PhysicsarXiv
Heuristic editor, no API keyVerdict: NotableCost of Delay for Post-Quantum Migration: Putting Classical and Harvest-Now-Decrypt-Later Risk on One Ordered List
Organisations deciding which assets to migrate to post-quantum cryptography first, and how that work competes with a backlog of classical findings, lack a common unit: post-quantum scores are dimensionless and…
Key numbers
- 91% of the uncertainty in
Caveats
- Preprint; not yet peer reviewed.
VerdictWorth a reader's time today.
Abstract
Organisations deciding which assets to migrate to post-quantum cryptography first, and how that work competes with a backlog of classical findings, lack a common unit: post-quantum scores are dimensionless and quantum-only, while classical risk is annualised loss. We express both threats as a cost of delay in currency per year on the same asset. The quantum term is the rate at which deferring migration commits irreversible harvest-now-decrypt-later loss, computed from required confidentiality duration, recordable traffic share and data turnover, using a quantum-arrival law fitted in closed form to published expert anchors. A competing-risks factor couples the two terms so the same loss is not counted twice. We prove that the construction is not a weighted sum of a classical and a quantum score, give a dominance threshold on the classical hazard that is independent of asset value, and show that the induced order is optimal for sequencing work under constant loss rates. We verify the implementation by simulation, adaptive quadrature and a second implementation. On four public systems with parameters assumed from public documentation, the quantum term reorders the asset list beyond input uncertainty for one system only (signal-to-noise 1.36 against 0.14-0.46), moves specific long-lived, quiet, recordable assets decisively, and otherwise changes magnitudes. Asset value and turnover explain 73-91% of the uncertainty in the quantum term; the arrival date explains 3-17%. The case studies are illustrative and are not validated against outcomes.
The editor's rubric
| Dimension | Level | Weight | What that level means |
|---|---|---|---|
| Leverage | ███░░ 3 | 18% | A method or resource many groups across the field will adopt within a year. |
| Magnitude | ███░░ 3 | 20% | Large gain: roughly 2x, or a clear new state of the art on a hard, unsaturated problem. |
| Evidence | ████░ 4 | 22% | Strong: large scale, preregistered, independently replicated, or a well-powered randomized trial. |
| Novelty | ██░░░ 2 | 22% | A new combination of known ideas. |
| Trajectory | ██░░░ 2 | 10% | Some room to improve with obvious engineering. |
| Stakes | ██░░░ 2 | 8% | Benefits a professional community (practitioners, clinicians, engineers). |
Editor’s rationale
Heuristic triage from title and abstract text only, not a reading of the paper. Cues found: breadth (many tasks); gains (versus baseline); verification (false alarm rate, error bars, experimental validation).
How the score was computed
- Merit
- 5.6 / 10
- Adjusted merit
- 4.7 / 10
- Attention
- 0%
- Freshness
- 86%
- Citations0 (reference 20, via semantic-scholar, Oct 8, 2026, 07:29 UTC)