract renewals, and your submissions roadmap — and you want an independent perspective on where to start — we are happy to have that conversation.
References & Sources
- World Economic Forum. “Pharma and life sciences must act now on the quantum threat.” September 2025. https://www.weforum.org/stories/2025/09/pharma-life-sciences-quantum-threat-cybersecurity/
- Palo Alto Networks. “Harvest Now, Decrypt Later: Quantum Security Risk.” Cyberpedia. https://www.paloaltonetworks.com/cyberpedia/harvest-now-decrypt-later-hndl
- National Institute of Standards and Technology. “NIST Releases First 3 Finalized Post-Quantum Encryption Standards.” August 13, 2024. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
- National Security Agency / Defense.gov. “Commercial National Security Algorithm Suite 2.0 (CNSA 2.0).” Updated May 2025. https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
- Johns Hopkins Medicine Institutional Review Board. “Record Retention Guidelines.” https://www.hopkinsmedicine.org/institutional-review-board/guidelines-policies/guidelines/record-retention
- Security Scientist. “How to Protect Pharma and Biotech from IP Theft.” https://www.securityscientist.net/blog/how-to-protect-pharma-and-biotech-from-ip-theft/
- HashiCorp. “Harvest now, decrypt later: Why today’s encrypted data isn’t safe forever.” https://www.hashicorp.com/en/blog/harvest-now-decrypt-later-why-today-s-encrypted-data-isn-t-safe-forever
- The Quantum Insider. “Q-Day Predictions: Anticipating the Arrival of CRQC.” https://postquantum.com/post-quantum/q-day-crqc-predictions/
- AxelSpire. “Post-Quantum TLS: How PQC Changes Certificates, Handshakes, and Performance.” https://axelspire.com/business/pqc-tls-certificate-impact/
- QuSecure. “CNSA 2.0 Explained: PQC Requirements, Timelines, and Federal Impact.” https://www.qusecure.com/cnsa-2-0-pqc-requirements-timelines-federal-impact/
- PostQuantum.com. “The Complete US Post-Quantum Cryptography (PQC) Regulatory Framework in 2026.” https://postquantum.com/quantum-policies/us-pqc-regulatory-framework-2026/
- IntuitionLabs. “21 CFR Part 11: Electronic Records, Signatures, AI, GxP Compliance.” https://intuitionlabs.ai/articles/21-cfr-part-11-electronic-records-signatures-ai-gxp-compliance
- GMP Insiders. “GAMP 5 In CSV: Definition, Categories, And Pharma Guidelines.” https://gmpinsiders.com/gamp-5-csv/
- Medcrypt. “Navigating Post-Quantum Cryptography in Medical Device Cybersecurity: 2025 FDA Compliance Guide.” https://www.medcrypt.com/blog/navigating-post-quantum-cryptography-in-medical-device-cybersecurity
- Contract Pharma. “Closing the Gaps: Cybersecurity and Compliance Challenges in Pharma CDMOs.” https://www.contractpharma.com/exclusives/closing-the-gaps-cybersecurity-and-compliance-challenges-in-pharma-cdmos/
- U.S. Food and Drug Administration. “Digital Certificates — Electronic Submissions Gateway.” https://www.fda.gov/industry/electronic-submissions-gateway-next-generation-esg-nextgen/digital-certificates
- Medcrypt. “What Is Post-Quantum Cryptography — and Why Should Medical Device Makers Care?” https://www.medcrypt.com/blog/what-is-post-quantum-cryptography—and-why-should-medical-device-makers-care
- EverTrust. “Hybrid Post-Quantum Certificates: Why Your First PQC Deployment Should Be Hybrid.” https://evertrust.io/blog/hybrid-post-quantum-certificates/
- Cybersecurity and Infrastructure Security Agency. “Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools.” September 2024. https://www.cisa.gov/sites/default/files/2024-09/Strategy-for-Migrating-to-Automated-PQC-Discovery-and-Inventory-Tools.pdf
- CycloneDX / OWASP. “Cryptography Bill of Materials (CBOM) Capability Reference.” https://cyclonedx.org/capabilities/cbom/
- Keyfactor. “How to Build a PQC Migration Roadmap: Step-by-Step Guide.” https://www.keyfactor.com/blog/how-to-build-a-pqc-migration-roadmap-step-by-step-guide/
- McKinsey & Company. “When and how to prepare for post-quantum cryptography.” https://www.mckinsey.com/~/media/mckinsey/business%20functions/mckinsey%20digital/our%20insights/when%20and%20how%20to%20prepare%20for%20post%20quantum%20cryptography/when-and-how-to-prepare-for-post-quantum-cryptography.pdf
- Deloitte UK. “Despite quantum computing’s slow start, LSHC organisations need to prepare now!” December 2024. https://blogs.deloitte.co.uk/health/2024/12/despite-quantum-computings-slow-start-lshc-organisations-need-to-prepare-now.html








Your perspective matters—join the conversation.