CFOtech UK - Technology news for CFOs & financial decision-makers
United Kingdom
Atsign adds post-quantum crypto to SDKs for legacy data

Atsign adds post-quantum crypto to SDKs for legacy data

Thu, 27th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Atsign has added NIST-approved post-quantum cryptography to its core software development kits, aiming to help organisations protect long-lived data from quantum-era decryption risks.

The integration gives developers a way to add post-quantum protection across new applications, existing systems and legacy environments without rewriting application code. It applies to software built directly on Atsign's SDKs and to connections handled through its NoPorts product.

The move responds to growing concern in cybersecurity over so-called harvest-now, decrypt-later attacks, in which adversaries collect encrypted data today and store it until quantum computers are powerful enough to break current public-key cryptography.

Current asymmetric cryptographic methods used for digital signatures, digital identity and key exchange remain beyond the reach of today's conventional computers. Security agencies and governments, however, have increasingly warned that organisations should prepare well before practical quantum attacks become possible, particularly where data must remain secret for many years.

Atsign's latest update embeds algorithms approved by the US National Institute of Standards and Technology into the SDK layer, rather than leaving engineering teams to retrofit cryptographic changes into each application individually. The approach is intended to reduce the effort needed to move towards post-quantum security, especially for businesses with older software estates.

Migration challenge

Post-quantum migration is widely seen as a long-term operational problem as much as a technical one. Organisations must identify where vulnerable cryptography is used across applications, devices and infrastructure, then test replacements without breaking existing services.

Atsign is positioning its software as a shortcut through that process. Customers can use the updated SDKs to build new applications, retrofit protection into existing software, or secure legacy systems that are unlikely to be rebuilt.

That last category is especially relevant for sectors that depend on old but still critical technology. NoPorts can provide authenticated, end-to-end encrypted access to existing services without exposing inbound ports or altering the underlying application, and those connections can now also be covered by post-quantum cryptography.

For companies with regulated data or long retention periods, the issue is becoming harder to defer. Guidance from agencies including NIST, the US Cybersecurity and Infrastructure Security Agency, the US National Security Agency and the UK's National Cyber Security Centre has pushed organisations to start planning migration paths well ahead of any practical cryptographically relevant quantum computer.

Several government strategies now set target timeframes for transition. In both the US and the UK, official roadmaps point to the first half of the next decade as the period by which broad migration work should be well advanced or completed across many public sector systems.

Customer response

Aparna Rayasam described the update as a way to make post-quantum protection part of the platform rather than a separate engineering project.

"At its core, this integration makes anything built on our platform quantum-safe by default. Achieving post-quantum readiness shouldn't require multi-year application overhauls. By embedding NIST-approved algorithms directly into our SDKs, we're delivering true crypto agility so engineering teams can focus on innovation rather than complex cryptographic mechanics," said Aparna Rayasam, Chief Executive Officer, Atsign.

The company also cited a customer example from NeuroVitals, a mental wellbeing business that uses the platform.

"Built-in post-quantum security will remove a significant burden for our development and security teams. What we really want to focus on is delivering and securing new capabilities for our customers, and this means we can do just that," said Deacon.

Open development

Atsign said it has developed its post-quantum work in the open, with its roadmap, architectural choices and code progress available publicly through its software repository. That may matter to buyers looking to assess implementation details rather than rely only on vendor claims, especially in an area where standards, interoperability and migration methods remain under close scrutiny.

The wider market for post-quantum migration remains fragmented. Large technology groups and infrastructure providers have begun setting internal deadlines, but adoption speeds vary widely across sectors depending on risk exposure, technical debt and regulatory pressure.

Financial services, healthcare, public sector bodies and operators of critical infrastructure are among the organisations likely to face the strongest pressure to act early because of the sensitivity and shelf life of their data. European rules such as NIS2 and DORA have also raised expectations around modern encryption and cryptographic inventory management.

For software suppliers, that creates an opening to package post-quantum protection into development tools and connectivity products rather than sell migration as a bespoke consulting exercise. Atsign's announcement reflects that shift, with the company arguing that cryptographic change should happen below the application layer wherever possible.

Google has set a 2029 timeline for its own transition to post-quantum cryptography.