Utilities plan in decades. A transformer, a protection relay or a smart meter bought this year may still be on the network in 2040. That long horizon changes how quantum computing in energy should be read: the security side needs action while equipment is being bought, and the computing side can be watched without hurry.
How long can grid equipment wait for post-quantum cryptography?
Grid equipment cannot wait long for post-quantum cryptography, because relays, meters and substation controllers bought today may still be in service when RSA and elliptic-curve keys are disallowed. NIST’s draft plan puts that at 2035. The cheapest fix is to require field-updatable cryptography in every new purchase now.
Operational technology in electricity, gas and water uses cryptography in more places than most people expect: remote access to substations, firmware signing on relays and controllers, meter data collection, SCADA links over public networks, and connections to market operators. Much of it rests on RSA or elliptic-curve keys. A large quantum computer running Shor’s algorithm would break both.
The risk for utilities is less about stolen data and more about forged commands and firmware. If an attacker can forge a valid signature, a device will accept instructions it should reject. That is why signature migration matters as much as encryption here.
The timelines are already written down. NIST published its post-quantum standards on August 13, 2024, and its draft NIST IR 8547 proposes disallowing RSA and elliptic-curve cryptography at common strengths by 2035. The European Union’s coordinated roadmap from June 2025 asks member states to start the transition by the end of 2026 and to move critical infrastructure no later than the end of 2030. The US executive order of June 22, 2026 set post-quantum deadlines for federal systems and directed support for critical infrastructure operators. The UK’s National Cyber Security Centre, in its March 2025 guidance, says the migration path for sectors that rely on OT “may initially be less clear, with fewer PQC products becoming available in the near future.”
Put those dates next to a 15 to 20 year asset life and the conclusion is simple. Devices bought from now on should support algorithm updates in the field, and contracts should say so.
What have utilities tested with quantum computing so far?
Utilities have tested quantum computing on energy risk pricing, battery placement on the grid and renewable forecasting, mostly in Europe through research pilots with IBM, Multiverse Computing and Pasqal. None claims a production advantage. The pilots build skills and test problem formulations for larger machines that do not exist yet.
E.ON and IBM developed a quantum algorithm for weather risk in energy contracts: estimating what a fixed-price supply contract will cost under different weather conditions, which feeds hedging decisions. The first version of the circuits was too long for the hardware available at the time, so the team used IBM’s dynamic circuits to break the problem into pieces a small machine could run. The result is a working method that could pay off on larger, more reliable machines.
Iberdrola and Multiverse Computing ran a pilot in northern Spain on where to install grid-scale batteries. They used a quantum annealer alongside classical hardware, and reported that some quantum and quantum-inspired algorithms matched or beat the classical benchmark on grid reliability and voltage control. “Matched or beat” on a specific network is a useful research finding, not proof that quantum solvers should run battery planning.
EDF has worked with the quantum company Pasqal on renewable forecasting and grid integration, including scheduling for electric vehicle charging.
A pattern runs through all three: utilities with large analytics teams use quantum pilots to build skills and test formulations, and they report results carefully.
Latin America has less to show so far, and most of it is in Brazil. Petrobras has co-funded quantum technology research at the Brazilian Center for Physics Research (CBPF) in Rio de Janeiro, including work on superconducting qubits. That is capacity building and research, not a quantum application in Petrobras’s operations. We know of no public quantum computing pilots at utilities in Colombia, Mexico or Chile, which means the practical work for a generator or distributor in the region today is the post-quantum migration.
Is materials simulation worth an energy company’s research budget yet?
Materials simulation is worth a small research budget only for energy companies that already run materials programs in batteries, hydrogen or carbon capture. Useful quantum chemistry needs error-corrected machines with far more logical qubits than exist today, so most utilities can follow the field through their suppliers.
The strongest long-term case for quantum computing in energy may be chemistry, not optimization. Better battery electrolytes, catalysts for hydrogen and carbon capture, and new solar materials all depend on how electrons behave in molecules and solids. Classical methods approximate those systems, and some of them are exactly the kind of problem quantum simulation is expected to handle well.
That future needs error-corrected machines with far more logical qubits than exist today. Google’s Willow chip, announced in December 2024, showed logical error rates falling as the system grew, which is a necessary step. It did not show useful chemistry. Energy companies with materials research programs should keep one or two people current on the field. Most others can follow it through their suppliers.
Now versus later, in one table
| Area | Now | Later | First step |
|---|---|---|---|
| OT and IT cryptography | Inventory across IT and OT, including vendor-managed devices | Legacy RSA and ECC disallowed under NIST’s draft plan by 2035 | List devices by remaining asset life |
| Procurement | Post-quantum and crypto agility clauses for meters, relays, RTUs and SCADA | Devices without upgrade paths replaced early | Add the clause to the next RFP |
| Network connections | Hybrid key exchange tests on internal and market-facing links | Post-quantum key exchange by default | Pick one internal link to test |
| Grid planning and dispatch | Small, measured experiments if you have a strong analytics team | Quantum-assisted planning, if research results hold up at scale | Benchmark your current solver |
| Materials | Follow the research through suppliers and universities | Simulation for storage, hydrogen and carbon capture on error-corrected hardware | Name one person to track it |
Where to start this year
For most utilities the right first step is a quantum readiness assessment. It ranks cryptographic exposure by asset life and criticality, and it checks whether any planning or trading problem is worth a quantum experiment. The migration itself, including OT constraints like limited bandwidth and long maintenance windows, is covered by our post-quantum cryptography migration service. If a grid or trading problem looks promising, quantum use case discovery tests it against classical methods before anyone buys quantum cloud time.
We are opening engagements in stages. Tell us about your network and we will tell you plainly what makes sense to do now.
Sources
- NIST CSRC, Post-quantum cryptography FIPS approved (FIPS 203, 204 and 205), August 13, 2024
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
- European Commission, EU reinforces its cybersecurity with post-quantum cryptography, June 23, 2025
- UK NCSC, Timelines for migration to post-quantum cryptography, March 20, 2025
- Mayer Brown, President Trump signs two executive orders on quantum computing and accelerated post-quantum cryptography migration, June 2026
- Nature, Quantum error correction below the surface code threshold (Google Willow), December 2024