Singapore Tells Its Critical Infrastructure to Finish Quantum-Safe Migration by 2031
Table of Contents
July 16, 2026 — The Cyber Security Agency of Singapore (CSA), with GovTech and the Infocomm Media Development Authority (IMDA), published version 1.0 of the Quantum-Safe Migration Handbook and its companion Quantum Readiness Index, closing a public consultation that ran from October 23 to December 31, 2025.
The Handbook sets out three dated milestones that CSA describes as requirements for owners of Critical Information Infrastructure. CII owners are to submit a quantum-safe migration plan to CSA by March 31, 2027. From January 1, 2028, newly procured and implemented CII computers and computer systems with a digital component should either support quantum-safe algorithms or be quantum-safe ready. By December 31, 2031, migration across CII systems should be complete and vulnerable cryptography should no longer be in use. CSA, GovTech and IMDA say detailed guidance to support those milestones is still in development.
Clear dates, less clear legal footing. The Handbook’s own disclaimer says it is not mandatory or prescriptive, and the 2028 and 2031 milestones use “should.” Under Singapore’s Cybersecurity Act, binding obligations on CII owners flow through Codes of Practice or written directions from the Commissioner, and I found no published instrument carrying these three dates. CSA may have issued or intend to issue one separately; the public record as of early August 2026 does not confirm it. That ambiguity does not make the dates commercially irrelevant. A supervisory expectation aimed at designated CII operators will influence plans, budgets and procurements whether or not the enforcement mechanism has been formally clarified.
That places Singapore among a small group of jurisdictions publishing a fixed completion milestone for critical-infrastructure cryptographic migration, and gives its designated operators roughly eight months to submit a plan. Singapore’s Cybersecurity Act designates CII across 11 sectors: energy, water, banking and finance, healthcare, land transport, maritime, aviation, infocomm, media, security and emergency services, and government.
The Handbook’s algorithm table deprecates RSA, Diffie-Hellman and elliptic curve cryptography at all key sizes. It recommends the NIST-standardized ML-KEM (formerly CRYSTALS-Kyber), ML-DSA (formerly CRYSTALS-Dilithium) and SLH-DSA (formerly SPHINCS+), and restricts the stateful hash-based schemes LMS and XMSS to firmware signing. On symmetric cryptography it deprecates AES below 128-bit keys and recommends AES-256. Hash functions with output below 256 bits are deprecated.
Both documents share five domains: Risk Assessment, Governance, Technology, Training and Capability, and External Engagements. Each domain carries one no-regrets move. Run cryptographic discovery on crown-jewel systems before inventorying everything. Name the person who owns the outcome. Identify replacement algorithms for priority systems and understand the performance cost before committing. Brief senior leadership. Ask key vendors for their post-quantum roadmaps.
The Quantum Readiness Index is a self-assessment questionnaire hosted at go.gov.sg/qri. It scores ten objectives across the five domains on a four-level scale adapted from ISACA’s Capability Maturity Model Integration, running from L0 (not started) to L3 (operationalised and continuously improved), and returns a PDF report with recommended next steps. A*STAR, Accenture, Deloitte, evolutionQ, SGTech, SpeQtral and the World Economic Forum were consulted on it. The Handbook was developed with Accenture, Amazon Web Services, Cisco, Deloitte & Touche, IBM, PQStation and the Association of Information Security Professionals, with additional feedback from Ensign InfoSecurity, Google, NCS, PQCee and Singtel.
On technology options, the Handbook puts post-quantum cryptography first and treats quantum key distribution as a complementary control for high-security point-to-point links, noting that QKD supplies neither digital signatures nor authentication without pre-shared keys or PQC signatures.
My Analysis
The Handbook is a good document. It is clearer than the October draft, better organised, and in places more honest about uncertainty than most government guidance manages. None of that is the news.
