Nation-state adversaries and cybercriminal organizations alike are investing heavily in quantum research, motivated by the promise of breaking public key cryptography as we know it. As leaders responsible for protecting federal systems and critical national infrastructure, we must move beyond awareness and toward aggressive, strategic implementation.
Over the past few years, the technological advancements in quantum computing have created a sense of urgency. The federal cybersecurity community now has the clarity it needs to act. With the National Institute for Standards and Technology (NIST) finalizing the first PQC standards in 2024, the publication of NIST IR 8545 providing a structured migration roadmap, and OMB’s M-23-02 mandate requiring annual reporting on quantum-vulnerable assets, agencies have clear marching orders. Combined with CNSS timelines that target 2030 for deprecating vulnerable cryptography and 2035 for classified systems, the path forward is defined—but the window for action is narrowing.
Early signals from the Trump Administration suggest continuity in prioritizing quantum-readiness, albeit with an eye toward cost-efficiency and mission assurance. The trends point to reaffirmation that quantum-readiness remains a bipartisan priority.
Adding urgency to these efforts, a recent study estimates that transitioning U.S. federal systems to post-quantum cryptography will cost approximately $7.1 billion. This figure underscores the significant investment required to secure national security systems against future quantum threats.
Taken together, these developments signal an inflection point. We are no longer discussing "if" quantum computers will impact national security, but "when," and what measures need to be planned and implemented.
For federal leaders looking for practical frameworks to start their journey, our recent Carahsoft webinar featuring Tanium, Accenture Federal Services, and NIST experts offered actionable guidance on the steps agencies should take now. For a deeper dive into emerging quantum standards, practical cryptographic inventory strategies, and government-industry collaboration, you can explore recent discussions hosted by leading experts in that webinar here.
The quantum threat: Strategic and tactical realities
The looming quantum challenge resembles the Y2K era in complexity and urgency: tight timelines, complex interdependencies, and mission-critical systems at stake. But today, the stakes are even higher.
Federal leaders must internalize three critical realities about the quantum threat:
- Comprehensive cryptographic inventory
Inventory is not "nice to have"—it is the foundation of any migration strategy. Without clear, automated discovery of certificates, libraries, protocols, and cryptographic modules in use across your enterprise, you are flying blind.
Modern platforms like Tanium Certificate Manager offer the ability to automate discovery at scale, uncovering vulnerabilities that spreadsheets and manual processes simply can't detect.
As Bill Newhouse from NIST emphasized during our discussion, most agencies underestimate the sprawl of cryptography across their environments. Without modern tools, they risk missing critical assets—or discovering too late that their systems are quantum-vulnerable. - Prioritization and risk management
Not all cryptographic assets are created equal. Agencies must prioritize based on:
• Data sensitivity (e.g., PII, national security data) • Mission criticality (e.g., command-and-control, public health systems) • Threat exposure (e.g., external-facing systems) Layering PQC migration into Zero Trust architectures provides a strategic path forward, merging initiatives rather than duplicating them. - Test, test, and test again
Hybrid cryptographic implementations—blending classical and quantum-safe algorithms—introduce new performance and interoperability challenges. TLS sessions, certificate chains, buffer sizes: all must be tested exhaustively.
Federal practitioners must build testbeds now. Waiting for "perfect" PQC solutions to mature is a strategic mistake. Early adoption of hybrid implementations, with controlled risk management, is critical.
Solutions showcased recently—including automated certificate discovery and real-time cryptographic visibility from Tanium and Accenture Federal Services—highlight what a pragmatic testing and migration path can look like. - Leadership education and strategic communication
Leadership must be brought into the quantum-readiness conversation now. CIOs and CISOs must understand that quantum cryptography migration is not a technology problem alone—it is an enterprise risk management problem.
Budget cycles are tight. Mission demands are increasing. Quantum migration must be framed not as an IT initiative but as essential to national security, operational resilience, and regulatory compliance.
[Go further: This pocket guide offers 7 steps for a quantum cybersecurity plan]
Looking forward: The path to quantum-resilient federal systems
There is no single "quantum day" when systems will break overnight. Rather, the erosion of trust in legacy cryptography will be gradual—and the agencies that move fastest today will maintain operational advantage tomorrow.
Key elements of successful quantum migration programs will include:
- Early pilot programs using NIST-approved PQC algorithms
- Cross-functional migration teams blending cybersecurity, application owners, procurement officials, and legal advisors
- Supplier engagement ensuring vendors embed PQC into future procurements
- Continuous monitoring and crypto-agility allowing rapid response to evolving threats and standards
Migration is not simply "rip and replace." It is a transformation in how we view, manage, and protect data at-rest and in-transit.
Unified action, urgent mission
Across the public and private sectors, one truth stands clear: The post-quantum cryptography threat is real. The clock is ticking. And the window for action is now.
As a federal IT and cybersecurity community, we have navigated transformational challenges before—from Y2K to cloud adoption and Zero Trust. The post-quantum transition demands that same spirit of collaboration, ingenuity, and relentless execution.
The security of our missions—and the trust of the American people—depend on it. Let's get to work.
