The order landed with a hard deadline attached, and it is aimed squarely at the systems that keep the lights on.

Intelligence heads from the Five Eyes alliance, the intelligence-sharing partnership among the United States, United Kingdom, Canada, Australia, and New Zealand, have released a defensive framework mandating that operators of critical infrastructure phase out legacy public-key cryptography by the end of the third quarter, replacing it with post-quantum encryption standards designed to withstand attacks from future quantum computers. The directive singles out electrical grids and water systems as priority targets, reflecting concern that these networks, often built on older technology stacks, are simultaneously the most consequential to secure and among the least prepared to make the transition quickly.

The push comes against a backdrop of what alliance officials describe as a marked increase in automated, nation-state-linked scanning activity directed at utility networks. Automated scanning tools allow adversaries to continuously probe infrastructure systems for vulnerabilities at a scale that would be impossible with manual reconnaissance, and intelligence officials have grown increasingly concerned that some of this activity is being paired with adversarial AI tools capable of identifying and exploiting weaknesses faster than defenders can patch them.

The underlying technical concern is what security researchers have long called the "harvest now, decrypt later" problem. Traditional public-key encryption, the standard that has protected sensitive data transmission for decades, relies on mathematical problems that are extremely difficult for classical computers to solve but that a sufficiently advanced quantum computer could, in theory, break. Adversaries do not need a working quantum computer today to benefit from this vulnerability; they can intercept and store encrypted data now, with the expectation of decrypting it once quantum computing capability matures. For critical infrastructure systems, where operational data and control communications may need to remain secure for years or decades, that risk window makes early migration to quantum-resistant encryption a priority even before quantum computers capable of breaking current standards actually exist.

The Q3 deadline gives utility operators a relatively narrow window to complete what is, in practice, a substantial technical undertaking. Migrating legacy systems to new cryptographic standards typically involves auditing existing infrastructure, testing compatibility across often decades-old industrial control systems, and rolling out updates without disrupting the continuous operation that critical infrastructure demands. For water and electrical utilities in particular, many of which operate equipment with long service lifespans and limited IT modernization budgets, meeting the deadline will likely require significant coordination between national regulators and infrastructure operators in the months ahead. How consistently the directive is enforced across the five member countries, and how utilities outside the alliance respond to a standard increasingly seen as a benchmark, will shape how much of the standard actually gets set by this deadline versus in the compliance period that follows it.