Post-Quantum Cryptography Migration in the United States: Managing Risk and Advancing Cyber Readiness in Critical Infrastructure
Authors
Table of Contents
- Executive Summary
- The Post-Quantum Moment: Understanding “Q-Day” and the Urgency of Migration
- Understanding the Post-Quantum Challenge Around U.S. Critical Infrastructure
- A Risk-Based Approach to PQC Migration
- Advancing Post-Quantum Readiness: Policy Recommendations
- Conclusion
Media Contact
For general and media inquiries and to book our experts, please contact: pr@rstreet.org
PQC migration is not merely a future-proofing exercise—it is a present-day risk-management imperative. Organizations must begin making decisions now about how to reduce future exposure.
Executive Summary
As quantum computing advances, the risk it poses to widely used cryptographic standards and systems is no longer theoretical. While the arrival of a fully realized “Q-Day” (the capability milestone at which quantum computers can break the cryptography securing today’s digital communications) remains uncertain, the conditions that create cybersecurity and national security risks are already taking shape.

Encrypted data can be collected today and decrypted in the future, creating a growing “harvest now, decrypt later” threat—particularly for systems that rely on long-term confidentiality.
Drawing on insights from the R Street Institute’s Post-Quantum Cryptography (PQC) Policy Working Group, this paper examines how the United States can approach PQC migration across critical infrastructure through a risk-based lens. Critical infrastructure presents a uniquely complex challenge: It is highly interconnected, often privately owned, and varies significantly in technical maturity and resource capacity. These factors make a uniform transition unlikely and reinforce the need for strategic prioritization and coordination.
This study advances three core findings. First, organizations need to treat PQC migration as a present-day risk-management objective, not a distant-future milestone. Second, data sensitivity, system criticality, and transition feasibility need to drive prioritization—particularly in sectors with long-lived data and operational dependencies. Third, federal leadership must move beyond high-level direction toward harmonized implementation.
To support policymakers and critical infrastructure leaders in this effort, this paper outlines four policy recommendations:
- Aligning federal leadership, budgeting, and accountability mechanisms
- Using targeted Requests for Information (RFIs) to identify implementation gaps and demonstrate solution pathways
- Expanding pilot programs in high-impact environments to generate practical lessons for broader adoption
- Leveraging market signals and private-sector leadership to accelerate adoption
Securing the United States’ transition to PQC will depend not only on government action but also on industry leadership. Early action—through inventory, innovation, cyber readiness, and modernization—will determine whether the United States can maintain secure, resilient infrastructure and sustain its strategic advantage in an increasingly competitive technological and threat landscape.
The Post-Quantum Moment: Understanding “Q-Day” and the Urgency of Migration
Recent technological advances are bringing the long-standing promise of a quantum-computing era closer to realization.[1] Quantum computing applies principles from quantum mechanics, such as entanglement, superposition, and quantum tunneling, to process information in fundamentally different ways from classical systems.[2] Where classical computers rely on bits that store information as either 0 or 1, quantum computers use quantum bits or “qubits,” which can exist in a superposition of multiple simultaneous states.[3] This allows qubits to encode a range of values simultaneously and process them in parallel, rather than one step at a time like classical computers.[4]
This architectural difference gives quantum computers the ability to solve certain classes of problems that are currently challenging or impossible—even for today’s largest classical supercomputers.[5] Harnessed effectively, this processing advantage has the potential to accelerate molecular analyses for drug discovery or improve fraud detection in financial modeling.[6] Used maliciously, however, it could threaten current public-key cryptography, which relies on mathematical problems that sufficiently powerful quantum computers may eventually break.
Researchers have understood quantum computers’ potential to outperform classical computers for decades. For instance, Shor’s 1994 algorithm marked a key theoretical breakthrough, demonstrating that a sufficiently powerful quantum computer could break widely used encryption.[7] Yet, for most of that time, the prospect of a machine capable of running that algorithm remained a largely theoretical concern.[8] As a result, quantum computing historically felt highly academic and abstract—something that was always on the horizon, but never quite arriving.[9]
However, that perception is beginning to change, as recent developments are bringing quantum capabilities closer.[10] In February 2026, Iceberg Quantum, a startup based in Sydney, introduced its “Pinnacle” architecture, reflecting a broader shift toward more efficient and scalable approaches to building quantum systems.[11] Early projections suggest that these approaches could significantly reduce the number of qubits required to break widely used encryption standards like RSA-2048—bringing what was once thought to require millions of qubits down to fewer than 100,000 in some cases.[12] In March 2026, a team of quantum physicists at the California Institute of Technology outlined a design for a quantum machine that would require only tens of thousands of qubits to break encryption and announced a new venture to build it.[13] That same month, researchers at Google Quantum AI published resource estimates showing that breaking elliptic curve cryptography—an encryption standard that had been considered more resistant to quantum attack than RSA—could require fewer than 500,000 physical qubits, roughly 20 times less than prior estimates.[14] Although these systems are not yet capable of breaking encryption, they all point to the same shift: The gap between theoretical possibility and practical capability is closing more quickly than expected.[15]
This shift gives rise to the concept of “Quantum Day,” more commonly referred to as “Q-Day”—the point at which a quantum computer becomes capable of breaking widely used public-key cryptographic systems, such as Rivest-Shamir-Adleman (RSA) and elliptic curve cryptography (ECC).[16]

More broadly, it reflects a turning point where quantum capabilities become operationally relevant—whether through selectively targeting high-value systems or enabling the decryption of already-harvested sensitive data.[17]
Q-Day is unlikely to arrive as a single, clearly defined moment.[18] Instead, experts expect its effects to be gradual, uneven, and difficult to detect, particularly because early quantum systems will be resource-constrained and confined to strategic deployments.[19] Still, even before systems can break encryption in minutes, the ability to do so in months or years could pose a risk and shape how adversaries prioritize targets—especially in situations where data must remain secure over long periods, such as national security and intelligence information, medical records, or financial data.[20]
This gradual emergence of risk makes it difficult for organizations to set realistic timelines for preventing Q-Day risks.[21] Encrypted data could be collected today with the expectation that it could be decrypted successfully later, and the process of replacing cryptographic systems—particularly across large, complex environments like critical infrastructure—will likely take years.[22] Many systems are deeply embedded, difficult to update, and dependent on broader operational constraints.[23] As a result, organizations may delay action until the threat feels immediate or damage has occurred, even though the window for proactive mitigation is already narrowing.[24] This dynamic helps explain why several major technology companies, have started to accelerate their timelines for post-quantum cryptography (PQC) migration.[25]
Against this backdrop, the challenge is not simply to recognize the risk but to determine how to act on it effectively, given the significant uncertainties around timing, standards, and implementation. Drawing on insights from the R Street Institute’s PQC Policy Working Group, which includes stakeholders across industry, academia, and government, this paper examines strategies for approaching PQC migration across critical infrastructure through a risk-based lens. In doing so, it focuses on three core topics:
- Prioritizing systems and environments for PQC migration
- Organizational management strategies to mitigate risk in systems that cannot easily transition
- The federal government’s role in enabling, accelerating, and harmonizing this risk-mitigation process
Thus, rather than attempting to predict a precise timeline for Q-Day and prescribing a single pathway forward, this study presents a framework that policymakers and critical infrastructure stakeholders can use to prioritize, coordinate, and take incremental action amid ongoing uncertainties.
