NIST finalised the post-quantum cryptography standards in late 2024. Eighteen months later, the ecosystem has caught up. Chrome, Firefox, and Safari ship hybrid post-quantum key exchange in TLS by default. Cloudflare, Akamai, and Fastly have it enabled at the edge. AWS KMS supports ML-DSA for signing. The infrastructure is ready.
What hasn't caught up is most internal infrastructure. Service-to-service TLS, internal CAs, code-signing pipelines, and VPN tunnels are still overwhelmingly RSA or ECDSA. That is the migration work that needs to happen in 2026, not 2030.
The 'harvest now, decrypt later' threat is real and underweighted. Adversaries are recording encrypted traffic today on the assumption that a Shor-capable quantum computer will exist within fifteen years. Anything in that recorded traffic that needs to remain confidential past 2040 is at risk. For most companies, that includes customer PII, trade secrets, and authentication credentials.
The migration is annoying but not hard. The signature schemes are roughly 10x larger than RSA, so your certificate sizes, TLS handshake bytes, and JWT tokens grow. Mostly that's a CDN cost and a load balancer config change. The cryptographic libraries already exist (Bouncy Castle, OpenSSL 3.3, libsodium with the libpqcrypto patches).
The two-step path most teams should follow: enable hybrid TLS at your edge this quarter, then migrate internal PKI to a hybrid-capable CA before end of year. Anything more aggressive is premature; anything less leaves a known vulnerability open.