The post-quantum transition has started. Learn how secure, upgradeable access-control infrastructure can protect clients today and preserve their options for tomorrow.
Quantum computers are not currently opening locked doors. The practical risk is that organisations keep physical access systems for a decade or more, while the cryptography behind cloud connections, mobile credentials, device certificates and software updates is entering a major transition. An access-control platform installed in 2026 could still be operating well into the 2030s. If it cannot accept new algorithms, keys or firmware, today’s purchase may become tomorrow’s forced replacement.
For solution providers, this creates a timely advisory opportunity. You can help clients separate genuine post-quantum exposure from marketing noise, retire weaknesses that are exploitable now and build a migration path that does not require every credential, reader and controller to be replaced at once.
Why 2030 belongs in the conversation
In June 2025, the European Commission announced that all EU Member States should start transitioning to post-quantum cryptography (PQC) by the end of 2026, while critical infrastructure should transition no later than the end of 2030. The 2030 date is not a prediction of when a cryptographically relevant quantum computer will arrive. It is a planning target that recognises how long discovery, procurement, testing and replacement can take.
The UK National Cyber Security Centre (NCSC) set out a complementary timetable in March 2025: complete discovery and an initial migration plan by 2028, carry out the highest-priority migrations by 2031 and complete the transition by 2035. Both roadmaps send the same message: waiting for ‘Q-day’ would leave organisations too little time to modernise complex estates.
The regulatory case strengthened further in January 2026, when the European Commission proposed amendments to the NIS2 Directive that would require Member States to include post-quantum cryptography migration policies within their national cybersecurity strategies. For solution providers serving critical infrastructure and essential-service clients across Europe, this begins to turn 2030 readiness from a security best practice into a named compliance requirement.
Know what quantum computers will – and will not – break
A sufficiently capable, fault-tolerant quantum computer would threaten much of the RSA- and elliptic-curve-based public-key cryptography used for key establishment and digital signatures. In August 2024, the US National Institute of Standards and Technology finalised its first three PQC standards, including ML-KEM for establishing shared secrets and ML-DSA and SLH-DSA for digital signatures. These standards give technology vendors a foundation for updating products, but adoption across physical security will take time.
That does not mean every old badge will suddenly become vulnerable to quantum computing. Low-frequency proximity cards and legacy reader interfaces can already be cloned, intercepted or tampered with using conventional tools. Conversely, NCSC guidance updated in 2024 states that symmetric cryptography is not significantly affected and that established algorithms with keys of at least 128 bits, such as AES, can continue to be used. The post-quantum concern is more likely to appear in PKI-enabled smart credentials, TLS and VPN connections, cloud APIs, device certificates, mobile-credential provisioning and the digital signatures used to authenticate firmware updates.
Map every place cryptography hides
A useful assessment must cover the entire access-control trust chain: the credential, the reader-to-controller link, the controller’s connection to an on-premises server or cloud service, administrative portals, identity-system integrations and the mechanism used to update devices. For each component, document the algorithms, keys and certificates in use; the sensitivity and useful life of the data; the responsible vendor; the support end date; and whether cryptography can be changed through a secure update.
This process also identifies today’s more immediate problems, including Wiegand connections, unsupported operating systems, hard-coded or poorly managed keys and readers that cannot accept signed firmware. The ‘harvest now, decrypt later’ risk matters most for information that must remain confidential for years. Physical access records can reveal working patterns, sensitive locations and security operations, so solution providers should ask not only whether a card is encrypted, but also how access data is transmitted, stored and protected throughout its lifecycle.
Use OSDP for today’s risk – and tomorrow’s flexibility
Replacing low-security Wiegand interfaces with the Open Supervised Device Protocol (OSDP) is an important near-term improvement. The Security Industry Association (SIA) released OSDP version 2.2.2 in October 2024 and identifies Secure Channel with AES-128 encryption, bidirectional communication, connection supervision and multi-vendor interoperability among the protocol’s benefits. Those capabilities strengthen security now and can make devices easier to manage over their useful life.
Momentum behind the standard is building specifically in Europe. SIA has established a dedicated EU Advisory Board tasked partly with advocating for wider OSDP adoption across the region, giving European integrators a more direct line into the standard’s development.
However, OSDP is a reader-to-controller communications protocol – not a credential format or a post-quantum algorithm suite. Deploying it does not automatically make a system quantum-resistant, and not every OSDP device supports remote firmware management. SIA’s February 2026 implementation checklist tells integrators to verify both peripheral devices and controllers, enable Secure Channel rather than unsecured mode, and separately confirm support for remote management and file transfer.
For a more resilient specification, select OSDP Verified readers and controllers, require Secure Channel in production, document how encryption keys are provisioned and rotated, and confirm that devices support authenticated firmware updates. Also ask vendors whether certificates and algorithms can be replaced, how long each product will receive security updates and what their roadmap is for NIST-standardised PQC. OSDP creates a stronger and more manageable foundation; these additional requirements create cryptographic agility.
The verified ecosystem is maturing quickly enough to support this approach: SIA passed 200 OSDP Verified device models from more than 30 manufacturers in July 2026, giving integrators a growing pool of independently tested, interoperable hardware to specify with confidence.
Turn cryptographic agility into a managed service
Post-quantum preparation gives your business a path beyond a one-off hardware refresh. Begin with a paid discovery engagement that inventories the client’s access-control cryptography and ranks systems by risk, data lifetime, criticality and upgrade difficulty. Next, pilot modern credentials, OSDP Secure Channel and updateable readers at a small number of doors before creating a phased migration plan for the wider estate.
The recurring service begins after deployment. Clients will need certificate and key lifecycle management, firmware and vulnerability monitoring, configuration reviews, support-lifecycle tracking and periodic updates to their cryptographic inventory. For customers operating essential services, you can map these activities to the EU’s 2030 target. For other organisations, the same work reduces present-day risk and prevents technical debt from becoming an emergency replacement project later.
Prepare for 2030 with BlueStar
Building a phased modernisation plan requires access to compatible hardware, identity technologies and integration expertise. BlueStar’s European ID & Security portfolio includes mobile-credential and badge readers, while its local teams support solution design, hardware configuration, software integration, kitting and fulfilment. These capabilities can help you assemble and scale an access-control refresh around each client’s risk, budget and timetable.
Use BlueStar and vendor specialists to validate OSDP Verified status, Secure Channel support, remote-update capabilities, product lifecycles and PQC roadmaps for every component. By starting now, you can replace what is unsafe today while preserving the flexibility to adopt new cryptography tomorrow. Discover how BlueStar can support your next security project by visiting our regional landing page.