Understanding the Post-Quantum Challenge Around U.S. Critical Infrastructure
PQC refers to a class of cryptographic systems designed to run on classical computers but resist attacks by quantum ones.[26] Unlike widely deployed public-key systems today like RSA and ECC, which rely on mathematical problems that could eventually be solved by sufficiently powerful quantum computers, PQC algorithms are based on different classes of mathematical problems—such as lattice-based, hash-based, code-based, and multivariate polynomial constructions—that are not known to be efficiently solvable by quantum computers.[27]

In practical terms, PQC functions as the cryptographic defense against the threats quantum computing could eventually pose.[28]
PQC matters because it links directly to the security and resilience of modern digital systems.[29] Cryptography already underpins financial transactions, identity management, secure communications, software updates, and critical infrastructure.[30] As quantum capabilities advance, migrating to PQC is not simply a technological upgrade; it is a critical step for safeguarding the integrity and confidentiality of U.S. systems and data.[31]
Although PQC migration will help address quantum-related threats before they fully materialize, it does bring practical challenges.[32] Many candidate algorithms require larger key sizes, which increase the amount of data that must be stored and transmitted for encryption, as well as greater computational overhead, which can slow processing speed. Additionally, these algorithms may not integrate cleanly into existing systems, especially older ones.[33] There is also the risk of premature or uneven adoption, particularly as standards mature and implementation guidance continues to evolve.[34] In this sense, PQC is not a single deployment or update decision—it is a complex, long-term migration that requires careful management.
Momentum around PQC is already building across the federal government. A March 2026 report from the Government Accountability Office highlights how quantum efforts are being coordinated under the National Quantum Initiative, with estimated federal investments of $200 million annually in quantum research and development.[35] Moreover, the National Institute of Standards and Technology (NIST) has finalized initial sets of quantum-resistant cryptographic standards and continues to support broader migration efforts through its PQC project, including implementation guidance and testing.[36]
Policy direction has also become more defined. The Trump administration’s National Cyber Strategy and Executive Order 14306 emphasize the need to prepare federal systems—and, by extension, critical infrastructure—for the transition to quantum-resistant cryptography.[37] In addition, both chambers of Congress have introduced a growing set of legislative proposals to accelerate readiness. For example, the Post Quantum Cybersecurity Standards Act (H.R. 3259) seeks to formalize requirements for federal adoption of PQC, and the Quantum Encryption Readiness and Resilience Act (H.R. 4942) focuses on assessing agency preparedness and identifying gaps in migration planning.[38] On the Senate side, the National Quantum Cybersecurity Migration Strategy Act (S.2558) and the Quantum Readiness and Innovation Act (S.3312) both aim to strengthen coordination across agencies and support long-term planning efforts.[39] More broadly, the National Quantum Initiative Reauthorization Act of 2026 (S.3597) reinforces federal investment and strategic direction, and the Support for Quantum Supply Chain Act (H.R. 3788) focuses on securing the ecosystem that will support quantum and post-quantum technologies.[40] Collectively, these efforts signal an increased national understanding of the need to advance the post-quantum transition.
Despite this progress, most of these efforts are broad in scope, offering limited specificity on how PQC migration should be implemented.[41] This gap between policy momentum and operational clarity creates implementation challenges for organizations across many sectors. One of the most basic challenges is determining who owns and participates in the migration process at the organizational level. Although cybersecurity issues usually default to the chief information security officer, PQC migration efforts require coordination across information technology, engineering, procurement, vendor management, and executive leadership. In addition, because PQC standards continue to evolve and there is no universally accepted implementation roadmap or timeline (federally mandated or otherwise), organizations must decide what actions and systems to prioritize, how to balance competing risks, and how to allocate funding and resources for long implementation timelines. Understandably, these efforts compete with more immediate, more easily quantifiable threats and operational priorities. Beyond these issues, modifying cryptographic systems introduces its own risks, including potential disruptions to existing operations. Together, these challenges create a push-and-pull dynamic, where organizations recognize the importance of the transition but delay action.
These issues carry especially high stakes for critical infrastructure systems (e.g., energy, water/wastewater, financial services, healthcare, communications, transportation, defense) necessary for national security, economic stability, and public safety.[42] Disruptions in these systems cause cascading effects across the economy in concrete ways: The 2021 ransomware attack on Colonial Pipeline triggered fuel shortages and price spikes across the East Coast, and the 2020 SolarWinds software supply-chain attack compromised multiple federal agencies and Fortune 500 companies through a single trusted update channel.[43] A successful exploitation of a cryptographic weakness at a comparable scale could be more difficult to detect, more challenging to remediate, and more durable in its effects.
The structure of the United States’ critical infrastructure adds yet another layer of complexity. Although the widely cited figure that approximately 85 percent of the United States’ critical infrastructure is privately owned and operated traces back to early federal strategy documents—not to a precise measurement—more recent analyses indicate that ownership varies significantly depending on how critical infrastructure is defined and which sectors are examined.[44] Some sectors are predominantly privately owned, whereas others are predominantly publicly owned. The distribution of which group serves the majority of the population also varies. For example, in the water/wastewater sector, a smaller share of publicly owned utilities may serve a disproportionately large number of users.[45] These distinctions are not merely structural—they shape how risk is distributed, who is responsible for managing it, and how quickly organizations are able to respond to emerging threats.
This variability has direct implications for the post-quantum transition in the United States. The federal government’s role has so far been indirect, providing guidance, coordination, and incentives rather than overseeing the transition in a centralized way. Implementation is therefore inherently uneven. Organizations differ widely in size, resources, regulatory exposure, and technical maturity, all of which influence their ability to adopt PQC solutions successfully. Bridging the gap between policy direction and operational execution will require a more practical approach—one that accounts for sector-specific needs and emphasizes prioritization, coordination, and risk management in environments often defined by uncertainty.
