A power grid built today will still be running in 2040. The VPNs protecting its SCADA traffic use key exchange negotiated right now. The harvest window is already open.
Where the cryptographic exposure sits
Critical infrastructure in LATAM runs on SCADA systems that communicate over IPSec VPNs, all using IKEv2 with ECDH key exchange. Government ministries use PKI certificates (often P-256 or P-384) for document signing, inter-agency authentication, and classified communications. National ID systems (Brazil's CPF infrastructure, Mexico's CURP/e.firma, Chile's Clave Única) use ECC-based signing chains. These systems have procurement and replacement cycles of 10-20 years, meaning whatever cryptography is deployed today must survive until quantum hardware is mainstream.
The regulatory landscape moving now
ANATEL, Brazil
Telecom operators under ANATEL face cybersecurity obligations (Regulamento de Segurança Cibernética, 2023) that reference ABNT/ISO 27001. NIST alignment is indirect but accelerating.
ENISA-equivalent mandates
Colombia's CONPES 3995 (Política Nacional de Confianza y Seguridad Digital) explicitly references cryptographic agility as a national objective.
AGESIC, Uruguay
National cybersecurity framework for government entities requires cryptographic controls consistent with international standards, tracking NIST post-2024.
CEPREDENAC / OAS frameworks
Inter-American cybersecurity frameworks increasingly reference quantum-safe migration as a medium-term requirement for critical infrastructure operators.
What a QTA delivers for this sector
A QTA scoped to your VPN key exchange surface and PKI certificate chain delivers: a map of which circuits are quantum-vulnerable today, which can be migrated without SCADA downtime, and a sequenced plan that fits government procurement timelines.
