In version 1.0 of the Quantum-Safe Migration Handbook jointly released this month by the Cybersecurity Agency of Singapore (CSA), GovTech, and Infocomm Media Development Authority (IMDA), the following requirements have been set for Critical Information Infrastructure (CII) owners:
- By 31 Mar 2027: Submission of CII owner’s quantum-safe migration plan to CSA.
- From 1 Jan 2028: Procurement and implementation of new CII computer and computer systems that have a digital component should either (a) support quantum-safe algorithms/ technologies; and/or (b) be quantum-safe ready.
- By 31 Dec 2031: Completion of quantum-safe migration across CII computer and computer systems, i.e. vulnerable cryptography should no longer be used.
CSA, GovTech, and IMDA are developing detailed guidance to support CII owners in meeting these milestones, according to the document.
CII are computer systems directly involved in the provision of essential services, as defined by Singapore’s Cybersecurity Act. The CII sectors are: Energy, Water, Banking and Finance, Healthcare, Transport (which includes Land, Maritime, and Aviation), Infocomm, Media, Security and Emergency Services, and Government.
The draft release, version 0.1, was released in October 2025 for public consultation. Version 1.0 incorporates feedback received during the public consultation period. Revisions have been made to address comments from stakeholders and to align with the latest developments in quantum-safe cryptography standards.
The new version further identifies “no-regret moves” across each domain that can be first stepping stones:
- Risk Assessment: Identify your most critical systems and run cryptographic asset discovery on those first. This helps to scope down the problem, rather than spend effort and resources inventorising across all systems at the outset.
- Governance: Identify who is accountable for quantum-safe migration decisions. This is the person who owns the outcome and approves the plan. Clear ownership upstream will facilitate execution later.
- Technology: For your priority systems, identify which quantum-safe algorithms can replace the vulnerable ones currently in use. Understand performance trade-offs before committing.
- Training & Capability: Brief senior leadership on the quantum threat now. This will help them to understand and approve the resources and timelines.
- External Engagement: Contact your key vendors now and ask for their post-quantum roadmaps. This will inform your migration timelines and approaches.
Version 1.0 of the Handbook also comes with the following algorithm recommendations, with the list to be updated as more options emerge:

The document was developed by CSA, GovTech, IMDA, in collaboration with the following industry partners: Accenture, Amazon Web Services, Cisco, Deloitte & Touche LLP, IBM, PQStation, The Association of Information Security Professionals (AiSP), along with “valuable feedback” shared by the following organisations: Ensign InfoSecurity Pte Ltd, Google, NCS, PQCee, Singtel.

