Overview
The quantum threat may be future-facing, but the transition deadline is already here.
Quantum computing will not break government systems overnight. But it can break the cryptography those systems rely on, and the transition away from vulnerable algorithms is now a policy-driven, deadline-backed program of work.
ASD guidance is explicit: traditional asymmetric cryptography, including RSA, DH, ECDH and ECDSA, should be phased out by the end of 2030. Agencies are expected to plan by the end of 2026, commence transition by the end of 2028, and complete transition by the end of 2030. In New Zealand, NZISM has warned that agencies may need to be prepared to transition away from current classical algorithms within the next 2–3 years.
The deadline is not theoretical. Without early discovery, agencies risk entering the transition window without a clear view of where vulnerable cryptography exists.
This matters now because “harvest now, decrypt later” makes PQC a current risk, not just a future technology issue. Sensitive government information collected today may remain valuable for years or decades, including classified material, citizen records, health information, justice data, financial information, critical infrastructure data, and other long-lived records.
The immediate challenge for most agencies is visibility and dependency: knowing where asymmetric cryptography is embedded, understanding reliance on vendors, shared platforms and procurement cycles, and turning general awareness into a practical, organisation-specific transition plan.
This course cuts through information overload and technical intimidation. Using plain-language explanations, public sector examples and ASD’s LATICE framework, participants build practical outputs including a first-cut CBOM, value / sensitivity assessment, triage table, vendor action list, executive briefing and one-page PQC transition plan.
Who Should Attend?
This course is designed for public sector professionals involved in cyber security, ICT infrastructure, enterprise architecture, digital risk, technology governance, and system transition planning.
CISOs and CIOs
Cyber security leads and security architects
Heads of ICT and ICT infrastructure leaders
Enterprise architects
ICT risk and digital strategy leads
Program directors and technology delivery leads
Governance and risk leads
Cloud, platform, identity, and PKI owners
Senior leaders responsible for digital resilience, critical systems, or technology transformation
Learning Outcomes
By the end of this course, you will be able to:
Explain quantum computing, CRQC and “harvest now, decrypt later” for non-technical stakeholders
Connect PQC readiness to ASD Guidelines for cryptography and the 2026 / 2028 / 2030 transition milestones
Identify where traditional asymmetric cryptography may exist across IT, cloud, PKI, identity, TLS, VPNs, code signing, OT / SCADA, embedded systems, shared platforms and vendor-managed services
Conduct a scoped discovery exercise and draft a first-cut Cryptographic Bill of Materials (CBOM) for one critical system or service
Assess long-lived data, system sensitivity, regulatory exposure, criticality and national infrastructure implications to prioritise transition activity
Build a prioritised PQC transition pathway using ASD’s LATICE framework, including procurement, vendor, supply-chain and crypto-agility actions
Translate PQC risk into decisions CIOs, CISOs, ICT infrastructure leaders, risk/governance teams and operational leaders can own, supported by a one-page transition plan and executive briefing
Online Training
Post-Quantum Cryptography for Government: From ASD Mandate to Action Plan
Session details
- Build PQC awareness without overwhelming non-technical leaders or turning the course into deep technical implementation
- Understand why PQC is a CIO, ICT infrastructure, enterprise architecture, procurement and business risk issue — not only a cyber security issue
- Use ASD / cyber.gov.au guidance as the reference point for transition planning and decision-making
- Move from general PQC awareness to a practical readiness plan with clear next steps, accountabilities and decisions required
- Improve visibility of cryptography across systems through CBOM concepts and scoped discovery exercises
- Understand vendor, shared-platform, procurement and supply-chain dependencies that can otherwise block transition
- Learn what “good” looks like in a public sector context, including critical infrastructure and long-lived sensitive data scenarios
- Produce tangible outputs participants can take back to their organisation, including a CBOM sketch, triage table, vendor action list, executive briefing and transition plan
Some familiarity with topic is recommended
Key Sessions
- Plain-language definitions and analogy sheet: qubits, superposition, entanglement, CRQC and PQC
- What quantum changes — and what it does not change
- CRQC explained through impact, not physics: from “billions of years” to “hours or days”
- Australia’s National Quantum Strategy and why agencies need credible, not vendor-led, understanding
- Link back to ASD / cyber.gov.au: why cryptography guidance is the operational anchor for the rest of the course
- Quick poll: what does your agency currently believe about quantum risk?
