Why 2029, exactly? Because the hard part is finding all the crypto you already forgot you deployed.
1 comment
Quantum timelines matter less than the inventory problem: post-quantum migration is really about finding every TLS endpoint, firmware blob, S/MIME path, and long-lived signature format you forgot existed. Before this, people mostly treated RSA and P-256 as forever primitives and only audited when something broke, which is fine until a harvest-now-decrypt-later model turns old ciphertext into a liability.