Pakistan is Building a Future on Yesterday’s Cryptography

A stylized composite graphic for post-quantum cryptography. In the center, a complex multi-tiered quantum computer processor is suspended against a large red circle and dark digital background. The left side features a glowing green circuit-board map of Pakistan with a crescent and star, while the right side displays the State Bank of Pakistan building, the national flag, and the official state emblem.
Future-proofing Pakistan's digital infrastructure against emerging quantum threats.

From Washington and Brussels to the boardrooms of Google, Microsoft, and Cloudflare, every serious actor on the planet has now published a legally binding timeline for retiring the public-key cryptography that quietly protects the internet, and Islamabad has yet to convene a single working group on what its own version of that plan should even look like.

Open your banking app for a moment and look at the small padlock next to the address bar, because that padlock, the encryption behind RAAST, the certificates protecting the citizen records held by NADRA, and the key exchange that authorises every card transaction at every point of sale terminal in the country all depend on two families of mathematics called RSA and elliptic curve cryptography. Both of those families are now on a countdown that Islamabad has not started reading, and the countdown is not a rhetorical device or a research community anxiety, because it has been written into the law of the jurisdictions whose standards Pakistani banks, telecom operators, and government agencies quietly follow whenever they procure hardware or license software.

On 22 June 2026, the United States signed Executive Order 14412, which makes migration away from the current public-key cryptography a binding legal obligation for every federal civilian agency and every contractor working with those agencies by the end of 2030. The European Union’s own timeline, published by the NIS Cooperation Group in mid-2025 and now being written into member-state law, requires each member country to publish a national post-quantum strategy and begin cryptographic inventories before the end of this year, complete migration for high-risk critical infrastructure by 2030, and finish medium-risk migration by 2035. Google announced in March that its internal operating target is 2029, four years ahead of the regulatory deadline it will eventually be measured against, and Microsoft shipped general availability of the new signature standard inside Active Directory Certificate Services on Windows Server 2025 in May of this year, which means the standard has already arrived inside the enterprise public-key infrastructure box that most large Pakistani banks quietly run behind the scenes.

Islamabad, by contrast, has published no version of any such timeline, no draft, no consultation paper, no white paper, and no announcement of a working group tasked with producing one. The Ministry of IT and Telecommunication has issued no circular on the subject, the State Bank of Pakistan has issued no guidance to the banks it supervises, the Pakistan Telecommunication Authority has said nothing to the operators it regulates, and the National Centre for Cyber Security, which has been funded through the Higher Education Commission since 2018 and coordinates eleven cybersecurity research labs across Pakistani universities, has published nothing on the migration question either. The silence spread across every institution that would ordinarily have a view is itself the entire story of this piece, and the rest of what follows is context for how strange that silence has become as we head into the last quarter of 2026.

What is actually being replaced, and why the rest of the world stopped waiting

In August 2024, the United States National Institute of Standards and Technology finalised three cryptographic standards known formally as FIPS 203, FIPS 204, and FIPS 205, and known in the technical community by their algorithm names of ML-KEM, ML-DSA, and SLH-DSA. Between them these three standards replace the public-key building blocks that most of the internet has relied on since the early nineteen-nineties, and the reason for the replacement comes down to a single algorithm published by the mathematician Peter Shor in 1994, which can factor large integers and solve discrete logarithms in polynomial time once it runs on a sufficiently large quantum computer. That single capability, whenever the hardware eventually arrives to run it at cryptographically relevant scale, breaks RSA, breaks elliptic curve cryptography, breaks the Diffie-Hellman key exchange sitting underneath most secure network protocols, and breaks every certificate authority in the world whose signatures rest on either of those foundations.

The date on which such a machine will actually exist remains genuinely contested inside the research community, and honest sources give ranges rather than points, but the Global Risk Institute’s Quantum Threat Timeline Report 2025, published in March of this year, found that the median estimated probability of a cryptographically relevant quantum computer arriving inside the next decade has reached its highest level in the seven-year history of the survey, and that finding is what has finally pushed the migration timelines from “eventually” into hard law across the western economies.

The urgency is also not really about the eventual arrival date, because it is driven by a much older intelligence strategy called Harvest Now, Decrypt Later, in which an adversary who can quietly copy encrypted traffic today and store it in bulk can decrypt whatever they have stored on whatever future date the quantum hardware finally becomes available. Anything with a confidentiality lifetime longer than roughly a decade is therefore already exposed at the moment of transmission, whether the record in question happens to be a tax filing, a NADRA biometric enrolment, a hospital record, a bank customer history, a diplomatic cable, or the transaction ledger of the digital rupee currently being piloted by the State Bank of Pakistan with a Japanese blockchain firm called Soramitsu.

