India is developing a national quantum-safe ecosystem under the National Quantum Mission, a ₹6,003 Cr (Cabinet-approved, April 2023) government outlay running FY2023-24 through FY2030-31.
Within that mission, the Department of Science and Technology’s Quantum-Safe Ecosystem strategy identifies a phased transition toward quantum resilience, including targets for Critical Information Infrastructure and wider enterprise adoption. It does not (yet) specify a single named, dated mandate the way frameworks like the NSA’s CNSA 2.0 do - the phasing is broader and still being defined in public guidance.
What the phased approach looks like
In broad strokes, the transition tracks the same three stages every serious PQC migration goes through:
Foundations - cryptographic inventory, risk analysis, and pilot post-quantum deployments across critical national systems.
Migration - bringing high-priority systems onto hybrid classical + post-quantum cryptography, with structured tracking of what’s been migrated and what’s still exposed.
Resiliency - post-quantum cryptography as the default across Critical Information Infrastructure systems, with legacy-only pipelines phased out.
Where AEGIS fits
AEGIS is built around this same three-stage shape - Discover, Protect, Migrate - because it mirrors how the DST strategy itself is structured, not because of a specific mandate with fixed dates. Today, Discover is a working proof of concept and Protect is a prototype; Migrate - the orchestration and reporting layer that would map platform activity onto formal compliance evidence - is on the roadmap, not yet built.
We’ll update this post as DST publishes more specific milestone guidance.
