Summary
The core message of the session is that post-quantum cryptography migration should move from abstract guidance into practical, organization-specific experimentation now, because the risk is foreseeable and the migration work can take years. Manon de Vries opened by aligning the audience on the basics: quantum computers already exist, are not yet advanced enough to break today’s widely used cryptography, but are expected to become stronger. The speakers stressed that many current cryptographic mechanisms will eventually become vulnerable, and that waiting is dangerous because migration itself may take five to ten years, while some data must remain confidential for twenty years and authenticity requirements, such as passports, can last a decade. They framed this as an unusual advantage for security teams: unlike an emergency such as Log4j, organizations can plan ahead, collaborate, and replace part of the invisible security “foundation” before a crisis arrives.
The session then explained why the speakers and their organizations began working on PQC migration in practice. Through the PCSI program, a cooperation between commercial and public organizations focused on cybersecurity innovation, participants identified in summer 2024 that many organizations were hesitant to start. The problem was not a lack of high-level guidance, but a lack of practical experience showing what actually happens when unsafe cryptography is migrated to quantum-safe alternatives. Five organizations each chose one application or area to migrate, covering examples such as own code, hardware, and vendor products. The goal was deliberately not to publish only polished success stories, but also to share what failed, what was ugly, what questions vendors really needed to answer, and what alternatives exist when direct migration is not possible.
After a year, the group concluded that it had learned enough to continue rather than stop. In summer 2025, the work evolved into a PQC work group focused on one of the first steps repeatedly recommended for migration: building a cryptographic inventory. Seven participating organizations, including TNO, ING, the Dutch tax office, an insurance company, ABN AMRO, a government IT provider, and RDI, pursued different inventory experiments because their environments and priorities differed. Use cases included TLS scanning, certificate analysis, code repository analysis, cryptographic library usage scanning, and PQC-vulnerability scanning. Gamze Tillem emphasized that each organization should identify its own priorities or low-hanging fruit and start there, rather than wait for a complete universal approach.
The available transcript closes as the speakers shift from technical experiments to organizational lessons. They define a useful cryptographic inventory as more than a list of libraries, keys, algorithms, and key sizes. To become actionable, the inventory must connect cryptographic assets with risk context: internet exposure, confidentiality requirements, critical business assets, crown jewels, and ownership. The speakers also underline that while central security teams such as a CISO organization may provide capabilities and guidance, product owners, asset owners, and business units must take responsibility for acting on the findings. The practical conclusion is that inventory building is not the final goal; it is the foundation for prioritizing and executing PQC migration.
Key Topics
5 key topics from Manon de Vries and Gamze Tillem at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Start PQC migration before quantum risk becomes urgent.
- Build a cryptographic inventory before prioritizing migration work.
- Combine crypto assets with exposure, confidentiality, and ownership data.
- Experiment on low-hanging use cases instead of waiting for completeness.
- Ask vendors migration-specific questions, not only generic security questions.
“We need to migrate now, not wait. Why? First of all, because migration takes a lot of time.”
Up Next



Next in agenda
Strategic dependencies cryptographic products & services


Also on post quantum crypto
PQC: Who owns cryptography? When decisions outgrow IT


Also on cybersecurity
