TL;DR: Vietnam's government has approved a national roadmap for post-quantum cryptography running through 2035, moving in three phases from standards and pilots to a full transition across government, finance, and energy systems. Businesses handling sensitive data have a five to ten year window to plan their own migration.
Post-quantum cryptography just became a formal national priority in Vietnam. At the AI4CRIS 2026 conference in Hanoi on August 14, 2026, a research team from the Department of Security Industry under the Ministry of Public Security, represented by Dr. Le Hai Trieu, presented a three-phase roadmap for post-quantum cryptography running from 2027 to 2035.
Lieutenant General Vu Ngoc Thiem, head of the Government Cipher Committee (Ban Co yeu Chinh phu), confirmed that the Prime Minister has already approved a dedicated scheme, the Quantum-Resistant Cryptography System Development Program for 2026-2035, marking a concrete step toward protecting national digital sovereignty.

Contents
- What are the three phases of Vietnam's post-quantum cryptography roadmap?
- Why does post-quantum cryptography matter now, not in 2035?
- What should businesses handling sensitive data do today?
- Frequently Asked Questions
What Are the Three Phases of Vietnam's Post-Quantum Cryptography Roadmap?
The first phase, 2027 to 2029, focuses on recognition and groundwork for post-quantum cryptography: issuing a national PQC standard, building an open testing environment for researchers and businesses, training 100 specialists, and completing a national inventory of systems and cryptographic algorithms in use. By the end of 2029, government agencies should be able to identify their own quantum risk exposure.
The second phase, 2030 to 2032, is the transition phase. Government, financial, and energy systems adopt post-quantum cryptography directly, with businesses receiving technical support and incentive policies to follow. The target is that roughly 70 percent of critical systems complete their transition by 2032. In parallel, a quantum key distribution pilot line between Hanoi and Ho Chi Minh City is proposed for data with extremely high security requirements.
The third phase, 2033 to 2035, is mastery. Post-quantum cryptography becomes the default cryptographic layer across digital systems, quantum key distribution serves internal networks and top-secret channels, and Vietnam aims to contribute to global post-quantum cryptography research rather than only adopting it.
Why Does Post-Quantum Cryptography Matter Now, Not in 2035?
Dr. Nguyen Quoc Hung of the Quantum Technology Institute at Vietnam National University, Hanoi, framed the urgency clearly: the combined time needed to keep certain data secure and to complete a cryptographic transition can run to several decades, while a quantum computer strong enough to break today's encryption, referred to as CRQC, could plausibly arrive within a few years.
He cited Google's own estimate that a cryptographically relevant quantum computer could emerge within four years, which is why some threat groups are already engaged in "harvest now, decrypt later" data collection, storing encrypted traffic today to break it once quantum hardware catches up. Sensitive data can require 20 to 30 years of confidentiality, while a full cryptographic transition typically takes 5 to 10 years, a gap that leaves very little room for delay.
"Migrating immediately is already dangerous, this is not only a problem in Vietnam, even the United States is not ready to transition its cryptographic systems," Dr. Hung said at the conference, underscoring that Vietnam's early roadmap puts it in reasonable company globally rather than behind. Vietnam's five identified barriers, a small and scattered pool of PQC specialists, no national testing platform yet, high transition costs for small and mid-size businesses, uncoordinated research efforts, and financing mechanisms not suited to long-term research, mirror challenges other governments are only starting to name.
What Should Businesses Handling Sensitive Data Do Today?
Enterprises do not need to wait for 2030 to start acting on post-quantum cryptography. The most useful first step mirrors phase one of the government roadmap at company scale: inventory which systems, vendors, and data flows still rely on cryptographic algorithms that quantum computing could eventually break, particularly anything protecting data with multi-decade confidentiality needs, such as financial records, health data, or government contracts.
Regulatory momentum around data itself is moving in parallel. Our analysis of Decree No. 314 and Vietnam's data market covers how the country is simultaneously building the legal infrastructure for a formal data economy, which will increasingly intersect with post-quantum cryptography requirements as more regulated data moves through digital platforms and cloud infrastructure.
Enterprise technology teams evaluating vendors and platforms should also watch how quickly the broader ecosystem responds. Our coverage of open source AI adoption trends in 2026 shows a similar pattern: capable technology becomes enterprise-ready only once tooling, standards, and skilled talent catch up, and post-quantum cryptography is following the same curve a few years behind.
Frequently Asked Questions
What is post-quantum cryptography?
Post-quantum cryptography refers to encryption algorithms designed to remain secure against attacks from quantum computers, while still running on today's ordinary computing and network infrastructure, unlike quantum key distribution, which requires dedicated optical hardware.
When does Vietnam's post-quantum cryptography transition need to happen?
The approved roadmap targets 2027 to 2029 for standards and groundwork, 2030 to 2032 for transitioning roughly 70 percent of critical systems, and 2033 to 2035 for making post-quantum cryptography the default layer across digital systems.
Why is post-quantum cryptography urgent if quantum computers are not ready yet?
Because data that must stay confidential for 20 to 30 years, combined with a 5 to 10 year cryptographic transition timeline, means organizations need to start migrating years before a quantum computer capable of breaking encryption actually exists.
Which sectors are prioritized first under Vietnam's roadmap?
Government, financial, and energy systems are named as the first sectors required to adopt post-quantum cryptography during the 2030 to 2032 transition phase, ahead of a broader rollout across the rest of the economy.
As Vietnam's data economy scales alongside this post-quantum cryptography roadmap, enterprises need verified, well-governed data infrastructure just as much as they need updated encryption. DataCore's data services give businesses a way to work with structured, verifiable data in Vietnam while these security standards mature around them.




Để lại một bình luận
You must be logged in to post a comment.