What Pakistan has done that at first glance reads like a response

There are four Pakistani initiatives worth naming here, because at first reading each of them appears to be a serious institutional response to the underlying problem, and it is only when you read them alongside the international standards documents that the gap becomes visible.

The first initiative is the Pakistan Security Standard, drafted by the National Telecommunication and Information Technology Security Board between 2021 and 2023, formally issued on 14 June 2023, and made mandatory across all cybersecurity products sold in Pakistan by Statutory Notification SRO 762(I)/2023, with full enforcement scheduled for 1 June 2028 and an accelerated December 2025 deadline for defence sector procurement. The PSS replaces Technical Memorandum 27, which had been the reference document since 1994 and never offered standardised evaluation criteria of any kind, so on paper this is a genuinely overdue reform that aligns Pakistan’s cryptographic assurance regime with international benchmarks like the American FIPS 140-2 and the European Common Criteria at ISO/IEC 15408. The problem with the PSS, and it is the specific problem this piece is about, is that the cryptographic algorithms it names for adoption and evaluation are AES, Triple DES, and RSA, which means Pakistan is finalising a legally binding cybersecurity standard around a public-key algorithm that the American federal government will be legally forbidden from using in new deployments approximately two years after the Pakistani law takes effect, and nobody at NTISB has publicly explained how the standard is meant to age past that inflection point.

The second initiative is the Pakistan Information Security Framework 2026, which was presented to parliament in July of this year as the country’s first cybersecurity standard and remains under Cabinet review at the time of writing. The publicly available summary lists compliance controls, audit requirements, and a mandate for public and private organisations to build fully operational Security Operations Centres within six months of adoption, but the summary contains no reference to post-quantum cryptography, no mention of ML-KEM or ML-DSA, no reference to cryptographic inventory as a mandatory practice, and no discussion of the crypto-agility principle that western regulators have now converged on as the operational foundation of every serious migration programme.

The third initiative is the National Artificial Intelligence Policy 2025, approved by the federal cabinet on 30 July 2025 and structured around six strategic pillars covering innovation, awareness, secure systems, sectoral transformation, infrastructure, and international partnerships, with a headline target of training one million Pakistanis in AI-related skills by 2030 and a National AI Fund carved out from the R&D budget managed by Ignite. It is a genuinely ambitious document running to dozens of pages, but the words “post-quantum,” “quantum-safe,” “quantum-resistant,” and any of the FIPS numbers that anchor the international conversation appear nowhere in the policy text, and neither does any acknowledgement that the AI infrastructure the policy commits Pakistan to building will run on top of cryptographic primitives that have already been scheduled for replacement in every jurisdiction Pakistan trades with.

The fourth initiative is the National Centre for Quantum Computing, announced through a memorandum of understanding signed in October 2025 between the Emerging Technologies Lab, which is a project of the Ministry of Planning funded through the PSDP, and China Electronics Technology Group Corporation, alongside a companion “Quantum Valley Project” that Federal Minister Ahsan Iqbal described at the signing as Pakistan’s answer to Silicon Valley. It is worth reading the coverage of this announcement carefully, because the memorandum is about building indigenous quantum computing capability with Chinese assistance, and it is not about defending Pakistani cryptography from the very capability that the same class of hardware, once it matures in adversary hands, will one day carry. Those are two entirely separate problems that require two entirely separate national programmes, and at present Pakistan has one memorandum of understanding on the offensive side and precisely nothing on the defensive side.

Why this matters more for Pakistan than for most countries currently in the migration conversation

Kaspersky reported at the eighth International Cyber Threat Intelligence Conference held in Islamabad in November 2025 that Pakistan absorbed more than 5.3 million on-device attacks and 2.5 million web-based threats in the first nine months of that year alone, with twenty-seven percent of Pakistani users and twenty-four percent of Pakistani corporate entities encountering active malware infections during the same window. Business Recorder, citing the National Cyber Crime Investigation Agency, reported a thirty-five percent year-on-year increase in cybercrime incidents through 2025 and a sixty-two percent increase in digital banking fraud reported by SBP for 2024, and the Cabinet Secretary told parliament in July of this year that Pakistan had recorded 927 detected cyberattacks on critical infrastructure in 2024 and 2025 combined, with 253 more logged in 2026 through mid-year.