• How traditional asymmetric cryptography works — RSA, DH, ECDH and ECDSA at a glance
• Why a CRQC breaks it: Shor’s algorithm in one slide
• Harvest now, decrypt later: why long-lived, classified and sensitive data is already exposed
• What stays safe: symmetric crypto, hashing and why AES-256 remains strong
• NIST-standardised PQC algorithms — ML-KEM, ML-DSA, SLH-DSA — with a simple decision table mapping use cases to algorithm families
• ASD / cyber.gov.au Guidelines for cryptography: what agencies should stop using, what remains acceptable, and why the 2026 / 2028 / 2030 milestones matter
• ASD positions on QKD and PQ / traditional hybrid schemes
• Public sector examples: TLS, VPNs, code signing, PKI, identity, cloud services, shared platforms, OT / SCADA and vendor-managed systems
Practical Application — Exposure Reflection and Day 2 Handoff
Participants identify long-lived data beyond 2030, high-sensitivity systems, vendor dependencies, shared-platform dependencies, upcoming procurements and likely cryptography blind spots.
Output: a scoped system or service to use as the seed for Day 2 CBOM and LATICE planning.
Group Discussion — What Leaders Need to Do Differently
• Translate strategic concepts into decisions leaders can own or influence
• How CIOs, CISOs, ICT infrastructure leaders, enterprise architects, procurement teams and operational leaders engage each other
• How to avoid panic, complacency and solution confusion
Reflections and Closing Remarks
• Key takeaways from Day 1
• What changes tomorrow: CBOM, LATICE, vendor dependencies and transition planning
Targeted Playbook — Building the Transition Pathway
• LATICE: Locate · Assess · Triage · Implement · Communicate & Educate
• ASD / cyber.gov.au Guidelines for cryptography as the reference point for each LATICE stage
• What good looks like by end of 2026 — and what to do this quarter
• Conducting a discovery exercise to locate asymmetric cryptography across a defined system scope
• Where cryptography hides: cloud, applications, hardware, certificates, PKI, identity, TLS, VPNs, code signing, machine identities, OT / SCADA, embedded devices, shared platforms and vendor SaaS
• Introducing the CBOM: what it is, why it matters and how it supports ASD-aligned readiness
• Quality standard and public-sector example: what a usable CBOM should include for a common critical system
• Exercise: Produce a first-cut CBOM for one critical system or service
• Link to ASD guidance: assessing whether current cryptography and data exposure create transition risk
• Valuing systems and data: confidentiality, integrity, regulatory and legal exposure
• Long-lived data: what has a confidentiality requirement beyond 2030?
• Sector lenses: government services, health, justice, finance, councils, utilities and national critical infrastructure
• Exercise: Rate systems from Module 3.1 against a value / sensitivity matrix
• Link to ASD milestones: sequencing work for plan-by-2026, commence-by-2028 and complete-by-2030
• Prioritisation factors: sensitivity, external interactions, ease of transition, legacy interoperability, bespoke vs commodity systems, lifecycle / refresh cadence and shared-platform dependency
• Exercise: Build a triage table — which systems move first, which can wait, what decisions are needed and who needs to act
• Link to ASD recommendations: choosing practical, standards-aligned transition paths without running ahead of guidance
• Vendor-led, service-provider-led and in-house pathways
• Patching vs library swaps vs procurement-led replacement
• PQ / traditional hybrid schemes and crypto-agility as transition principles
• Procurement and vendor obligations: contract clauses, vendor assurance questions, whole-of-government platforms, shared services and supply-chain pressure beyond a questionnaire
• OT / ICS / SCADA case study: embedded and hard-to-replace environments
• Exercise: Identify one system from the triage table and outline its implementation and procurement pathway
• Link to ASD guidance: building a credible internal narrative around risk, milestones and responsibilities
• Bringing executives, boards, ministers and senior operational leaders along
• Talking to vendors: what to ask now and how to avoid buying the wrong solution
• Exercise: Draft a five-bullet executive briefing for a CIO / Secretary / senior leadership team
• Participants finalise a one-page PQC Transition Plan mapped to LATICE, ASD Guidelines for cryptography and the 2026 / 2028 / 2030 milestones
• Group share-back and Q&A
Meet Your Facilitator
Craig Costello
Professor, Queensland University of Technology
Professor Craig Costello is a cryptographer in the School of Computer Science at QUT, specialising in quantum-resistant encryption. For over a decade, his research has helped shape the global development of post-quantum cryptographic standards - the tools needed to secure systems against the coming wave of quantum-enabled threats. Before returning to QUT in 2025, he was a Principal Research Scientist at Microsoft Research in the USA, where he led work on deploying post-quantum cryptography into real-world protocols and systems. His mission now is to help Australian companies and government agencies navigate the cryptographic upgrade mandated by national policy and coming into force by 2030.
Register Today
Join this training for professionals working within the Public Sector
Extra Early Bird
Ends 28 Aug
$A 795
per person + tax $400 savingEarly Bird
Ends 25 Sep
$A 995
per person + tax $200 savingRegular
Ends 10 Nov
$A 1195
per person + taxFor group or payment enquiries or custom training solutions, please contact [email protected]
Can't see what you need?
Download our training catalogue to review all available topics