Solutions

15.07.2026

|

Reading time5 min

The race to Q-Day: how to protect digital trust in the age of quantum computing

The race to Q-Day: how to protect digital trust in the age of quantum computing

Cybersecurity and cryptographic migration: Qualified Trust Service Providers (QTSP) strengthen their defenses against future quantum threats by increasing their robustness.

By Simone Baldini, Head of Business Compliance

The race to Q-Day: how to protect digital trust in the age of quantum computing

As the adoption of advanced technologies accelerates business processes, the evolution of industrial-scale quantum computers calls for an immediate rethink of our security standards.


In this article you’ll discover:

The cybersecurity landscape is facing an unprecedented transformation. While the attention of the media and of businesses is currently focused mainly on the opportunities and risks of artificial intelligence, an even deeper challenge is looming on the horizon. The development of industrial-scale quantum computers is a genuine technological revolution, but it brings with it a systemic threat: the ability to easily break the public-key cryptographic protocols that today form the backbone of the internet and of global trust services. Protecting the integrity and legal validity of digital documents and identities is therefore a priority that can no longer be postponed.

The threat of quantum computing and the “Harvest Now, Decrypt Later” scenario

The quantum computer capable of breaking today’s encryption systems is not yet a widespread reality, but the threat it poses calls for immediate, proactive adaptation. Sufficiently powerful quantum computers could, in fact, solve in a very short time some of the mathematical problems that make public-key cryptography secure today, and would thus be able to break cryptographic keys that are currently considered safe.

The term Q-Day identifies the exact moment when a sufficiently powerful and stable quantum computer will be able to break the mathematical shields of classical cryptography. Although a machine with such computational capabilities is not yet available on the market, according to the Quantum Threat Timeline Report of the Global Risk Institute — the most authoritative and long-running expert survey on this topic — the estimated probability that such a quantum computer will become a reality by 2035 now stands between 28% and 49%, a marked increase compared to previous editions of the report.

The most concrete and current risk is linked to a strategy adopted by cybercriminals and other malicious actors, known as “Harvest Now, Decrypt Later”. Large quantities of encrypted data are intercepted and stored today, with the aim of decrypting them as soon as sufficiently powerful quantum machines become available. This scenario puts the integrity and legal validity of digital documents and identities at risk in the long term, because data that seems safe today could prove vulnerable in a few years.

The ENISA guidelines and the two-phase migration strategy

To counter this scenario, the European Union Agency for Cybersecurity (ENISA) has issued specific guidelines that must be adopted by qualified trust service providers (QTSPs). The recommendations of the European authority suggest adopting measures to strengthen the security of services and, with their reference within the eIDAS Implementing Acts, they apply in full from 19 August of next year: a specific obligation for qualified trust service providers, distinct from the broader European roadmap for the transition to Post-Quantum Cryptography (PQC), which has its own deadlines between 2026 and 2030.

The technological migration strategy set out by ENISA is divided into two sequential macro-phases. First, current technologies and algorithms are kept in place, but with a significant increase in the size of the cryptographic keys to strengthen their protection. The next phase involves a complete technological replacement that will integrate PQC mechanisms, introducing algorithms designed specifically to withstand quantum attacks while running on traditional infrastructure. It is essential to distinguish the scope of the two phases. The first, immediate phase increases the length of classical cryptographic keys (for example, towards 3072-bit RSA where this widely used algorithm is employed): a strengthening of robustness, aligned with the strictest ENISA requirements currently available, but one that does not in itself make certificates “quantum resistant”. A sufficiently powerful quantum computer would still be able to break an RSA key, even a 3072-bit one, albeit with greater difficulty. True resistance to quantum attacks will be guaranteed only by the second phase, with the adoption of Post-Quantum Cryptography (PQC) algorithms.

How Intesa can support your business in the quantum transition

Protecting a company’s information assets and ensuring the long-term validity of digitally signed documents requires expertise, ready infrastructure and a clear vision of crypto-agility.

As a leading QTSP in the sector, Intesa has already defined its technology roadmap in full compliance with European guidance. The move to stronger keys will not be imposed from above, but will be a controlled process carried out by agreement with, and with the consent of, the customer. This methodological approach is essential to ensure full system interoperability: an abrupt, unagreed change could in fact make files signed with the new specifications temporarily unreadable by third parties or by public administrations that are not yet aligned with the new standards. This is the first step of a broader path: Intesa is actively following the evolution of Post-Quantum Cryptography standards in order to plan, in the next phase, the migration to truly quantum-safe algorithms.

Through its solutions for digital signature and document management, Intesa supports companies at every stage of this delicate regulatory and technological transition. Choosing Intesa’s trust services means relying on a partner that accompanies you step by step through the cryptographic upgrade, from the immediate strengthening of keys to the future adoption of post-quantum standards, ensuring business continuity at every stage.


Discover our solutions for your company’s digital transformation:

You might be interested in

ButanGas, flexibility and simplicity to put the customer at the centre

Solutions

07.10.2026

ButanGas, flexibility and simplicity to put the customer at the centre

Success Stories shared by our clients

Continue reading

Electronic invoicing in France: what changes from September 1, 2026

Regulations, Solutions

24.08.2026

Electronic invoicing in France: what changes from September 1, 2026

La Francia sta rivoluzionando il proprio sistema fiscale digitale. Con l'avvio ufficiale del progetto pilota a febbraio 2026, il Ministero dell’Economia (DGFiP) punta a eliminare…

Continue reading

Everything you need to know about electronic signatures

Solutions

16.08.2026

Everything you need to know about electronic signatures

Tutto (veramente tutto) quello che devi sapere sulla firma elettronica.

Continue reading