Three lines in a shaded box on page 25 convert quantum risk from an advisory topic into a dated plan-submission expectation for eleven sectors of the Singapore economy. I have argued for two years that the deadlines matter more than the predictions, and that the useful question for a CISO is not when a cryptographically relevant quantum computer arrives but which regulator, insurer, or customer has already put a date on the calendar. Singapore has now put three.
The middle date is the one that reprices things
Everyone will report the 2031 completion deadline. The clause that will actually move money is January 1, 2028.
From that date, a new CII system with a digital component should support quantum-safe algorithms or be quantum-safe ready. If CSA applies that milestone as an enforceable procurement condition, it functions as a market-access gate for products procured as, embedded in, or directly supporting designated CII systems, and it lands on suppliers roughly seventeen months from publication. HSM vendors, PKI providers, network OEMs, identity platforms, SCADA integrators and cloud services forming part of a designated CII environment all fall inside the perimeter. Prudent procurement teams will pull the date forward into 2027, because a contract signed before the gate can create a stranded asset or a future exception. In practice the gate binds well before it opens.
This is how national deadlines actually propagate. Singapore is a small market with an outsized supplier base: the vendors serving its CII sectors are the same vendors serving critical infrastructure across the region and, in many cases, globally. A requirement written for eleven Singapore sectors becomes a roadmap item in Munich and San Jose, because vendors frequently prefer common product baselines across jurisdictions. That transmission effect is the same one I described in Quantum Ready as trickle-down compliance, and it is why an organisation with no Singapore exposure whatsoever should still read page 25.
There is a second, less comfortable reading of that date. A procurement gate in 2028 assumes the products exist. The base ML-DSA and ML-KEM profiles for X.509 and CMS were published as IETF standards-track RFCs in October 2025 and March 2026, so the standards foundation is further along than the Handbook acknowledges when it advises deferring large-scale migration until the CMS work is formally established. But hybrid and composite profiles are still developing, practical support across libraries, certificate tooling and HSMs remains uneven, and algorithm-level CAVP validations should not be confused with full FIPS 140-3 module validation, which remains a separate deployment bottleneck. The US executive order itself directs NIST to accelerate that process. CSA is asking buyers to demand something the supply chain is in the middle of building. That is a defensible way to force a market. It is also a way to generate vendor attestations that mean less than they appear to, which is the argument for writing crypto-agility into the contract instead of a product name.
How 2031 sits against everyone else
The UK’s NCSC set 2028, 2031 and 2035 as discovery, high-priority migration and full migration, which I covered when the timelines were published. The EU’s coordinated roadmap runs first steps by the end of 2026, high-risk use cases by 2030, and everything else by 2035. The United States still retains a broader 2035 horizon for the remaining federal estate, but Executive Order 14412 (signed June 22, 2026) now requires federal high-value assets and high-impact systems to move key establishment by the end of 2030 and digital signatures by the end of 2031, with CNSA 2.0 separately driving national security systems on a tighter track. Canada’s federal non-classified roadmap follows a similar 2031/2035 shape. Australia’s ASD recommends completion by 2030 across organisations, with additional government requirements flowing through the ISM. India’s official national strategy proposes full PQC for CII by 2029, which is earlier than Singapore, though that date is not yet a binding regulatory obligation.
So Singapore’s 2031 is not the earliest date in the field. Its distinctive feature may be less the date itself than the attempt to apply one timetable across a defined population of designated CII operators who already file incident reports and submit to audits under the Cybersecurity Act, though the public enforcement instrument behind the quantum milestones has yet to be confirmed. Many national publications remain cross-economy recommendations or government-wide roadmaps; this one is aimed at specific operators. I maintain a running comparison of these regimes in the Global PQC Migration Timelines deep dive.
