JAKARTA — Indonesia is accelerating preparations to protect government systems, critical infrastructure and sensitive data from a cybersecurity threat that has not yet fully materialized: quantum computers powerful enough to compromise widely used forms of public-key encryption.
The move places Southeast Asia’s largest economy within a widening international effort to transition toward post-quantum cryptography (PQC) — cryptographic algorithms designed to remain secure against attacks from both conventional and future quantum computers.
Indonesian government officials, cybersecurity authorities, state telecommunications company Telkom Indonesia, academics and industry representatives met on August 6 to discuss preparations for the post-quantum era. Priorities include developing a national PQC migration roadmap, identifying highly sensitive data requiring early protection and strengthening coordination across government. Participants also proposed creating a National Quantum Center focused on research, standardization, talent development and technology implementation.
According to Indonesia Business Post, Indonesia’s National Cyber and Encryption Agency, BSSN, has established a National Task Force for Post-Quantum Cryptography Migration. Telkom says BSSN has also prepared a phased migration framework covering cryptographic asset inventories, risk assessments, prioritization, migration planning and implementation across ministries, state-owned enterprises and strategically important sectors.
Telkom is also supporting research and development around quantum-safe infrastructure, including applications for financial payments, digital identities, electronic certificates, cloud infrastructure and secure communications.
Why governments are moving before the threat arrives
Today’s quantum computers are not known to be capable of breaking the cryptographic systems securing much of the global digital economy. But sufficiently powerful future machines could threaten widely deployed public-key systems such as RSA and elliptic-curve cryptography.
That has turned the transition into a long-term infrastructure challenge rather than one governments can safely postpone.
One concern is “harvest now, decrypt later”: adversaries could collect encrypted information today and retain it until future quantum computers are capable of decrypting it. The risk is particularly significant for government, financial, defense and other data that must remain confidential for years.
The challenge is compounded by the difficulty of replacing cryptography across sprawling digital systems. The U.S. National Institute of Standards and Technology (NIST) says organizations first need to identify where quantum-vulnerable algorithms are embedded across hardware, software and services before developing prioritized migration plans.
The global migration is accelerating
Indonesia’s preparations come as several major economies move from research toward implementation.
The United States finalized its first three major post-quantum cryptography standards through NIST in August 2024 and has urged organizations to begin transitioning. Washington has since accelerated its plans, with new executive orders calling for key federal systems to move toward post-quantum cryptography around the beginning of the next decade as the country simultaneously pushes development of more powerful quantum computing capabilities.
The United Kingdom has established its own transition milestones. The National Cyber Security Centre recommends organizations complete cryptographic discovery and initial migration planning by 2028, move their highest-priority systems by 2031 and complete broader migration by 2035.
France is applying regulatory pressure even earlier. Its cybersecurity agency, ANSSI, announced in June that it intends to stop certifying security products that do not incorporate quantum-resistant encryption beginning in 2027, a policy designed to accelerate adoption across government and critical infrastructure.
China is also moving toward post-quantum standards. Reuters reported in March that leading Chinese cryptographer Wang Xiaoyun expects national standards to emerge within roughly three years as the country increases investment in quantum technologies. Finance and energy are among the sectors where adoption could expand, although the timeline is an expert projection rather than an official government deadline.
The transition is also extending into global finance. A Europol-linked financial security forum has warned banks that they should begin preparing for quantum risks rather than wait for quantum computers capable of breaking existing encryption to arrive.
Taken together, these moves show that post-quantum security is shifting from a specialized technical issue to a broader question of national infrastructure resilience.
Digital sovereignty enters the quantum era
For Indonesia, the issue reaches beyond cybersecurity.
Government services, banking, communications, digital identity systems and commercial activity increasingly depend on interconnected digital infrastructure. Indonesia has separately made technology sovereignty a national policy priority, with Telkom promoting domestic capabilities in sovereign cloud infrastructure, artificial intelligence and cybersecurity.
Post-quantum readiness fits naturally within that broader strategy.
The proposed National Quantum Center could give Indonesia a platform not only for cybersecurity preparation but also for domestic research, standards development and talent formation. Indonesian officials and industry leaders have increasingly framed quantum readiness as part of the country’s ability to protect strategic data while remaining competitive in emerging technologies.
For a country of more than 280 million people with a rapidly expanding digital economy, the scale of the transition could be significant. Banks, telecommunications networks, government databases, cloud infrastructure, digital identity platforms and critical industries may ultimately require assessment and, where necessary, migration.
What governments should watch
The next test will be whether Indonesia converts its emerging strategy into concrete national policy.
Key questions include whether Jakarta establishes formal PQC migration deadlines; which government, defense and critical-infrastructure systems receive priority; whether requirements eventually extend to regulated industries; and how closely Indonesian standards align with international frameworks.
Governments elsewhere should also watch Indonesia as a potential indicator of how major emerging economies approach the transition. The U.S., UK and France are already establishing standards, timelines and certification requirements, but countries with rapidly expanding digital economies face the additional challenge of upgrading existing infrastructure while continuing to build new systems.
International interoperability will be particularly important. Banking, telecommunications, cloud infrastructure and cross-border government communications depend on systems operating across jurisdictions, making incompatible cryptographic standards a potential source of both security and economic friction.
What businesses should watch
For businesses, post-quantum cryptography is moving from a theoretical technology risk toward a procurement, compliance and infrastructure issue.
Banks, telecommunications companies, cloud providers, data-center operators and technology vendors should expect governments and regulators to increasingly ask where vulnerable cryptography exists within their systems and how quickly it can be replaced.
France’s decision to incorporate quantum resistance into security-product certification demonstrates how PQC could eventually become a market-access requirement for companies supplying governments and critical infrastructure. Similar requirements elsewhere could affect procurement standards, cybersecurity certifications and technology contracts.
Companies should therefore pay close attention to crypto-agility — the ability to identify and replace cryptographic systems as standards evolve. Organizations holding sensitive information with a long confidentiality lifespan face greater urgency because data intercepted today could still be valuable when more capable quantum computers emerge.
For technology providers, the transition also creates a commercial opportunity. Demand is likely to grow for quantum-safe cybersecurity, network infrastructure, cloud services, digital identity systems, migration consulting and cryptographic assessment tools as governments move from planning to implementation.
The quantum transition has already begun
The central reality of the post-quantum transition is that governments do not need to know exactly when a cryptographically relevant quantum computer will arrive to know that preparation must begin.
The United States, United Kingdom, France, China and now Indonesia are approaching the challenge through different combinations of standards, timelines, research and infrastructure investment. But the direction is increasingly clear: quantum resilience is becoming part of national cybersecurity, economic security and technological sovereignty.
For Indonesia, the challenge will be turning early coordination into implementation — establishing standards, identifying vulnerable systems, developing domestic expertise and ensuring that government and critical infrastructure can migrate without disrupting an increasingly digital economy.
The implications extend well beyond Indonesia. As quantum capabilities advance, governments will increasingly shape the rules and timelines for migration, while businesses will be responsible for implementing much of that transition across the infrastructure underpinning finance, communications, cloud computing and digital commerce.
The quantum threat may still lie in the future. The race to secure the systems that will have to survive it has already begun.
RELATED STORIES:
Follow SDG News on LinkedIn







