ON2IT - Zero Trust Innovators

Select your region

Talk to us →
← Back to blog Post-Quantum Cryptography

Quantum is an asset problem. Not a math problem.

August 13, 2026 · 5 minutes read · By Jeroen Scheerder

Summary

On June 22, President Trump signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks.” The mandate: federal information systems move to post-quantum cryptography (PQC), and they move on a clock. High-value assets transition key establishment by the end of 2030 and digital signatures by the end of 2031. A pilot has to be done by the end of 2027. And it does not stop at federal agencies. The order pushes the same requirement onto federal contractors, and directs guidance for a cryptographic bill of materials.

If you sell to the government, or to anyone who sells to the government, this is now your timeline too.

Why you cannot wait for the deadline

There is a reason this is a present-day risk and not a 2030 problem. It has a name: harvest now, decrypt later.

An attacker does not need a quantum computer today to do damage today. They intercept your encrypted traffic now, store it, and decrypt it later once the hardware catches up. Everything you encrypt today that still holds value in five or ten years, contracts, health records, intellectual property, classified data, is already exposed. The clock on that exposure started a long time ago. The executive order just made the response mandatory.

So the 2030 and 2031 deadlines are not when the risk begins. They are when you run out of runway. The data you need to protect against quantum decryption is being collected right now.

“Support” is not “ready”

Here is the mistake a lot of organizations are about to make. They hear “post-quantum,” call their vendor, get told the product “supports” the new algorithms, and check the box.

Support means a system can use the new algorithms. Ready means something else entirely: you know where cryptography lives in your environment, which systems are exposed, which dependencies matter, and how to make the switch without breaking anything. Migration touches more than a crypto library. Larger key sizes, new protocol behaviors, hybrid modes, hardware acceleration, interoperability with legacy systems, all of it can create real performance and availability problems if you change things blindly.

That is not a math problem you hand to the cryptographers. It is an inventory problem. And it is exactly where that cryptographic bill of materials comes from. It sounds like new compliance overhead, but at its core it is something you needed all along: knowing what cryptography runs where. You cannot migrate what you cannot see.

One more reason not to rush blindly: do not hard-wire yourself to a single new algorithm. Standards evolve, and algorithms can be weakened or withdrawn. The goal is crypto-agility, the ability to swap algorithms as guidance matures, not a one-time replacement you bet everything on.

And there is a deeper version of this point. Migrating to post-quantum algorithms while your data practices stay sloppy is polishing the lock on a door you left open. If you over-collect, over-retain, and scatter data across systems you cannot see, stronger cryptography protects less than you think. Quantum-safe is one layer. Knowing what data you hold, why, and where, and holding less of it, is the layer underneath.

Why Zero Trust gives you a head start

If you already operate on Zero Trust principles, you are ahead. Because the first question of a quantum migration, “where does my cryptography live and what does it protect,” is the same question you already answer when you define a Protect Surface. You have divided your environment into bounded segments with known data, applications, assets, and services, and you know, per Protect Surface, what is being protected and how.

That turns the quantum question from an overwhelming “we have to replace all our encryption” into a manageable “which Protect Surfaces hold long-lived data, and what cryptography runs there.” You prioritize by data sensitivity and system criticality, not by panic. You start with the Protect Surfaces where harvest-now-decrypt-later hurts most, and you work outward.

No big bang. No year of inventory before you do anything. Just the structure you already have, used to start where it counts.

What you can do this quarter

You do not have to wait for OMB’s implementing guidance to start moving. Three concrete steps:

Map which of your Protect Surfaces hold data that will still be sensitive in five to ten years. That is your harvest-now-decrypt-later exposure, and it is the top of your priority list.

Stop asking vendors whether they “support” PQC. Ask when and how they actually migrate, and what that means for your environment. The difference between those two questions is the difference between a checkbox and a plan.

Start your cryptographic inventory, even if it is incomplete. Visibility is the precondition for everything that follows. The organization that knows where its cryptography lives today will not be scrambling to find it under a deadline.

Becoming quantum-safe is not a cryptography project you delegate and forget. It is risk management, and it starts with knowing what you protect.

Want to know which of your Protect Surfaces deserve attention first in a post-quantum migration? Schedule a conversation with our team.