Which raises the arithmetic problem. Working backwards from December 2031, and assuming the plan filed in March 2027 is worth the paper, discovery has to be substantially done during 2027 and execution has to fit in 2028 through 2031. Roughly four years to remove RSA and ECC from estates that took three decades to accumulate. For scale: even the narrower SHA-1 deprecation consumed years across PKI hierarchies, code signing, browsers, embedded devices and legacy applications. NIST began pushing that transition in the mid-2000s and is still completing the final retirement. PQC is broader: it changes key material, signature sizes, protocol messages, hardware dependencies and interoperability assumptions. Singapore is asking for a harder transition in less time.
I do not think that date holds for every operator. The forthcoming detailed guidance will need an explicit exception or waiver process for systems that cannot be migrated safely by 2031. The CII Code of Practice already provides a waiver mechanism for provisions of the Code, but the public material does not establish whether that mechanism applies to the quantum-safe milestones. In my experience, a deadline that produces 80 percent migration and 20 percent documented exceptions by 2031 is still a vastly better outcome than the alternative, which is the 2035 crowd discovering in 2033 that they never did discovery. Ambitious dates that slip beat comfortable dates that never start.
Three places the guidance slips
The Handbook is careful almost everywhere, with three exceptions.
Start with the Preface, which contains the only sentence in either document that reads like it came from a vendor deck. On Q-Day, CSA asserts that “Expert consensus place it within 5–10 years,” with more conservative estimates at 10 to 20. There is no citation, and there is no such consensus. The most systematic longitudinal measurement we have is the Global Risk Institute’s Quantum Threat Timeline Report, whose 2025 edition surveyed 26 experts and put the probability of a CRQC within ten years at 28 to 49 percent, rising to 51 to 70 percent at fifteen years. I analysed that report in April. A probability range that tops out just below 50 percent is not a consensus that Q-Day falls inside ten years, and the difference is not pedantic: one is a quantified risk estimate, the other sounds like a settled prediction. The sting is that Michele Mosca, co-founder and CEO of evolutionQ, co-authored that very report, and evolutionQ is listed on the QRI’s consultation roster. CSA had the right number one document away.
I want to be careful here, because this is exactly the terrain where the quantum panic industry operates and where I spend a lot of my time pushing back. The rest of the Handbook does not need that sentence. Its actual argument for urgency, which is that migration takes years and harvest-now-decrypt-later exposure accrues daily, stands on its own without an unsupported expert-consensus claim propping it up. Delete the sentence and the document gets stronger.
The second slip is Grover’s algorithm. Page 7 gets it right, flagging that the algorithm’s practical effectiveness against symmetric primitives is debated given the memory and hardware an attack would require. Page 18 then contradicts page 7. In the family-office worked example, the Handbook describes Grover’s as reducing AES-128 to roughly 64-bit effective security and treats that as a compounding risk alongside Shor’s algorithm breaking the RSA/ECC key exchange. The asymptotic square-root statement is correct. Treating it as practical equivalence to 64-bit classical security is not, because Grover’s algorithm is inherently sequential and parallelises terribly. NIST uses AES-128 key recovery as its Category 1 post-quantum security benchmark and explicitly accounts for realistic circuit depth and parallelisation constraints. In Filippo Valsorda’s gate-cost model, published in April, a Grover attack on AES-128 costs approximately 4.3 x 10^23 times more than using Shor’s against P-256. I laid out the full argument, and my one small disagreement with the strongest version of it, in Grover’s Algorithm vs AES.
That confusion carries into the algorithm table, which deprecates only AES below 128 bits (correct), then recommends AES-256, and the surrounding prose hardens that recommendation into an instruction to migrate. A CII owner reading quickly will conclude that AES-128 must be retired by 2031. AES-256 is a sensible default for new high-assurance designs where the marginal cost is low, and other policy requirements may independently justify it. But wholesale AES-128 replacement should not displace the urgent work of finding and migrating RSA, Diffie-Hellman and ECC, which is where the actual quantum threat sits.
