Why Critical Infrastructure Is at Risk
Critical infrastructure sectors, including energy, water systems, transportation, and communications, rely on networked control systems whose disruption would have severe consequences for public safety, economic security, and national security. These systems use cryptography to authenticate commands, protect communications, and secure remote access.
The harvest-now-decrypt-later threat is particularly significant for critical infrastructure because adversaries collecting encrypted operational technology communications today can decrypt them to understand system configurations, operator procedures, and network topologies. This intelligence could inform future attacks, even if decryption occurs years after the data was collected.
Operational Technology Challenges
Operational technology (OT) environments, including industrial control systems (ICS), SCADA systems, and programmable logic controllers (PLCs), present migration challenges distinct from IT environments.
Constrained compute
Many OT devices have limited processing power and memory. Some post-quantum algorithms require more computation than classical alternatives. Resource-constrained deployments may require selecting the smallest parameter sets or deferring PQC until device replacement.
Real-time requirements
Industrial control systems often have strict real-time requirements. Cryptographic operations that introduce unacceptable latency in command-response cycles cannot be deployed. Performance testing in representative environments is required before any migration.
Patching and update cycles
OT systems are often updated infrequently because patches require downtime, testing, and vendor certification. A cryptographic algorithm change may require a formal change management process that takes months to complete.
Long equipment lifetimes
Industrial equipment routinely operates for 15 to 30 years. Decisions made today about what cryptographic algorithms to deploy in new equipment will affect security for decades. Post-quantum readiness must be a procurement requirement for new OT purchases.
Key Sectors and Systems
Energy sector systems, including power generation, transmission control, and distribution management systems, use cryptography for authenticated remote access, operator communications, and SCADA protocol security. These systems control infrastructure whose disruption would affect public safety across wide areas.
Water and wastewater systems use networked controls with similar cryptographic dependencies. The relatively smaller scale of many water utilities means they may have fewer dedicated security resources, making sector-wide guidance and shared tooling particularly important.
Transportation systems, including air traffic control, rail management, and port operations, depend on cryptographic authentication for command-and-control communications. Aviation systems in particular have long certification cycles that make early migration planning essential.
Regulatory and Guidance Context
CISA has published sector-specific cybersecurity guidance for critical infrastructure that addresses post-quantum risk. The Cybersecurity Performance Goals (CPGs) published by CISA provide a baseline framework that critical infrastructure owners and operators can use to assess and improve their cryptographic posture.
The Transportation Security Administration (TSA) has issued cybersecurity directives for pipeline, rail, and aviation operators that address encryption and authentication requirements. Post-quantum considerations should be integrated into compliance planning for these directives.
The North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) standards govern cybersecurity for the North American bulk power system. NERC CIP does not yet explicitly require post-quantum cryptography, but the standards' requirements for access control and cryptographic security extend to algorithm choices.
Addressing Long Equipment Lifecycles
The most effective intervention for long equipment lifecycles is procurement policy. Requiring post-quantum algorithm support in new equipment purchases ensures that the next generation of OT hardware will be capable of running ML-KEM and ML-DSA without replacement. This should be implemented as an immediate procurement policy change.
For existing equipment that cannot be updated in place, migration must be planned around equipment replacement cycles. The cryptographic inventory should identify which systems are approaching end-of-life and can be replaced with post-quantum-capable hardware within the migration window.
Implementation Approach
The migration starting point for critical infrastructure is a cryptographic inventory that distinguishes IT systems from OT systems. IT systems supporting corporate functions (HR, finance, email) can follow standard IT migration approaches. OT systems require a separate track that respects operational constraints and vendor certification requirements.
Remote access systems for OT networks are an early priority. VPNs and remote desktop infrastructure used for OT access should be migrated to hybrid or post-quantum key exchange to protect operator communications. These systems often run on standard IT hardware and are more tractable to update than field devices.

