Abu Dhabi to pioneer post-quantum encryption for secure government systems

Abu Dhabi-Abu Dhabi is moving towards developing post-quantum encryption across government systems, embedded across their technology systems. Officials view this as an early step towards gaining greater visibility and control as they prepare for the quantum era.
H.E. Najyb Al Maskari, Executive Director of the Government Cybersecurity Operations Sector at the Department of Government Enablement (DGE), said that there have been investments made by the UAE Cybersecurity Council and the Technology Innovation Institute (TII) into sovereign encryption protocols designed for agility.
The sovereign encryption protocols aim to secure transactions between various departments such as finance, health and between the government and citizens through their services like TAMM.
“With the right tools we are now seeing the first successful cryptographic inventories,” said Dr Victor Mateu, chief researcher TII’s Cryptography Research Centre as the first successful cryptographic inventories are now emerging.
These inventories give organisations a foundation for migration by identifying the cryptographic systems already operating across their infrastructure.
Dr Mateu added that discovery remains the point at which most organisations get stuck. Some run cryptographic services they did not build and may not know are still operating, he said, noting that they have come across deprecated services still running and exchanging data without the IT team realizing “You cannot migrate what you cannot see,” he added.
Dr Mateu described visibility as the first of three practical challenges facing UAE entities as awareness turns into implementation. The second challenge is assigning responsibility. Migration requires knowledge of both an organisation’s infrastructure and its operational realities. Bringing new people into the process midway can cause delays, Mateu said, making clearly defined responsibilities essential.
Pradeep Menon, Chief AI and Security Officer at Paramount Assure, said that while a number of advanced organisations have started formal assessments, most enterprises are still in the discovery phase.
"Understanding the cryptographic footprint is the crucial first step before any large-scale post-quantum migration can begin," he said.
Vendor dependency is the third challenge. Much of the cryptography deployed inside an organisation comes from suppliers with their own priorities and schedules, requiring migration plans to be developed with existing vendors and, where necessary, processes for moving to new ones.
The wider transition could also give the UAE greater control over the cryptographic technology used across devices in the country.
The UAE currently relies largely on imported solutions that have long been embedded in IT infrastructure, and their vendors can use existing capabilities to support migration, Dr Mateu said.
Cloud providers, including AWS and Microsoft, are investing in post-quantum technology, according to Al Maskari. Many are now publishing their migration timelines, which helps organisations that rely on cloud assets plan their own transition, according to Dr Mateu.
Al Maskari, however, said no formal migration timelines have been published by cloud providers, despite industry targets set around 2030. "These estimates could change," he added.
Dr Mateu said that the shift creates an opportunity to develop sovereign technologies that can be audited, reported on and modified in the country. Such control would allow decisions on which algorithms to support or retire to be made in line with national requirements rather than solely according to a vendor’s timetable.
Menon added that the UAE is not alone in facing these challenges. Its leading government and enterprise organisations are progressing in line with many international peers, with a growing focus on crypto-agility and long-term quantum resilience.