Encrypted data intercepted today can be stored and decrypted tomorrow, once a sufficiently powerful quantum computer becomes available. In 2024, the NIST finalized three post-quantum cryptography standards, corresponding to ML-KEM, ML-DSA and SLH-DSA; a standard based on FALCON was still in preparation. The United States has established a federal transition to quantum-resistant algorithms and has prioritized data that must remain sensitive until 2035; the NIST proposed deprecation timelines starting in 2030 and prohibition after 2035 for certain uses. Preparation is heterogeneous in Latin America; some countries, including Brazil, have already launched public initiatives related to post-quantum cryptography.
The Essentials
- The post-quantum migration follows a fixed timeline: states that do not comply will see their encrypted communications of today become decryptable tomorrow.
- In 2024, the NIST standardized four PQC algorithms (CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and FALCON); the NSA and CISA require migration of American national systems by 2030.
- The migration of the global financial sector alone is estimated between 100 and 500 billion euros; the average technical timeline is three to seven years, according to the NIST.
- The critical window known as “harvest now, decrypt later” is already open: hostile actors are storing encrypted flows awaiting quantum capacity, with a cryptanalysis window estimated between 2026 and 2033.
- Latin America faces this transition without a coordinated national roadmap, creating an exploitable risk asymmetry for its diplomatic, financial and industrial data.
The Three Standards Reshaping Global Security
NIST standardization did not happen overnight. The process began in 2016 with sixty-nine candidates submitted by teams from around the world. Eight years later, three standards were finalized following evaluations by academic cryptographers, government agencies and industry professionals. CRYSTALS-Kyber protects key exchanges. CRYSTALS-Dilithium ensures digital signatures.
SPHINCS+ offers an alternative based on hash functions. The first three PQC standards finalized by NIST in 2024 constitute the first NIST set of standards designed to resist quantum attacks.
Standardization is one thing. Migration is another. Changing the cryptographic infrastructure of a state, central bank or telecom operator does not happen within months. The NIST indicates that historically, the complete integration of new algorithms into systems can take ten to twenty years. The United States has established a federal transition to quantum-resistant algorithms and has prioritized data that must remain sensitive until 2035.
For countries with limited cybersecurity resources, migration can present additional difficulties.
Cost is another variable. The cost of migrating the financial sector depends notably on the scope and age of the systems to be replaced. Central banks, property registries, interbank payment systems, encrypted diplomatic archives: systems and data whose confidentiality must last a long time must be prioritized according to an analysis of risk, duration of sensitivity and cryptographic dependencies.
“Harvest now, decrypt later”: The Threat Building in Silence
The time constraint is not theoretical. It is based on a mechanism documented by the NIST and American federal authorities under the name “harvest now, decrypt later”: American authorities warn that malicious actors can collect and retain today data protected by classical algorithms vulnerable to quantum computers in order to attempt to decrypt them when sufficient quantum capacities become available. Public estimates on the timeline vary; the 2030-2035 period is sometimes presented as a turning point, not as a certainty. This estimate remains conditional, no one knows precisely when a large-scale quantum computer will be operational, but it structures the decisions of the national security agencies of countries that have the means.
For a Latin American country whose diplomatic negotiations, infrastructure contracts or financial data reserves are encrypted with classical protocols, the threat is concrete. Data correctly protected by current asymmetric mechanisms are not supposed to be decryptable with available classical capacities, but this security depends on implementation and key management. They could be decrypted later if a cryptographically relevant quantum computer became available. Post-quantum cryptography, often deployed with hybrid mechanisms and a crypto-agility strategy, is the main long-term response; other measures, however, reduce risk during the transition.
The calendar gap between developed and developing countries has concrete consequences. A complete and properly implemented migration would greatly reduce future quantum risk, but does not alone guarantee protection of all data. Data already collected and encrypted with vulnerable asymmetric mechanisms can remain exposed during the transition if they retain value until the arrival of relevant quantum capacity. Migration delay increases the risk that data protected by vulnerable asymmetric mechanisms, and intercepted, will be decrypted later. Risk varies by country and system.
Latin America Facing a Transition Without a National Compass
The Latin American continent is not homogeneous. Brazil has the ANPD, the National Data Protection Agency, competent mainly in personal data and privacy, and does not have a national cybersecurity agency called ANPD, has a sophisticated banking sector and a cryptography research community. Chile produced a revised national cybersecurity strategy in 2023. Colombia has active organizations in digital security, notably ColCERT and a national security operations center; the creation of a national agency specialized in digital security was still in preparation according to the official source consulted. In the region, approaches to post-quantum migration differ by country.
The main obstacle is not ignorance of the problem. Latin American researchers participate in international cryptography conferences; the region’s central banks are aware of NIST’s work. The obstacle is structural: migrating to PQC algorithms requires rare skills, an exhaustive inventory of existing cryptographic systems, the capacity to test and deploy new protocols on heterogeneous infrastructures, and multi-year dedicated budgets. The availability of these factors varies by country and sector in the region.