The federal government already has the authority needed to accelerate PQC migration without waiting for new legislation. Executive Order 14306 and the administration’s National Cyber Strategy establish a clear policy direction on preparing federal systems for quantum-resistant cryptography.[46] The Office of Management and Budget (OMB) has the authority to incorporate PQC requirements into agency planning cycles, and the Cybersecurity & Infrastructure Security Agency (CISA) can translate technical standards into operational expectations for federal agencies and critical infrastructure operators. With these policy tools in place, the more pressing question becomes whether existing authorities are being exercised with the specificity and urgency required to make meaningful progress before the window for proactive migration narrows further.
A Risk-Based Approach to PQC Migration
Organizations often frame PQC migration as a future problem with a distant deadline—most commonly estimated around 2035.[47] While estimating a date can be useful for planning purposes, the risk associated with quantum-enabled decryption does not emerge suddenly at a fixed point in time. It develops gradually and changes with advances in quantum capability, the value of targeted data, and the strategic incentives of potential adversaries.
This means that even before quantum systems are capable of breaking encryption in minutes, intermediate capabilities could still be consequential.[48] A quantum system that reduces decryption timelines from infeasible timeframes to months—or even years—may be sufficient to influence adversary behavior. In such a scenario, threat actors are unlikely to deploy quantum capabilities indiscriminately. Rather, they would allocate those resources toward the most valuable targets: systems that store sensitive, long-lived data or support critical functions. From this perspective, the relevant question is not whether Q-Day has arrived—it is whether a given system or dataset would be worth targeting under evolving conditions of partial quantum capability.
Thus, PQC migration is not merely a future-proofing exercise—it is a present-day risk-management imperative.

Organizations must begin making decisions now about how to reduce future exposure, even amid uncertainty around timing, standards, and implementation. A risk-based approach to PQC migration provides a way to navigate that uncertainty by focusing on prioritization, sequencing, and incremental progress.
Strengthening Cyber Readiness and Resilience
The starting point for PQC migration is not the selection of new algorithms, but the ability to understand and manage existing cryptographic dependencies. In many organizations, visibility into where those dependencies exist and what they collectively protect remains limited.[49] Cryptography is embedded across systems, applications, and supply chains, often without centralized tracking or clear ownership.[50] Without a clear inventory of where cryptographic functions are used and what data they protect, it is difficult to prioritize migration efforts in a meaningful way.
Basic cyber hygiene is the foundation for strengthening cyber readiness and resilience. This includes maintaining an accurate cryptographic inventory, strengthening key management practices, and identifying dependencies across internal systems and third-party vendors.[51] These activities are not unique to PQC migration, but they take on greater urgency in this context because they determine whether an organization can execute a transition at scale. Reliable backup and recovery mechanisms are important for a related reason.[52] If a cryptographic system is compromised—whether through quantum-enabled decryption or other means—backups provide a critical safeguard for restoring operations and preserving data integrity.[53]
Resilience also depends on adaptability. Systems should be designed with failback mechanisms and crypto-agility in mind, allowing organizations to update or replace cryptographic components without significant disruption. At the same time, validation processes—such as NIST’s Cryptographic Module Validation Program—remain critical for ensuring trust in deployed solutions.[54]
More broadly, PQC migration should be viewed as an opportunity to modernize the technology stack.[55] Many of the systems this transition will affect are already due for upgrades because of age, security gaps, or operational inefficiencies. Aligning PQC efforts with broader modernization initiatives—such as replacing legacy infrastructure, strengthening software supply chains, and improving development and deployment pipelines—can help organizations address multiple risks at once. The transition to PQC does not eliminate existing vulnerabilities; rather, it unfolds alongside them in an environment where exploitation capabilities—particularly those enabled by artificial intelligence—are continuing to advance.
Prioritizing Critical Infrastructure
Some critical infrastructure sectors are inherently better positioned to mitigate cyber risks than others. These include sectors like financial services, healthcare, energy, defense, and telecommunications, where organizations must protect highly sensitive data or provide life-sustaining services, often within established regulatory frameworks designed to safeguard critical data and infrastructure.
It is therefore important to look beyond sector-wide assumptions and assess organization-level factors that increase cyber risk exposure, such as the sensitivity of the data involved, the length of time data must remain secure, the criticality of the system, and the feasibility of PQC migration. The size of the organization can also be an important factor: Large, well-resourced organizations may be able to begin transitioning now, whereas smaller entities like regional banks or local healthcare providers may have insufficient resources to transition proactively.
A helpful framing exercise is to assess organization-level “harvest now, decrypt later” threats.[56] Systems that store or transmit data with long-term sensitivity (e.g., financial records, healthcare data, national security information) require a higher level of risk mitigation, even if immediate decryption is not possible.[57] An organization’s risk should also be considered heightened if nation-state adversaries would view the interruption of that infrastructure as an attractive target for triggering cascading effects across the U.S. economy and society.[58]
The post-quantum challenge facing critical infrastructure systems is also shaped by the time PQC migrations will take. Many environments—particularly those that rely on operational technology and legacy systems—not only face longer and more complex migration timelines but also create predictable windows of exposure and constraints that make full, timely migration difficult.[59]
The time required to complete these transitions proactively is an especially relevant factor when considering the recent acceleration of Q-Day estimates. Federal planning in the United States has generally pointed toward a 2035 migration horizon, but some private-sector organizations have recently suggested that timeline should be closer to 2029. Some countries appear to be compressing migration timelines to better align with earlier estimates.[60] China, for example, is working to develop PQC national standards in the next three years, and its most recent five-year plan names scalable quantum technology as a core strategic industry alongside embodied artificial intelligence, nuclear fusion, and brain-computer interfaces.[61] China has also signaled its intent to shape international standards, positioning itself not only as a participant but also as a potential rule-setter in this space.[62]
The national security implications of certain nation-states taking a more coordinated and accelerated approach to post-quantum readiness are significant. If a threat actor were able to strengthen the protection of its own data while taking advantage of slower or uneven transitions elsewhere, those gaps could translate into prolonged exposure for high-value, critical infrastructure targets.[63]
The federal government is not the only driver of PQC adoption—and it may not be the most effective one. Microsoft, along with other major technology companies, has already begun to accelerate its PQC migration timeline. This acceleration has been driven by a combination of risk awareness and competitive incentives.[64] As large technology companies increasingly embed PQC requirements into their products and platforms, they are creating new baseline security expectations for the broader vendor ecosystem. Consequently, organizations that depend on their offerings inherit a degree of quantum resilience, regardless of their own migration status. Private-sector procurement decisions, vendor requirements, and the competitive differentiation that comes from demonstrable PQC readiness may ultimately drive faster and more durable adoption across the private sector than federal mandates alone, particularly in sectors with limited regulatory pressure and long implementation timelines.