The third gap is the one I flagged in October and CSA has not closed: there are no cost benchmarks. Not a percentage of security budget, not a per-system range, not a headcount ratio, not even an order of magnitude. That was a defensible omission in a voluntary consultation draft. It is harder to defend in a document that expects a migration plan by March 2027, because a plan without a number is a wish, and the CFO reading it will treat it accordingly. Once the first plans arrive, CSA will be better placed than almost any regulator to collect anonymised cost and resource benchmarks across sectors. Its implementation partners may also have useful project data. Publishing even broad ranges in the next revision would do more for actual migration progress than another domain would.
What version 1.0 fixed
Credit where it is due, and this is the part I did not expect.
When I reviewed the consultation draft in October, my main technical criticism was that it mentioned both QKD and PQC without telling anyone when either made sense. Version 1.0 answers the question directly. PQC is the primary migration path. QKD is a complementary control for high-security point-to-point links where the physical infrastructure investment is justified, and the Handbook then enumerates the limitations that QKD vendors tend to leave off the slide: no signatures, no authentication without pre-shared keys or PQC signatures, a mandatory authenticated classical channel or the whole thing falls to a man-in-the-middle, trusted relay nodes that each have to be secured individually, side-channel exposure in the physical setup, and standards for testing that ISO and ETSI are still writing.
Read that against Singapore’s own investments. This is a government that backed the National Quantum-Safe Network through its Quantum Engineering Programme, whose central bank ran a QKD sandbox for financial institutions, and which has SpeQtral, a domestic QKD company, sitting on the QRI consultation roster. Writing that QKD is not a PQC replacement, in a document its own national champions helped shape, is genuine institutional discipline. I have read national quantum strategies that could not manage a tenth of it.
The HNDL treatment shows the same restraint. Rather than asserting that everything is being harvested, the Handbook says plainly that scepticism about the scale of HNDL is reasonable, that indiscriminate interception and decades of storage carry substantial overhead, and that the capability therefore sits mainly with well-resourced actors who will prioritise targets with the longest payoff. Then it names those targets: critical infrastructure configuration and authentication traffic, identity and biometric data, legal archives. That is how you write about a threat you take seriously without inflating it.
One more thing changed between drafts, and it made me laugh. The second threat-modelling walkthrough in the consultation draft followed a customer making an online purchase. In version 1.0 it follows a family office wealth management platform holding ownership records, trust structures and asset allocation documents. Somewhere between October and July, someone in Singapore decided the worked example should reflect the actual clientele. Fair enough.
While I am being petty: the closing section announces that three things remain true and then lists two. I have shipped enough documents in the last week before release to know exactly how that happens.
What to do before March
If you own designated CII in Singapore, the plan due date is the only date that should be on your slide this quarter. Start the crown-jewel discovery now, before the plan is written, because the plan is unfalsifiable without it, and CSA will be reading eleven sectors’ worth of these side by side. Put the January 2028 procurement gate into your contract renewal calendar today, since every agreement you sign between now and then either helps you or becomes an exception you will be explaining in 2031. And send the vendor letter this month; the Handbook’s own no-regrets move for External Engagements is exactly that, and vendor response latency is the variable you control least and depend on most.
Vendors are on the shorter clock. If you sell into Singapore CII and have no published post-quantum roadmap, you have roughly seventeen months to acquire one, and your customers are about to start asking in writing.
If neither applies to you, the Singapore documents are still the best free starting point I have seen from a national regulator, and the QRI is a usable self-assessment instead of a maturity model that flatters whoever fills it in. Pair it with the PQC Migration Framework for the execution detail the Handbook deliberately leaves out, and with my practical steps to quantum readiness if you are starting from zero.
Nothing in these two PDFs changes the engineering picture. No qubit was added, no logical error rate improved, no line on the CRQC Quantum Capability Framework moved. The Q-Day estimate is exactly where it was on July 15. What changed is that for eleven sectors of one economy, the physics forecast stopped being the operative clock. A regulator-set milestone replaced it.