DataCenterNews US - Specialist news for cloud & data center decision-makers
United States
Veridos: Why designing quantum-ready trust for global travel and identity starts now

Veridos: Why designing quantum-ready trust for global travel and identity starts now

Fri, 21st Aug 2026 (Today)
Jake MacAndrew
JAKE MACANDREW Interview Editor

Quantum computers capable of breaking today's cryptography are still, by most estimates, a decade or more away. But according to Armin Reuter, Director of Innovation at identity solutions provider Veridos, the more challenging phase for passports and national IDs isn't that eventual breakthrough; it's the years-long migration window that leads up to it.

In a new whitepaper from Veridos, the firm argues that this window requires action from governments and other issuers of identity documents. Reuter said the paper grew out of Veridos' broader monitoring of technology trends within G+D, the security tech group Veridos is part of.

"We understand now that this is a movement that's accelerating," Reuter said, citing McKinsey's 2026 Quantum Technology Monitor, which found investment in quantum computing increased more than sixfold from 2024 to 2025.

The industry shorthand for the moment quantum computers become powerful enough to break current cryptography is "Q-Day." The exact date for that event can´t be foreseen," Reuter said, but estimates run anywhere from the early 2030s to 2040.

The U.K. National Cyber Security Centre recommends completing discovery and migration planning by 2028, carrying out the highest-priority upgrades by 2031 and completing migration by 2035. In the United States, a June 2026 White House order requires federal high-value assets and high-impact systems to adopt approved post-quantum methods for key establishment by Dec. 31, 2030, and digital signatures by Dec. 31, 2031.

Reuter stressed that migrating to post-quantum cryptography is not a matter of flipping a switch on a fixed date. 

"It's not really a window that's closing; it's a window that's opening," he said. "You need to prepare yourself for this crypto agility - where you need to make yourself ready to be able to set up your systems in a way that you can deal more easily with changes as we see it right now because the potential is there that those moves and those challenges will repeat."

Harvest now, decrypt later

Reuter also pointed to the "harvest now, decrypt later" threat: the practice of intercepting and storing encrypted data today in the expectation that it can be decrypted once quantum computers are capable enough. It's a well-known risk to ordinary internet traffic, but Reuter said it applies to identity documents too, since data on a passport chip, including name, date of birth, and biometrics such as fingerprints and a face image, could be captured now and read years later once the underlying cryptography is broken.

If an attacker obtains a copy of protected passport-chip data or associated communications, future cryptanalytic capabilities could expose confidentiality protections. Once current signature schemes become breakable, a quantum break of the signing system could threaten the document's authenticity and integrity.

That risk is compounded by how long identity documents stay in circulation. Many passports have a validity period of 10 years. Reuter said documents issued well before Q-Day could still be in active use once decryption of data by quantum computers becomes feasible.

Unlike a password, biometric data can't simply be reissued if it's compromised, which is part of what makes identity documents a distinct case from ordinary encrypted communications.

The bigger practical risk is sitting one level up from any individual person's data: the cryptographic signature that authenticates a passport's chip data as genuine, anchored in a public key infrastructure that traces back to a private key held by the issuing country.

If that trust chain is broken, Reuter said, bad actors wouldn't just be able to read data - they could, in theory, forge passports that carry a valid-looking digital signature and would be indistinguishable from a genuine document. That's a scenario the International Civil Aviation Organisation (ICAO), which sets the interoperability standards passports rely on, has prioritised addressing through its standardisation work.

Backward compatibility as a design constraint

As different countries will migrate systems to post-quantum readiness at different speeds, Reuter said any new passport signature scheme has to remain backwards compatible. A country issuing quantum-safe passports needs those documents to still be readable by older inspection systems abroad that haven't yet upgraded.

Reuter framed the decision each country faces as fundamentally a risk-assessment question: how urgently they judge the threat, versus how much disruption they're willing to accept for their own passport ecosystem.

The starting point for the shift is the U.S. National Institute of Standards and Technology, which ran a multi-year process to select cryptographic algorithms resistant to quantum attack and published its resulting standard in August 2024.

The United Nations' ICAO is now working to bring a compatible standard for passports into its own specifications, which Reuter expects to land around mid-2027, as the first step in its migration path aimed at the highest-priority risk first: securing passport authenticity before moving on to more complex protections.

Until that global alignment is reached, Reuter said the core challenge for ICAO is moving quickly enough to close the exposure window, without individual countries moving unilaterally in ways that leave others behind or break cross-border interoperability.