Managing Risk in Difficult-to-Transition Systems
Not all systems can be migrated to PQC quickly, and in many cases, full migration simply is not feasible in the near term. This is particularly true for operational technology environments, legacy systems, and resource-constrained organizations, which include small and medium-sized businesses, state and local governments, tribal entities, and certain critical infrastructure sectors such as water.[65] Similar constraints are also expected to affect non-critical sectors, such as retail, education, and media and entertainment, where resources, incentives, and regulatory drivers to prioritize PQC migration are comparatively weaker.
In these environments, the focus must shift from immediate, full migration to targeted, manageable risk reduction.[66] Rather than attempting to address all systems at once, organizations can begin by identifying where sensitive data resides, how long it must remain secure, and where cryptographic protections are weakest or most exposed. They should evaluate how cryptographic risk affects their business operations and broader mission and whether potential risks involve service delivery, financial stability, or national security considerations. That assessment should inform how resources are allocated and where incremental improvements can have the greatest impact.
Vendor risk also matters across the software ecosystem. Many organizations rely on third-party vendors, yet there is still limited visibility into how those vendors are preparing for PQC migration. Encouraging greater transparency and moving toward default-secure configurations can help reduce friction for end users while improving overall security outcomes.
Advancing Post-Quantum Readiness: Policy Recommendations
The risk-based approach outlined in this paper provides the foundation for a set of best practices for prioritizing and better managing PQC migration.

To ensure that policymakers support, scale, and sustain these approaches across sectors—particularly in critical infrastructure environments—we recommend four key, actionable policy strategies below.
Of note, we have not recommended an immediate intervention to mitigate the harvest-now-decrypt-later threat. This is not an oversight. Because of the nature of the threat and the plethora of vulnerable systems, no single policy action could immediately secure sensitive, long-lived data. As such, we focus instead on recommendations that could realistically accelerate the pace and improve the coherence of migration efforts in light of the quickly compressing timeline.
- Align Federal Leadership, Budgeting, and Accountability Mechanisms
The federal government should begin by making fuller use of the authorities it already has. Existing tools within the executive branch, such as the OMB’s authority over agency planning cycles and CISA’s role in translating technical standards into operational expectations, can drive meaningful progress in the near term. To realize that potential, the executive branch must take a more explicit role in deploying those tools with specificity and urgency, and Congress must simultaneously align agency budgeting and oversight to support sustained implementation. This complementary effort is critical, as priorities set through executive direction alone are more likely to fluctuate with administration changes, creating uncertainty in long-term planning.
This approach should not impose a rigid, one-size-fits-all implementation model. Agencies and sectors will continue to face different constraints and risk profiles, and flexibility will remain essential. Still, clearer baseline expectations would help harmonize efforts, reduce ambiguity, and provide a more consistent foundation for progress. The overall policy objective should be to move from a collection of parallel efforts to a more integrated federal approach—one in which standards, budgets, timelines, implementation guidance, and oversight are aligned to support sustained progress on PQC migration.
- Use Targeted RFIs to Identify Implementation Gaps and Demonstrate Solution Pathways
Government agencies are already using RFIs to engage industry on post-quantum readiness, but their value depends on the specificity and practicality of the responses. Rather than issuing broad exploratory requests, agencies should use RFIs strategically to identify a set of common, cross-cutting implementation challenges—such as cryptographic inventory, legacy system constraints, integration into existing architectures, and validation requirements. Narrowing and clarifying key challenges would provide a more actionable basis for identifying where solutions are needed most.
Recent efforts in this regard show what targeted RFIs can look like in practice. In March 2026, the Federal Aviation Administration issued an RFI to support the transition of the National Airspace System to PQC, signaling a shift toward more operationally grounded engagement.[67] It distinguishes between safety-critical air traffic control systems and enterprise information technology environments, addresses harvest-now-decrypt-later risks for long-lived data, and solicits vendor input on phased deployment timelines and procurement architecture. This level of specificity is what allows responses to generate actionable implementation guidance rather than general expressions of industry readiness. Similar efforts are underway across the federal landscape, including guidance from CISA and standards development through NIST.[68]
Once agencies identify common implementation challenges, they should bring them into structured testing environments where solution providers can assess approaches against real-world use cases, determine what works, identify persistent gaps, and uncover tradeoffs organizations will need to manage. The National Cybersecurity Center of Excellence is particularly well positioned to take the challenges identified through RFIs and translate them into demonstration projects in this way.
The outputs of this work should be shared. Publishing implementation approaches, lessons learned, and reference architectures allows agencies and critical infrastructure operators to build on validated solutions rather than starting from scratch. Over time, this creates a more practical pathway for migration—one where tested solutions can be shared across the technology stack and adapted to different operational environments. In this way, RFIs can serve as the starting point for a continuous feedback loop: identifying common challenges, validating solutions through demonstration, and sharing results in a way that enables broader, more consistent progress.
- Launch Targeted Pilot Programs in High-Impact Environments
Agencies will encounter different obstacles as they begin integrating post-quantum solutions, so pilot programs will be key for moving from theoretical challenges to practical solutions. The Department of Energy and the Department of Defense are good candidates to lead early efforts, given the sensitivity of their data, the complexity of their systems, and the potential national security implications if those systems are compromised. The Department of the Treasury is also well positioned to participate in early efforts, as it secures financial systems, sanctions infrastructure, and stores data that must be protected over long periods. Finally, there would be value in including agencies with sector-specific responsibilities like the Department of Homeland Security and sector risk management agencies to help ensure that lessons learned are relevant to critical infrastructure operators.
The goal of such efforts would not be to fully define a preferred pathway in advance, but to begin working through options in context. Some pilot implementations would naturally move faster than others, and some would likely surface unexpected dependencies or constraints, but these challenges represent a lower risk than waiting for full clarity before acting, which will only compress the window for implementation later.
