Published: August 12, 2026
Las Vegas, United States — August 11, 2026 — Critical infrastructure operators worldwide are confronting a mounting compliance challenge as government-mandated post-quantum cryptography (PQC) deadlines approach, while the Operational Technology (OT) Security Market grapples with legacy systems that remain structurally unprepared to adopt quantum-safe algorithms. Industry practitioners and cybersecurity authorities warn that software upgrades alone will not be sufficient to secure OT environments against the quantum threat.
The National Institute of Standards and Technology (NIST) finalized its post-quantum cryptography standards in August 2024, and governments across multiple jurisdictions have since established hard deadlines — predominantly between 2028 and 2030 — for critical infrastructure operators to achieve compliance. NIST's algorithms are mandated to replace current RSA and elliptic-curve cryptography starting in 2030, with existing standards prohibited by 2035.
However, practitioners warn that the OT ecosystem — encompassing power grids, water systems, transportation networks, and industrial control systems — is structurally ill-equipped for this transition. Field-level protocols that transmit commands and telemetry to remote terminal units (RTUs), protection relays, and inter-control center communications were never designed with meaningful cryptography, making post-quantum migration fundamentally different from a standard software update.
"In large parts of OT, it currently is not [ready]," said Marin Ivezic, CEO of Applied Quantum, referring to the readiness of OT environments to run quantum-safe algorithms.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) cautioned in October 2024 that OT "accounts for a significant proportion of out-of-date operating systems and software platforms," including end-of-life systems such as Windows XP still running in the field, and warned that OT "may account for some of the last remaining platforms to achieve post-quantum cryptographic standards" due to long software patching cycles, hardware replacement timelines, and strict governance procedures.
A.B. Sengupta, alternate CISO with Grid Controller of India, described a two-tier challenge: while IT-heavy OT layers — including PKI, VPNs, and remote access — are realistic candidates for post-quantum migration, field-level protocols and inter-control center communications have little cryptography built into them at all. Maria Christofi of the European Union Agency for Cybersecurity (ENISA) further noted that migration assumes all systems can be upgraded to versions supporting PQC — a step that "can be really difficult and long" for enterprises running OT systems.
DigiCert's Quantum Readiness Outlook (July 2026) found that 87% of organizations report planning, testing, or implementing PQC, yet only 7% report that more than half of their digital certificates use quantum-safe or hybrid cryptography — a figure that improved less than 2% since May 2025.
NIST's finalized PQC algorithms must replace RSA and elliptic-curve cryptography starting in 2030, with existing standards prohibited by 2035, creating a compressed compliance window for OT operators globally.
Hardware constraints present a structural barrier: many older field controllers lack the memory capacity to run post-quantum signatures, which are larger and more memory-intensive than current cryptographic standards.
Cryptographic asset inventory gaps persist across OT environments — organizations frequently lack visibility into what cryptography, if any, is embedded in their systems, a prerequisite for any migration planning.
According to analysts at Next Move Strategy Consulting, the post-quantum compliance challenge is arriving at a particularly consequential moment for the OT security sector. The global OT Security Market was valued at USD 24.67 billion in 2024 and is projected to reach USD 95.06 billion by 2030, growing at a CAGR of 25.5% — a trajectory driven in part by escalating regulatory mandates and the increasing sophistication of cyber threats targeting critical infrastructure.
NMSC analysts note that the convergence of post-quantum migration requirements with legacy OT infrastructure constraints is likely to accelerate demand for purpose-built OT security solutions, managed security services, and cryptographic asset management tools. Organizations that proactively invest in OT-specific security frameworks and conduct early cryptographic inventories will be better positioned to meet compliance deadlines while maintaining operational continuity.
The realistic picture for OT ecosystems by the end of this decade, as described by practitioners, is one of triage rather than comprehensive migration. PKI, VPNs, and remote-access gateways are expected to achieve quantum-safe status on schedule, while field-level protocols and embedded hardware are projected to lag significantly behind.
Some legacy devices may never receive a post-quantum upgrade, leaving operators to choose between deploying compensating controls, replacing hardware, or formally accepting residual risk. The absence of consensus on hybrid cryptography standards — where classical and post-quantum algorithms run in parallel during the transition — further complicates interoperability planning across the sector.
For the broader OT security industry, the post-quantum challenge underscores the structural limitations of applying IT-centric security frameworks to industrial environments. Vendors supplying hardware-layer components, including intelligent electronic devices, RTUs, and PLCs, remain fragmented in their post-quantum roadmaps, creating supply chain dependencies that operators cannot resolve unilaterally. The coming years are expected to intensify investment in OT-native security architectures capable of bridging the gap between compliance mandates and operational realities.
Source: OT.today
For More Information: Download FREE Sample on Operational Technology (OT) Security Market Report
Prepared By: Sanyukta Deb
Sanyukta Deb is a senior content writer and content analyst with expertise in content strategy, audience engagement, and research-driven storytelling. With a strong leadership approach and strategic mindset, she drives content initiatives that strengthen brand communication and audience connection. She combines creativity with analytical insight to develop impactful, value-led content while mentoring collaborative efforts across teams to ensure consistent, meaningful engagement and long-term brand growth across digital platforms.
Debashree Dey is a senior content writer and communications specialist known for crafting audience-focused narratives and insight-driven content strategies. As a published manuscript author, she combines creative storytelling with strategic thinking to strengthen brand messaging, enhance visibility, and drive meaningful audience engagement across digital platforms. With a collaborative leadership approach, she contributes to high-impact communication initiatives that ensure consistency, clarity, and long-term brand value. Outside of work, she finds inspiration in creative projects, design exploration, and storytelling-driven ideas.
This website uses cookies to ensure you get the best experience on our website. Learn more
✖
Add Comment