Skip to main content
Modernizing federal cryptography in the quantum age featured blog image
Emerging Issue

Modernizing federal cryptography in the quantum age: From urgency to unified action

Quantum computing is no longer a distant threat on the horizon. It is rapidly materializing into a real, operational risk to the foundations of our cybersecurity ecosystem.

Nation-state adversaries and cybercriminal organizations alike are investing heavily in quantum research, motivated by the promise of breaking public key cryptography as we know it. As leaders responsible for protecting federal systems and critical national infrastructure, we must move beyond awareness and toward aggressive, strategic implementation.

Over the past few years, the technological advancements in quantum computing have created a sense of urgency. The federal cybersecurity community now has the clarity it needs to act. With the National Institute for Standards and Technology (NIST) finalizing the first PQC standards in 2024, the publication of NIST IR 8545 providing a structured migration roadmap, and OMB’s M-23-02 mandate requiring annual reporting on quantum-vulnerable assets, agencies have clear marching orders. Combined with CNSS timelines that target 2030 for deprecating vulnerable cryptography and 2035 for classified systems, the path forward is defined—but the window for action is narrowing.

Early signals from the Trump Administration suggest continuity in prioritizing quantum-readiness, albeit with an eye toward cost-efficiency and mission assurance. The trends point to reaffirmation that quantum-readiness remains a bipartisan priority.

Adding urgency to these efforts, a recent study estimates that transitioning U.S. federal systems to post-quantum cryptography will cost approximately $7.1 billion. This figure underscores the significant investment required to secure national security systems against future quantum threats.

Taken together, these developments signal an inflection point. We are no longer discussing "if" quantum computers will impact national security, but "when," and what measures need to be planned and implemented.

[Did you know: 62% of technology and cybersecurity professionals worry quantum will break today’s internet encryption]

For federal leaders looking for practical frameworks to start their journey, our recent Carahsoft webinar featuring Tanium, Accenture Federal Services, and NIST experts offered actionable guidance on the steps agencies should take now. For a deeper dive into emerging quantum standards, practical cryptographic inventory strategies, and government-industry collaboration, you can explore recent discussions hosted by leading experts in that webinar here.

The quantum threat: Strategic and tactical realities

The looming quantum challenge resembles the Y2K era in complexity and urgency: tight timelines, complex interdependencies, and mission-critical systems at stake. But today, the stakes are even higher.

Federal leaders must internalize three critical realities about the quantum threat:

  1. Comprehensive cryptographic inventory
    Inventory is not "nice to have"—it is the foundation of any migration strategy. Without clear, automated discovery of certificates, libraries, protocols, and cryptographic modules in use across your enterprise, you are flying blind.
    Modern platforms like Tanium Certificate Manager offer the ability to automate discovery at scale, uncovering vulnerabilities that spreadsheets and manual processes simply can't detect.
    As Bill Newhouse from NIST emphasized during our discussion, most agencies underestimate the sprawl of cryptography across their environments. Without modern tools, they risk missing critical assets—or discovering too late that their systems are quantum-vulnerable.
  2. Prioritization and risk management
    Not all cryptographic assets are created equal. Agencies must prioritize based on:
    • Data sensitivity (e.g., PII, national security data) • Mission criticality (e.g., command-and-control, public health systems) • Threat exposure (e.g., external-facing systems) Layering PQC migration into Zero Trust architectures provides a strategic path forward, merging initiatives rather than duplicating them.
  3. Test, test, and test again
    Hybrid cryptographic implementations—blending classical and quantum-safe algorithms—introduce new performance and interoperability challenges. TLS sessions, certificate chains, buffer sizes: all must be tested exhaustively.
    Federal practitioners must build testbeds now. Waiting for "perfect" PQC solutions to mature is a strategic mistake. Early adoption of hybrid implementations, with controlled risk management, is critical.
    Solutions showcased recently—including automated certificate discovery and real-time cryptographic visibility from Tanium and Accenture Federal Services—highlight what a pragmatic testing and migration path can look like.
  4. Leadership education and strategic communication
    Leadership must be brought into the quantum-readiness conversation now. CIOs and CISOs must understand that quantum cryptography migration is not a technology problem alone—it is an enterprise risk management problem.
    Budget cycles are tight. Mission demands are increasing. Quantum migration must be framed not as an IT initiative but as essential to national security, operational resilience, and regulatory compliance.

[Go further: This pocket guide offers 7 steps for a quantum cybersecurity plan]

Looking forward: The path to quantum-resilient federal systems

There is no single "quantum day" when systems will break overnight. Rather, the erosion of trust in legacy cryptography will be gradual—and the agencies that move fastest today will maintain operational advantage tomorrow.

Key elements of successful quantum migration programs will include:

  • Early pilot programs using NIST-approved PQC algorithms
  • Cross-functional migration teams blending cybersecurity, application owners, procurement officials, and legal advisors
  • Supplier engagement ensuring vendors embed PQC into future procurements
  • Continuous monitoring and crypto-agility allowing rapid response to evolving threats and standards

Migration is not simply "rip and replace." It is a transformation in how we view, manage, and protect data at-rest and in-transit.

Unified action, urgent mission

Across the public and private sectors, one truth stands clear: The post-quantum cryptography threat is real. The clock is ticking. And the window for action is now.

As a federal IT and cybersecurity community, we have navigated transformational challenges before—from Y2K to cloud adoption and Zero Trust. The post-quantum transition demands that same spirit of collaboration, ingenuity, and relentless execution.

The security of our missions—and the trust of the American people—depend on it. Let's get to work.

[Listen also: Accenture’s Stephen Harper has a hack for federal agencies – here’s how to take data and modify it to meet new quantum reporting requirements]