Over time, what matters most is how these efforts connect. Pilot programs should feed directly into federal guidance, procurement decisions, and standards development. Without that feedback loop, they risk becoming isolated efforts. With it, they become a strategic way to build practical knowledge so that PQC migration can move forward more consistently across government and critical infrastructure. - Leverage Market Signals and Private-Sector Leadership to Accelerate Adoption
Federal action is necessary but insufficient to drive PQC migration. The scale and complexity of PQC migration across U.S. critical infrastructure means that the government cannot bring about this transition alone, nor should it attempt to do so. Meanwhile, the private sector is already demonstrating that market-driven adoption is both possible and consequential, and policymakers should leverage that momentum.
Technology companies that embed PQC into their products and platforms effectively set baseline security expectations for the organizations and vendors that depend on them. This creates a multiplier effect: When a major cloud provider, communications platform, or financial infrastructure provider migrates, the downstream effects extend well beyond the migrating organization itself. Policymakers should seek to accelerate and broaden this dynamic rather than defaulting to federal mandates as the primary mechanism for driving PQC adoption.
Federal agencies should incorporate PQC readiness as an explicit requirement in procurement and contracting decisions, sending clear market signals that quantum-resistant security is a baseline expectation for conducting business with the government. Government and critical infrastructure sector risk management agencies should also work with industry to develop voluntary frameworks that help organizations of varying sizes assess and demonstrate their PQC readiness. This would reduce friction for smaller organizations that lack the resources to develop their own approaches.
Early movers in the private sector should be recognized and supported as resources in this transition rather than outliers. Organizations that invest in PQC migration ahead of regulatory requirements are generating practical knowledge about implementation challenges, integration constraints, and cost trade-offs that could benefit the broader ecosystem. Structured mechanisms—demonstration projects, working groups, or public-private information-sharing agreements—would allow leading-edge organizations to pull the rest of the ecosystem forward. In a transition of this scale and complexity, distributed, market-informed progress may prove more durable than centralized mandates alone.
Conclusion
PQC already appears on the radar of many policymakers, technologists, and industry leaders, but most still perceive Q-Day risks as distant and uncertain. Set against the immediate costs of migration, those distant risks understandably lose out to current, concrete needs, but leaders need to bridge this awareness-action gap now to avoid severe long-term consequences.
Doing so requires a shift in mindset and approach. Policymakers and stakeholders must appreciate that the post-quantum migration is not a discrete event that can be timed precisely or deferred until clearer signals emerge; it is a gradual, ecosystem-wide process that will intersect with broader efforts to modernize infrastructure and improve cyber resilience. They must also treat cybersecurity as a core facet of national security and strategic competition, as advances in technological innovation or capability do not translate into a durable strategic advantage if the systems that support and scale them are not secure.

For policymakers, the stakes extend beyond technical readiness. Quantum computing is increasingly part of strategic competition, particularly with China, which is investing heavily not only in advancing quantum capabilities but also in securing its own systems against them.[69] If China were to reach meaningful post-quantum readiness first, the advantage would not be theoretical. It would enable targeted access to sensitive government, military, and commercial systems while reducing its own exposure to similar risks. That imbalance would carry direct consequences for intelligence collection, operational planning, and military decision-making.
For critical infrastructure operators and technology leaders, the implication is equally clear. Waiting for certainty before initiating PQC migration is no longer a tenable position.[70] The foundational steps of conducting a cryptographic inventory, prioritizing the most sensitive long-lived data, and beginning migration where feasible are available now. While these actions cannot protect already-harvested data, they could mitigate the risk of future exposure. The critical takeaway is that decisions made now around system design, vendor selection, and data protection will shape exposure for years to come, particularly for systems that depend on long-term confidentiality and resilience.
The post-quantum transition will help define whether the United States can sustain its leadership in both technological innovation and national security. Cybersecurity is the foundation that enables both. Getting this migration right is what will ensure that U.S. systems—and the economy, technologies, and institutions they support—remain secure and resilient enough to lead.
The sources included in this paper were verified and active at the time of publication.
[1] Dan Goodin, “Recent advances push Big Tech closer to the Q-Day danger zone,” Ars Technica, April 17, 2026. https://arstechnica.com/security/2026/04/while-some-big-tech-players-accelerate-pqc-readiness-others-stay-the-course.
[2] Brady D. Lund and Sakib Shahriar, “Quantum Computing: A Concise Introduction,” Encyclopedia 5:4 (Oct. 15, 2025). https://www.mdpi.com/2673-8392/5/4/173; Gabriel Popkin, “Quantum Computing Explained,” National Institute of Standards and Technology, March 30, 2026. https://www.nist.gov/quantum-information-science/quantum-computing-explained; “What is Quantum Computing?,” AWS, last accessed April 24, 2026. https://aws.amazon.com/what-is/quantum-computing.
[3] Office of Science, “DOE Explains…Quantum Computing,” U.S. Department of Energy, last accessed April 24, 2026. https://www.energy.gov/science/doe-explainsquantum-computing.
[4] Popkin. https://www.nist.gov/quantum-information-science/quantum-computing-explained.
[5] Ibid.
[6] Beth Stackpole, “Quantum computing: What leaders need to know now,” MIT Management Sloan School, Jan. 11, 2024. https://mitsloan.mit.edu/ideas-made-to-matter/quantum-computing-what-leaders-need-to-know-now.
[7] Stackpole. https://mitsloan.mit.edu/ideas-made-to-matter/quantum-computing-what-leaders-need-to-know-now; “Shor’s algorithm,” IBM Quantum Platform, last accessed April 24, 2026. https://quantum.cloud.ibm.com/docs/en/tutorials/shors-algorithm.
[8] Ibid.
[9] Beth Stackpole, “Quantum report charts growing business interest, varied public awareness,” MIT Management Sloan School, Nov. 26, 2025. https://mitsloan.mit.edu/ideas-made-to-matter/quantum-report-charts-growing-business-interest-varied-public-awareness.
[10] “Q-Day Just Got Closer: Three Papers In Three Months Are Rewriting The Quantum Threat Timeline,” Quantum Insider, March 31, 2026. https://thequantuminsider.com/2026/03/31/q-day-just-got-closer-three-papers-in-three-months-are-rewriting-the-quantum-threat-timeline; Charlie Wood, “New Advances Bring the Era of Quantum Computers Closer Than Ever,” Quanta magazine, April 3, 2026. https://www.quantamagazine.org/new-advances-bring-the-era-of-quantum-computers-closer-than-ever-2026040.
[11] Paul Webster et al., “The Pinnacle Architecture: Reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes,” arXiv, Feb. 12, 2026. https://arxiv.org/html/2602.11457v1.
[12] Ibid.
[13] Madelyn Cain et al., “Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits,” arXiv, March 30, 2026. https://arxiv.org/abs/2603.28627.
