By: Medha Prasanna
When it comes to cybersecurity, energy and utilities are among the most heavily targeted sectors of critical infrastructure. The threats are only intensifying. By early 2026, the average organization worldwide faced 2,086 cyberattacks a week, and AI is making it easier for state-backed hackers to target power plants and water systems. In August, as ransomware incidents hit a global record, attacks on utilities doubled, the sharpest increase of any sector, albeit from a small base. While the operational technology that physically run power plants and substations are meant to be sealed off from the internet (air-gapped), they are often not. Among nearly a million industrial operational technology devices studied, 12% carried known exploited vulnerabilities, and 40% of the organizations had some of these devices insecurely exposed online. The sector already struggles to defend these assets against today’s attackers, let alone tomorrow’s quantum-enabled ones. That is why the sector will meet quantum as a threat to its infrastructure well before it confronts quantum as a meaningful demand on the grid.
Early policy debates treated quantum as the energy sector’s next AI, a new source of load driven by cryogenic cooling and the need for highly stable power. But rapid advances in quantum hardware have brought forward Q-Day, the point at which a quantum computer can break the public-key cryptography securing most digital systems, which is now considered plausible by 2030. Governments are now setting deadlines to migrate to post-quantum cryptography (PQC), algorithms designed to withstand quantum-enabled attacks. The United States has ordered its most sensitive federal systems to switch to PQC encryption by the end of 2030. The European Union has set the same date for high-risk systems, which includes energy systems under its cybersecurity law. India’s National Quantum Mission has proposed the most ambitious target of the three, recommending that critical sectors, including power, migrate by 2029. Only the U.S. deadline is binding, and it covers federal systems, not the privately owned utilities that run most of the American grid. The EU and Indian timelines are only recommendations. None yet binds the companies that operate the grid.
The threats are not waiting for Q-Day. The U.S. National Security Agency has warned that adversaries may already be collecting encrypted data of long-term value to decrypt once quantum computers mature, a tactic known as “harvest now, decrypt later.” For a power system, the graver risk is to authentication. Digital control equipment installed today can remain in service for 20 to 40 years, so its cryptography will likely be obsolete long before the hardware is retired. Migration is also slow. A 2025 study estimated that realistic PQC migration takes five to seven years for small enterprises, 8 to 12 for mid-sized ones, and 12 to 15 or more for large ones, which include most major utilities. A large utility starting now would not finish until the late 2030s, years after Q-Day may have arrived.
This becomes a global challenge because even though utilities seldom cross borders, their supply chains almost always do. Five firms account for roughly 50% of the global power Supervisory Control and Data Acquisition (SCADA) market, the systems utilities use to monitor and control their networks. Public procurement is one of the few policy levers that can reliably shape what vendors build. The U.S. federal government’s procurement is a signal to the wider market, and the EU roadmap explicitly asks suppliers to align their product roadmaps with its deadlines. If the largest buyers aligned their timelines and procurement rules, vendors would build to one standard that could benefit smaller markets.
Settling on that standard is as much a geopolitical question as a technical one. The post-quantum encryption standards published by the U.S. National Institute of Standards and Technology (NIST) in 2024 are fast becoming the global reference, and India’s roadmap draws on them. Beijing, however, is developing its own standards outside the NIST process, and Washington is watching closely. In a June 2026 executive order, U.S. President Donald Trump directed the U.S. State Department to encourage foreign governments and industry groups to adopt NIST-standardized algorithms. This competition extends beyond standards to the infrastructure itself. China’s State Grid Corporation reports investing in and operating 13 major grid projects in ten countries and regions, among them the Philippines, Brazil, and Chile. As emerging economies expand their grids, the suppliers and investors they choose will decide which cryptographic standard protects that infrastructure for decades.
Closing these gaps means treating post-quantum readiness as infrastructure planning rather than a deferred information technology upgrade. In the United States, that begins with binding requirements for the grid itself. The bipartisan Quantum-GUARD Act, introduced in August, points the way. Internationally, the United States, EU, and India, who are among the largest electricity markets with published timelines, could work toward aligning PQC requirements for grid equipment. Externally, in terms of exports or outbound investments, quantum-safe design should be a condition for funding grid projects.
As countries race to connect renewable generation, expand transmission, and meet surging demand from data centers, electricity grids are being built at unprecedented speeds. Every substation and control system commissioned in this buildout will still be running when quantum computers mature. Building quantum-safe cryptography while equipment is being designed and procured is far easier than retrofitting it later.
Medha Prasanna is a Program Coordinator and Junior Fellow for the Energy & Climate program at ORF America.