The breach record over the same period is what should worry a policy reader most, because NADRA lost the credentials of 2.7 million citizens between 2019 and 2023 as uncovered by a joint investigation team in early 2024, login credentials for more than 180 million users tied to Pakistani services surfaced in a global leak reported in May 2025, Pakistan Petroleum Limited absorbed a ransomware attack on its IT systems on 6 August 2025, and the Capital Development Authority’s billing system was ransomed in June 2026 in an incident that disrupted revenue collection across Islamabad and prompted the Interior Ministry to convene a technical committee. Every one of these breaches involved the exfiltration of encrypted data alongside credentials, and every byte of that encrypted data now sits somewhere it should not, waiting for the day when the encryption around it can be undone at leisure.

Overlay the ambitions on top of the breach record and the picture sharpens further, because the State Bank confirmed in September 2025 that its central bank digital currency pilot had gone live with Soramitsu as the technology partner, NADRA continues to expand biometric enrolment coverage across the country, the AI Policy commits Pakistan to national compute infrastructure and centralised datasets by 2027, and the PSS makes cryptographic products a regulated market from June 2028 onwards. Every one of those systems will generate data with a confidentiality lifetime longer than the arrival window most quantum researchers now assign to a cryptographically relevant machine, every one of those systems will protect that data using RSA or elliptic curve cryptography because that is what the standards Pakistan is writing and the products Pakistan is buying still specify, and every one of those systems sits in a region where at least one adversary has a national quantum programme with a double-digit billion dollar annual budget behind it.

What an actual response would look like in practical terms

A real response to the situation described in this piece is not a press conference and not another memorandum of understanding, because it takes the form of four specific technical and administrative actions that the relevant Pakistani institutions could take within the next twelve months without waiting for anyone abroad to move first.

NTISB should publish an amendment to the Pakistan Security Standard that names ML-KEM-1024 and ML-DSA-87 as the target public-key algorithms for cryptographic equipment sold into Pakistan after 2028, with a hybrid transitional profile allowed until then in the same way the European standards bodies have already structured their own hybrid approach, and this amendment is a two-page technical annex that does not require new primary legislation. The State Bank should issue a Payment Systems Circular requiring every scheduled bank to complete a cryptographic inventory of its production estate by the end of 2027, using the CycloneDX Cryptography Bill of Materials format that most international regulators have already converged on, because inventory precedes migration in every serious plan on the subject, and there is no public evidence that any Pakistani bank has completed the mapping exercise for its own production estate.

NADRA should commission an external cryptographic review of the protection applied to the biometric enrolment corpus it holds on behalf of the state, with a specific mandate to answer whether that data is currently protected against the Harvest Now, Decrypt Later threat and, if the answer is that it is not, to recommend a re-encryption path with a costed schedule. The Ministry of IT should convene a national post-quantum working group with membership drawn from NTISB, SBP, PTA, NCCS, NADRA, and the Pakistani academic institutions that already carry quantum-relevant expertise, giving that group a public reporting mandate and a twelve-month deadline to publish a draft national migration roadmap that follows the template the EU, the UK, the US, France, Germany, Canada, Singapore, South Korea, and the Netherlands have already published in some form.

None of the four actions above is particularly expensive, none of them requires foreign technical assistance, and none of them requires legislation that has not already been drafted somewhere in a jurisdiction Pakistan can borrow from. What they require is a decision at the level of a Federal Secretary or above that the migration problem is worth working on before something breaks that cannot be quietly patched afterwards, and at the time this piece is being written, in the second week of August 2026, there is no public evidence that any such decision has been taken.

The next piece in this series will take one specific institution, the State Bank of Pakistan, and walk through what its published policy stack currently requires of the banks it supervises on cryptographic matters, what it does not require, and what a minimally responsible SBP circular on post-quantum readiness would actually contain if somebody at the Governor’s office decided next Monday morning to write one.

Muhammad Shaheer Bin Junaid
Written by

Muhammad Shaheer Bin Junaid is an applied cryptographer and security researcher working on post-quantum encryption, the migration toward it, and the attacks that test whether these systems actually hold. Alongside his research, he builds real systems, and brings an operator’s eye from years of running his own companies. His focus is what quantum-safe security means for the parts of the world the conversation tends to leave out. The author can be reached at contact@mshaheerbjunaid.com.