Why post-quantum readiness is becoming a manufacturing leadership issue

Why post-quantum readiness is becoming a manufacturing leadership issue

Industrial IoT growth and evolving cybersecurity risks are pushing post-quantum cryptography to the forefront of manufacturing strategy, says Ben Packman, Chief Strategy Officer, PQShield.

Connected devices now sit at the heart of modern manufacturing, from production lines and warehouses to robotics, maintenance systems and industrial monitoring. Industrial IoT has helped manufacturers improve efficiency, reduce downtime and make faster decisions. With forecasts pointing to as many as 39 billion IoT devices in the sector by 2030, that reliance is only likely to deepen.

The question for enterprise leaders is what kind of security foundation those environments are being built on.

After the early hype and panic around AI, CIOs and CISOs are starting to recognise that AI changes the economics of trust. There is now less room for assumption as high-assurance security becomes more valuable when vulnerabilities can be found, tested and exploited faster. For enterprise teams, that means security cannot stop at the application layer. They need to look deeper into the hardware, firmware and cryptography underneath and they need to ask the same questions of their suppliers.

Why trust now runs deeper in manufacturing

Against this backdrop, a new cybersecurity challenge for IoT is gathering momentum – the need to adopt post-quantum cryptography (PQC). If AI is making it harder to rely on assumed security then the mechanisms that establish trust between devices, software and systems matter much more. That is why PQC is moving up the agenda.

It is no longer just a future upgrade to think about once the market settles. It is becoming part of the security foundation for connected systems that need to remain trusted for years, especially in manufacturing where operational assets are long-lived, hard to update and deeply embedded into day-to-day operations.

That is important in manufacturing because most industrial organisations are not building from scratch. They are layering new connected capabilities onto estates that already include legacy systems, ageing firmware, constrained devices and assets expected to remain in service for years.

In those environments, cryptography runs through device identity, secure boot, firmware signing, update mechanisms, certificates, gateways and machine-to-machine communications. That makes post-quantum readiness a leadership issue, not just a technical one.

Manufacturers need to prioritise PQC earlier than many other sectors because those cryptographic choices can remain locked in for years after deployment. Changing them is difficult in any enterprise environment but in industrial settings it can be harder still.

Security upgrades can mean downtime, revalidation, production risk and difficult coordination across multiple vendors. Some devices are physically hard to reach while others were never designed to support major cryptographic change once deployed. That is what makes manufacturing uniquely exposed: the issue is not just a future quantum threat but whether systems being deployed now will remain trusted, supported and updateable over their full operational life.

Why the planning window is narrowing

This is also why the industry is starting to use NIST’s transition work as a practical reference point. NIST has finalised its first PQC standards and says organisations should begin migrating now. Its transition plan says quantum-vulnerable public-key algorithms will be deprecated and ultimately removed from NIST standards by 2035, with higher-risk systems expected to move earlier.

That does not mean manufacturers need to attempt a wholesale replacement programme overnight. It does mean however the planning window is narrowing. Google’s 2029 post-quantum migration target is already becoming a market reference point, showing how quickly expectations can shift when a hyperscaler starts moving.

At the same time, governments and standards bodies are pushing quantum resilience higher up the agenda. For manufacturers and critical infrastructure operators, this changes the planning horizon. Procurement and refresh decisions being made now will shape what security their environments can realistically support into the next decade.

Where manufacturers should start

So where should organisations start? Not every system carries the same long-term risk. The practical starting point is not perfect visibility of every cryptographic dependency on day one but enough visibility to prioritise smartly.

Which assets establish trust? Which systems protect sensitive data? Which devices are likely to remain in the field the longest? Secure boot, firmware validation, update infrastructure and device identity often come into focus early because they sit closest to the foundation of trust.

If those layers are difficult to change later, the cost and complexity of future migration rises sharply.

The supply chain test for PQC readiness

The next issue is supplier accountability. In Industrial IoT, manufacturers often depend on technology they do not fully control. Critical cryptographic decisions may sit inside chipsets, embedded operating systems, communications stacks, PKI tooling or vendor-managed platforms.

That means enterprise teams need to ask harder questions of suppliers: what cryptography is embedded, what migration path exists, what standards support is planned and whether deployed products can realistically be updated without disruption.

This is where AI and post-quantum readiness begin to converge. As AI increases the rate at which weaknesses are discovered, enterprises are likely to place greater value on modular, standards-aligned components that can be assessed, upgraded or replaced with confidence as risk changes over time.

That should lead to a tougher conversation across the supply chain but ultimately a healthier one.

For leadership teams, the point is not simply that stronger algorithms are coming. It is that long-term trust in connected industrial systems is becoming harder to assume and more important to prove. In manufacturing, where technology remains in service for years and disruption carries real commercial consequences, post-quantum readiness is becoming part of mainstream resilience planning.

Browse our latest issue

Intelligent CISO

View Magazine Archive