[14] Ryan Babbush et al., “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations,” Google Quantum AI, March 30, 2026. https://quantumai.google/static/site-assets/downloads/cryptocurrency-whitepaper.pdf.
[15] Wood. https://www.quantamagazine.org/new-advances-bring-the-era-of-quantum-computers-closer-than-ever-2026040; “What is Q-Day?,” Palo Alto Networks, last accessed April 24, 2026. https://www.paloaltonetworks.com/cyberpedia/what-is-q-day.
[16] Amit Katwala, “The Quantum Apocalypse Is Coming. Be Very Afraid,” Wired, March 24, 2025. https://www.wired.com/story/q-day-apocalypse-quantum-computers-encryption; “RSA,” NIST Computer Security Resource Center, last accessed April 24, 2026. https://csrc.nist.gov/glossary/term/rsa; “Blockchain – Elliptic Curve Cryptography,” GeeksforGeeks, Oct. 11, 2025. https://www.geeksforgeeks.org/ethical-hacking/blockchain-elliptic-curve-cryptography.
[17] “What is Harvest Now, Decrypt Later (HNDL)?,” paloalto Networks, last accessed April 24, 2026. https://www.paloaltonetworks.com/cyberpedia/harvest-now-decrypt-later-hndl.
[18] “What is Q-Day?,” https://www.paloaltonetworks.com/cyberpedia/what-is-q-day.
[19] Ross Coffman, “We Are Already in Q-Day. We Just Haven’t Admitted It Yet.,” Cyber Defense Magazine, Feb. 13, 2026. https://www.cyberdefensemagazine.com/we-are-already-in-q-day-we-just-havent-admitted-it-yet.
[20] Nikita Ostrovsky, “AI Helped Spark a Quantum Breakthrough. The World ‘Is Not Prepared,’” Time, April 7, 2026. https://time.com/article/2026/04/07/ai-quantum-computing-advance.
[21] Tran Duc Le et al., “Are Enterprises Ready for Quantum-Safe Cybersecurity?,” arXiv, Sept. 1, 2025. https://arxiv.org/html/2509.01731v1; Danny Bradbury, “Survey: Security Pros Hit Snooze Button on Quantum Computing Alarm,” Tanium, Aug. 14, 2025. https://www.tanium.com/blog/survey-security-pros-hit-snooze-button-on-quantum-computing-alarm.
[22] Francis Kagai, “Harvest-Now, Decrypt-Later: A Temporal Cybersecurity Risk in the Quantum Transition,” Telecom 6:4 (Dec. 18, 2025). https://www.mdpi.com/2673-4001/6/4/100; Javier Blanco-Romero et al., “On the Practical Feasibility of Harvest-Now, Decrypt-Later Attacks,” arXiv, March 1, 2026. https://arxiv.org/html/2603.01091v1.
[23] “A practical guide to securing the enterprise for the quantum era,” PQ Shield, last accessed April 24, 2026. https://pqshield.com/post-quantum-cryptography-companies; Gaurab Chhetri et al., “Post-Quantum Cryptography and Quantum-Safe Security: A Comprehensive Survey,” arXiv, Oct. 12, 2025. https://arxiv.org/html/2510.10436v1.
[24] Duc Le et al. https://arxiv.org/html/2509.01731v1; Bradbury. https://www.tanium.com/blog/survey-security-pros-hit-snooze-button-on-quantum-computing-alarm.
[25] “Post-quantum cryptography,” Google Cloud, last accessed April 24, 2026. https://cloud.google.com/security/resources/post-quantum-cryptography; Bas Westerbaan, “Cloudflare targets 2029 for full post-quantum security,” Cloudflare, April 7, 2026. https://blog.cloudflare.com/post-quantum-roadmap; Rafael Misoczki et al., “Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways,” Meta, April 16, 2026. https://engineering.fb.com/2026/04/16/security/post-quantum-cryptography-migration-at-meta-framework-lessons-and-takeaways.
[26] Nick Barney et al., “What is post-quantum cryptography? Comprehensive guide,” TechTarget, July 2, 2025. https://www.techtarget.com/searchsecurity/definition/post-quantum-cryptography.
[27] Tushin Mallick et al., “Study of Post-Quantum status of Widely Used Protocols,” arXiv, March 30, 2026. https://arxiv.org/html/2603.28728v1; Tanmay Tripathi et al., “Post Quantum Cryptography & its Comparison with Classical Cryptography,” arXiv, March 28, 2024. https://arxiv.org/html/2403.19299v1.
[28] “What Is Post-Quantum Cryptography?,” NIST, last accessed April 24, 2026. https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography.
[29] “What ‘post-quantum’ means for cybersecurity,” PQ Shield, last accessed April 24, 2026. https://pqshield.com/what-post-quantum-means-for-cyber-security; Edward Parker, “U.S.-Allied Militaries Must Prepare for the Quantum Threat to Cryptography,” RAND, June 6, 2025. https://www.rand.org/pubs/commentary/2025/06/us-allied-militaries-must-prepare-for-the-quantum-threat.html.
[30] Sarah Simpson, “Cryptography Defined/Brief History,” University of Texas at Austin, Spring 1997. https://www.laits.utexas.edu/~anorman/BUS.FOR/course.mat/SSim/history.html; Michele Mosca and Donna Dodson, “Here’s why it’s important to build long-term cryptographic resilience,” World Economic Forum, Dec. 20, 2024. https://www.weforum.org/stories/2024/12/cryptographic-resilience-build-cybersecurity-nist.
[31] Joe Guerra, “Breaking Traditional Encryption Protocols: Quantum Computing and the Future of Secure Communications,” Cyber Defense Magazine, Feb. 24, 2026. https://www.cyberdefensemagazine.com/breaking-traditional-encryption-protocols-quantum-computing-and-the-future-of-secure-communications; “Report on Post-Quantum Cryptography,” The White House, July 2024. https://bidenwhitehouse.archives.gov/wp-content/uploads/2024/07/REF_PQC-Report_FINAL_Send.pdf.
[32] “Post-Quantum Cryptography,” Department of Homeland Security, last accessed April 24, 2026. https://www.dhs.gov/quantum; “Post-quantum cryptography for modern security,” PQ Shield, last accessed April 24, 2026. https://pqshield.com/post-quantum-cryptography; “Post-Quantum Cryptography,” Commvault, last accessed April 24, 2026. https://www.commvault.com/explore/post-quantum-cryptography.
