Harvest-now-decrypt-later means adversaries collect your encrypted traffic today to decrypt with quantum computers tomorrow. For Saudi banks, health providers, and government suppliers with 6-year archives, migration to post-quantum crypto cannot wait until standards feel mature. NIST has finalized ML-KEM for key exchange and ML-DSA for signatures. Browsers and Cloudflare already support hybrids.
This is the full migration checklist for Saudi IT teams from inventory to pilot to rollout.
1. Inventory what breaks first
List TLS endpoints by Cloudflare and origin versions, VPN concentrators with IKE versions, code-signing certs for apps and Fatoora EGS keys, file backups with encryption age, and database column encryption. Tag each by data lifetime. Anything kept over 5 years like Fatoora archives, health records, and contracts is priority one.
Tooling is censys plus internal CMDB plus manual vendor emails. Ask every vendor for PQC roadmap with dates for HSM, VDR, and SaaS. No roadmap means replacement risk in RFPs.
2. Hybrid first, pure later
Do not jump to pure post-quantum yet. Deploy hybrid X25519 plus ML-KEM-768 for TLS via Cloudflare origin plus Chrome test. This keeps classical security while adding quantum resistance. Measure handshake size increase of 1 to 2KB and CPU overhead under 10 percent. Most Saudi 4G users see no UX change.
For signatures, pilot ML-DSA for internal code signing alongside classical ECDSA. Dual-sign artifacts during transition. For VPN, upgrade to IKE with ML-KEM where vendor supports, otherwise plan hardware refresh in 2027 budget.
3. Data re-encryption plan
Re-encrypt long-lived PII archives with hybrid envelope encryption. Keep original ciphertext until new decryption verified, then securely delete old keys per PDPL minimization. Prioritize Fatoora 6-year archives, HR records under Qiwa, and patient data.
For backups, rotate keys and re-encrypt fulls quarterly. Test restore with new algorithms on staging. Document key ceremonies in Arabic and English for auditors.
4. Timeline for Saudi teams
2026 is pilot. Enable hybrid TLS on public sites, inventory vendors, and run one internal ML-DSA signing flow. 2027 is migrate external TLS, VPN for critical sites, and re-encrypt archives. 2028 is enforce PQC-only for new systems and deprecate RSA-2048 for sensitive data.
Budget HSM upgrades, as older HSMs lack ML-KEM firmware. Include PQC requirements in every RFP from now. Vendors respond to procurement language faster than tech blogs.
Start with external TLS this quarter. It is low-risk, visible, and unblocks enterprise deals that already ask about quantum readiness. Internal systems follow once runbooks exist.
Bottom line is harvest risk is real for long archives. Inventory this month, hybrid TLS next quarter, re-encrypt archives by 2027. That is quantum-safe without hype.