Timelines mechanically lengthen. A country that begins its cryptographic inventory in 2026 will finish its mapping in 2027 or 2028. The migration itself can extend over several years depending on systems. Full protection will depend on the rate of migration and effective coverage of systems. Data with long-term confidentiality that remain protected by vulnerable mechanisms can be exposed to collection risk for later decryption during any migration delay.
Asymmetry is exploitable in differentiated ways. Communications and data whose sensitivity persists over a long period must be prioritized according to their duration of confidentiality, their exposure to interception and their dependence on vulnerable cryptography. An actor with advanced quantum capacities in 2030 could decrypt negotiations conducted in 2025 with Latin American partners. This potentially includes negotiating positions on trade agreements, data on critical infrastructure, or communications between governments and strategic businesses.
States That Migrate Early
Post-quantum migration is not solely a defensive challenge. As we examined in a previous article on post-quantum cryptography, states that invest early in this transition acquire a structural advantage: they master the protocols, develop skilled teams, and participate in defining standards. The three standards finalized by NIST in 2024 are ML-KEM, ML-DSA and SLH-DSA, derived respectively from CRYSTALS-Kyber, CRYSTALS-Dilithium and SPHINCS+. China is conducting its own standardization programs for post-quantum algorithms, independently of NIST, in a logic of cryptographic sovereignty.
For the United States, the 2022 National Security Memorandum NSM-10 established migration priority and the NSA has published sectoral guidelines for defense, intelligence and critical infrastructure. The British government followed in 2023 with a similar framework. South Korea, Singapore and Australia have launched national cryptographic inventory programs. These states do not merely comply with a timeline: they train cohorts of specialized engineers, certify suppliers, and create the conditions for a domestic post-quantum security market.
This last point deserves attention. PQC migration generates considerable industrial demand: audit of existing systems, development of cryptographic libraries, integration into network protocols (TLS, SSH, VPN), updating of hardware equipment. Countries that launch early national programs grow a local industrial fabric. Countries that migrate late will purchase solutions from foreign suppliers, reproducing a technological dependence that we already observe in other areas, a dynamic found in the unequal structuring of the global technology value chain.
The Value of Information for Countries That Migrate Late
The question posed by unequal migration goes beyond cybersecurity in the strict sense. It touches on informational sovereignty over the medium term. A country whose strategic data of the 2020s is potentially decryptable by hostile powers in 2030 suffers a form of lasting informational asymmetry. Past decisions, negotiating positions, vulnerabilities identified in government communications become readable in hindsight. The effect is not immediate, but it is cumulative.
Two trajectories seem probable by 2030-2035 for Latin America. In the first, a few countries, likely Brazil and Chile, possibly Mexico, launch national programs between 2025 and 2027, support the upskilling of specialized teams, and achieve partial migration of the most sensitive systems by 2032-2033. Their exposure remains real during the transition, but they enter the category of states that have acted. In the second, several economies in the region progress more slowly, particularly when funding, institutional capacities and political prioritization are insufficient.
These two trajectories are not mutually exclusive: they can coexist within the same country, depending on sectors. A central bank can migrate its payment systems by 2030 while sectoral ministries remain on classical protocols until 2038. This internal heterogeneity is itself a vulnerability: hostile actors do not attack the best-protected systems, they seek weak links.
The International Telecommunication Union (ITU) and the Organization of American States (OAS) have both published guidance on post-quantum transition for developing countries. These frameworks exist. In several countries in the region, the translation of these guidelines into budgets, recruitment and binding timelines remains to be consolidated. A few initiatives deserve to be tracked: the cybersecurity cooperation program between Brazil and the European Union launched in 2023, the work of INCO (National Institute of Cryptology) in Argentina, and discussions within MERCOSUR on harmonizing digital security standards. These mechanisms have not necessarily produced a coordinated regional PQC roadmap.
The question that remains open is that of funding. Can the post-quantum migration of critical infrastructure in a middle-income country be integrated into digital development aid programs? The European Union, the United States and the Inter-American Development Bank have mechanisms that could finance part of these transitions, provided that beneficiary governments build the institutional capacities to absorb them. The lock is not solely financial: it is political and administrative. Post-quantum cryptography is a topic that does not make the front page, but whose effects will be felt when it is too late to react quickly.
Sources
- NIST Post-Quantum Cryptography Standardization, https://csrc.nist.gov/projects/post-quantum-cryptography
- SOCI Report 2026, “Ten Scientific Advances Getting Ready to Change the World”, https://www.soci.org/news/2026/6/ten-scientific-advances-getting-ready-to-change-the-world
- NSA/CISA, “Quantum-Resistant Cryptography Migration Guidelines”, NSA Cybersecurity Advisory, 2022-2024
- ENISA, “Post-Quantum Cryptography: Current state and quantum mitigation”, European Union Agency for Cybersecurity
- ITU, “Quantum Technologies and Developing Countries: Bridging the Gap”, International Telecommunication Union
- OAS, “Cybersecurity in Latin America and the Caribbean”, Organization of American States, annual reports
- Directive NSM-10, National Security Memorandum on Quantum Computing, White House, May 2022