[33] “Post-Quantum Cryptography,” Department of Homeland Security. https://www.dhs.gov/quantum; Oleksii Borysenko, “How Post-Quantum Cryptography Affects Security and Encryption Algorithms,” Cisco, July 11, 2025. https://blogs.cisco.com/developer/how-post-quantum-cryptography-affects-security-and-encryption-algorithms; “The Risks of Post-Quantum Cryptography in a Quantum Future,” Quantropi, last accessed April 24, 2026. https://www.quantropi.com/the-risks-of-post-quantum-cryptography-in-a-quantum-future.
[34] Ibid.
[35] “Quantum Computing: Updating the National Strategy Could Promote U.S. Leadership,” U.S. Government Accountability Office, March 18, 2026. https://www.gao.gov/products/gao-26-107759.
[36] “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” NIST, Aug. 13, 2024. https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards; National Cybersecurity Center of Excellence, “Migration to Post-Quantum Cryptography,” NIST, last accessed April 24, 2026. https://www.nccoe.nist.gov/applied-cryptography/migration-to-pqc; Eric Geller, “NIST explains how post-quantum cryptography push overlaps with existing security guidance,” Cybersecurity Dive, Sept. 19, 2025. https://www.cybersecuritydive.com/news/nist-post-quantum-cryptography-guidance-mapping/760638.
[37] “Changes to National Cyber Policy in the Trump Administration,” The White House, June 18, 2025. https://www.congress.gov/crs_external_products/IN/HTML/IN12570.html; “President Trump’s Cyber Strategy for America,” The White House, March 2026. https://www.whitehouse.gov/wp-content/uploads/2026/03/president-trumps-cyber-strategy-for-america.pdf; Corie Whalen, “Statement responding to the Trump administration’s new National Cybersecurity Strategy,” R Street Institute, March 6, 2026. https://www.rstreet.org/commentary/statement-responding-to-the-trump-administrations-new-national-cybersecurity-strategy.
[38] “H.R. 3259, the Post Quantum Cybersecurity Standards Act,” House Committee on Science, Space, and Technology, May 7, 2025. https://republicans-science.house.gov/2025/5/h-r-3259-the-post-quantum-cybersecurity-standards-act; John Curran, “Bipartisan House Bill Aims to Speed Quantum Security Work,” MeriTalk, Aug. 12, 2025. https://www.meritalk.com/articles/bipartisan-house-bill-aims-to-speed-quantum-security-work.
[39] “S.2558 – The National Quantum Cybersecurity Migration Strategy Act of 2025,” Congress.gov, July 30, 2025. https://www.congress.gov/bill/119th-congress/senate-bill/2558; “S. 3312 – Quantum Readiness and Innovation Act of 2025,” Congress.gov, Dec. 2, 2025. https://www.congress.gov/bill/119th-congress/senate-bill/3312.
[40] “Senate Commerce Committee Unanimously Passes National Quantum Initiative Reauthorization Act,” Quantum Computing Report, April 19, 2026. https://quantumcomputingreport.com/senate-commerce-committee-unanimously-passes-national-quantum-initiative-reauthorization-act; “H.R.3788 – Support for Quantum Supply Chains Act,” Congress.gov, June 5, 2025. https://www.congress.gov/bill/119th-congress/house-bill/3788.
[41] Terry Gerton, “Quantum computing is a national priority, but who’s actually in charge?,” Federal News Network, April 22, 2026. https://federalnewsnetwork.com/technology-main/2026/04/quantum-computing-is-a-national-priority-but-whos-actually-in-charge.
[42] “Critical Infrastructure Sectors,” Cybersecurity & Infrastructure Security Agency, last accessed April 24, 2026. https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors.
[43] Jen Easterly and Tom Fanning, “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years,” Cybersecurity & Infrastructure Security Agency, May 7, 2023. https://www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years; Vijay A. D’Souza, “SolarWinds Cyberattack Demands Significant Federal and Private-Sector Response (infographic),” U.S. Government Accountability Office, April 22, 2021. https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic.
[44] Brian E. Humphreys, “Critical Infrastructure: Emerging Trends and Policy Considerations for Congress,” Library of Congress, March 10, 2026. https://www.congress.gov/crs-product/R48878; Paul Rosenzweig, “Turns Out It Is Not 85 Percent,” Lawfare, June 2, 2022. https://www.lawfaremedia.org/article/turns-out-it-not-85-percent.
[45] James McBride and Noah Berman, “How U.S. Water Infrastructure Works,” Council on Foreign Relations, May 2, 2024. https://www.cfr.org/backgrounders/how-us-water-infrastructure-works.
[46] “Changes to National Cyber Policy in the Trump Administration,” https://www.congress.gov/crs_external_products/IN/HTML/IN12570.html; “President Trump’s Cyber Strategy for America.” https://www.whitehouse.gov/wp-content/uploads/2026/03/president-trumps-cyber-strategy-for-america.pdf.
[47] Evan Schuman, “NIST publishes timeline for quantum-resistant cryptography, but enterprises must move faster,” CSO, Nov. 13, 2024. https://www.csoonline.com/article/3604824/nist-publishes-timeline-for-quantum-resistant-cryptography-but-enterprises-must-move-faster.html; Dina Genkina, “Is the World Adopting Post-Quantum Cryptography Fast Enough?,” IEEE Spectrum, Aug. 13, 2025. https://spectrum.ieee.org/post-quantum-cryptography-standards-nist; John Hewitt Jones, “NSA sets 2035 deadline for adoption of post-quantum cryptography across national security systems,” FedScoop, Sept. 7, 2022. https://fedscoop.com/nsa-sets-2035-deadline-for-adoption-of-post-quantum-cryptography-across-natsec-systems.
[48] Erica Portnoy, “Yikes, Encryption’s Y2K Moment is Coming Years Early,” Electronic Frontier Foundation, April 9, 2026. https://www.eff.org/deeplinks/2026/04/yikes-encryptions-y2k-moment-coming-years-early.
[49] Charlie Lewis et al., “Quantum is almost here: Are you and your systems ready?,” McKinsey & Company, April 24, 2026. https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/quantum-is-almost-here-are-you-and-your-systems-ready.
[50] Shaun Waterman, “Crypto is a mess inside enterprises,” CyberScoop, Oct. 14, 2016. https://cyberscoop.com/encryption-pki-enterprises-certificate-authority-a-mess; Marc Manzano and Ryan Hurst, “Cryptography: A Forgotten Part of Software Supply Chain Security,” SandboxAQ, Aug. 15, 2024. https://www.sandboxaq.com/post/cryptography-a-forgotten-part-of-software-supply-chain-security; Anna Ribeiro, “Industrial systems face structural gap as quantum risks drive urgency for crypto-agility and post-quantum readiness,” Industrial Cyber, April 12, 2026. https://industrialcyber.co/features/industrial-systems-face-structural-gap-as-quantum-risks-drive-urgency-for-crypto-agility-and-post-quantum-readiness.
[51] “What is Cyber Hygiene?,” proofpoint, last accessed April 24, 2026. https://www.proofpoint.com/us/threat-reference/cyber-hygiene; “Basic cyber hygiene prevents 99% of attacks,” Microsoft, Aug. 31, 2023. https://www.microsoft.com/en-us/security/security-insider/risk-management/risk-management-hygiene-guide; Murali Palanisamy, “Using Post-Quantum Planning to Improve Security Hygiene,” Dark Reading, April 9, 2025. https://www.darkreading.com/vulnerabilities-threats/post-quantum-planning-security-hygiene.
[52] Kelli Hartwick and Iain Beveridge, “Resilience and Recovery: Mitigating Threats in the PQ Era,” Veeam, March 24, 2026. https://www.veeam.com/blog/veeam-entrust-pqc-backup-recovery.html; Chuck Suter, “Are Your Backups Quantum Safe?,” World Wide Technology, Aug. 28, 2025. https://www.wwt.com/blog/are-your-backups-quantum-safe.
[53] Ibid.
[54] Anna Ribeiro, “NIST advances CMVP modernization to close gap between cryptographic innovation and validation capacity,” Industrial Cyber, April 17, 2026. https://industrialcyber.co/nist/nist-advances-cmvp-modernization-to-close-gap-between-cryptographic-innovation-and-validation-capacity.
[55] “Post-quantum cryptography: A federal modernization moment,” Leidos, March 27, 2026. https://www.leidos.com/insights/post-quantum-cryptography-federal-modernization-moment; David Mussington, “Entangled Migrations PQC, QKD, and US-PRC Risk Postures for Critical Infrastructure,” Institute for Critical Infrastructure Technology, March 20, 2026. https://www.icitech.org/post/entangled-migrations-pqc-qkd-and-us-prc-risk-postures-for-critical-infrastructure; Alejandro R.-P. Montblanch et al., “Quantum-safe migration: Why now is an opportunity to modernize cryptography for the new age,” World Economic Forum, Jan. 26, 2026. https://www.weforum.org/stories/2026/01/quantum-safe-migration-cryptography-cybersecurity.
[56] “Post-quantum cryptography: A federal modernization moment.” https://www.leidos.com/insights/post-quantum-cryptography-federal-modernization-moment.
[57] Ibid.
[58] Jon Clay, “U.S. Public Sector Under Siege: Threat Intelligence for Q1 2026,” Trend, April 9, 2026. https://www.trendmicro.com/en_us/research/26/d/us-public-sector-under-siege.html; “China-Linked Cyber Operations Targeting US Critical Infrastructure,” New Jersey Cybersecurity & Communications Integration Cell, May 2025. https://www.cyber.nj.gov/threat-landscape/nation-state-threat-analysis-reports/china-linked-cyber-operations-targeting-us-critical-infrastructure.
[59] Javier Oliva delMoral et al., “Cybersecurity in Critical Infrastructures: A Post-Quantum Cryptography Perspective,” arXiv, June 11, 2024. https://arxiv.org/html/2401.03780v2.
[60] Joseph Federici, “Vying for Quantum Supremacy: U.S.–China Competition in Quantum Technologies,” U.S.–China Economic and Security Review Commission, Nov. 18, 2025. https://www.uscc.gov/research/vying-quantum-supremacy-us-china-competition-quantum-technologies.
[61] Laurie Chen, “China likely to have standards for post-quantum cryptography in 3 years, expert says,” Reuters, March 18, 2026. https://www.reuters.com/world/asia-pacific/china-likely-have-standards-post-quantum-crytography-3-years-expert-says-2026-03-19.
[62] Ibid.
[63] Wei Meng, “Accelerating the Deployment of China’s National Standard and Industrialisation of Quantum Resistant Cryptography (PQC) Proposal for Building National Security ‘Double Insurance’ in Quantum Era,” SSRN, Sept. 8, 2025. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5402545.
[64] Brad Smith, “Investing in American leadership in quantum technology: the next frontier in innovation,” Microsoft, April 28, 2025. https://blogs.microsoft.com/on-the-issues/2025/04/28/investing-in-american-leadership-quantum; “Post-quantum cryptography.” https://cloud.google.com/security/resources/post-quantum-cryptography; Westerbaan. https://blog.cloudflare.com/post-quantum-roadmap.
[65] Robert Campbell, “Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks,” Computers 15:1 (Dec. 24, 2025). https://www.mdpi.com/2073-431X/15/1/9; Val Moon and Hugo Holopainen, “Entangled migrations: PQC, QKD, and US-PRC risk postures for critical infrastructure,” SC Media, March 23, 2026. https://www.scworld.com/perspective/entangled-migrations-pqc-qkd-and-us-prc-risk-postures-for-critical-infrastructure; “Best Practices for Resisting Post-Quantum Attacks,” Palo Alto Techdocs, April 2, 2026. https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/best-practices-for-resisting-post-quantum-attacks.
[66] Ibid.
[67] “Request for Information: Post Quantum Cryptography Support for FAA Information Technology and National Air Space Systems,” Federal Aviation Administration, March 10, 2026. https://fedscoop.com/wp-content/uploads/sites/5/2026/03/PCQRFI697DCK-26-RFI-PQCFinal.pdf.
[68] “CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump’s Executive Order 14306,” Cybersecurity & Infrastructure Security Agency, Jan. 23, 2026. https://www.cisa.gov/news-events/news/cisa-releases-product-categories-list-propel-post-quantum-cryptography-adoption-pursuant-president; Tracye Winfrey Howard et al., “Migrating from Traditional Algorithms to Post-Quantum Cryptography: What Your Organization Needs to Know,” JD Supra, Feb. 6, 2026. https://www.jdsupra.com/legalnews/migrating-from-traditional-algorithms-6746255.
[69] Smith. https://blogs.microsoft.com/on-the-issues/2025/04/28/investing-in-american-leadership-quantum.
[70] Han Lee, “Why full-stack post-quantum cryptography cannot wait,” Cisco, April 1, 2026. https://blogs.cisco.com/networking/why-full-stack-post-quantum-cryptography-cannot-wait.