up:: 00 Start Here

For Policymakers

Governments reached their conclusion on this some time ago. The United States has written deadlines into executive orders and agency memoranda, the NSA has published its own schedule, and comparable rules exist across Europe, the UK, Canada, Australia, and Japan. The legislative question isn’t whether the risk is real, because that’s settled in published policy.

What’s genuinely open is harder: whether the deadlines are achievable, who pays, what happens to organizations and countries that can’t comply, and how much of a nation’s critical infrastructure is running on encryption nobody has inventoried.

5 things you must understand about Q-Day

  1. Whether it’s real is already settled in published policy. The U.S., the U.K., Germany, France, Canada, Australia, and the EU each reached that conclusion independently and published dated schedules. The open questions are achievability, funding, and what happens to those who can’t comply.
  2. For critical infrastructure the threat is forgery rather than eavesdropping. Nobody cares about reading an old command to open a valve. They care about issuing a new one that verifies as authentic, and that capability arrives live rather than retroactively.
  3. The collection happening now is undetectable and covered by no notification duty. Copying encrypted traffic enters no system and leaves no artifact, so no breach law is triggered and no attribution is available.
  4. No announcement is coming. Every major cryptographic break in the historical record stayed secret while it remained useful, so policy that waits for confirmation is waiting for an event that won’t occur.
  5. Migration takes about a decade at national scale. The U.S. schedule for federal civilian systems runs 2025 to 2035 at a projected $7.1 billion, which makes deadlines set years out already tight rather than generous.

Source: CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, CSI factsheet; Office of Management and Budget, “Report on Post-Quantum Cryptography,” July 2024, OMB PQC Report.

The short version:

  • The replacement encryption standards were finalized by NIST in August 2024, so the technical solution exists and is published.
  • The U.S. schedule retires today’s public-key encryption: the weaker key sizes deprecated after 2030, and everything classical disallowed after 2035 regardless of size.
  • Multiple binding instruments already exist, including executive orders, OMB memoranda, an act of Congress, and NSA requirements for national-security systems.
  • Most organizations can’t yet answer the first question a regulator will ask, which is where their cryptography actually lives.
  • A large share of the problem sits inside purchased products, so the organization holding the risk often can’t fix it without the vendor.
  • The migration is slow by nature, and historically this class of change takes a decade or more, which is why deadlines set years out are already tight.
  • No announcement is coming. Every major cryptographic break in the record stayed secret while it was useful, so planning that waits for confirmation is planning against the wrong event.

What lives here

Need it on one page? The one-page briefing is the whole issue, sourced, printable, for a member or a staffer with 5 minutes.

  1. What laws and rules already exist? The U.S. instruments in plain terms: the executive orders, the OMB memoranda, the act of Congress, and the NSA’s schedule.
  2. What are other countries doing? How the European, British, German, French, Canadian, Australian, and Japanese approaches compare, and where they diverge.
  3. Is anyone coordinating this internationally? Whether nations trust one another’s standards, and what happens when they don’t.
  4. What happens to countries that can’t afford to migrate? The equity problem, and why an uneven transition is a global security problem rather than a national one.
  5. What critical infrastructure is exposed? Power, water, health systems, transport, and the equipment that can’t be updated over the air.
  6. What isn’t legislated yet? The gaps, including liability, private-sector obligations, and long-lived consumer data.
  7. Who pays for this? Public funding, unfunded mandates, and the organizations with no capacity to comply.
  8. What does history tell us about broken codes? Venona, Enigma, and why every previous break stayed secret while it mattered.
  9. What should a government actually do? The concrete list, sorted by what works this year versus what needs a legislative cycle.
  10. What should I ask in a hearing or briefing? The questions that produce real answers rather than reassurance.
  11. What is technically happening to national systems? The mechanism at national scale: classification horizons, national trust anchors, and why allied algorithm choices already differ.
  12. Model legislative language Draft statutory language for the 3 unclosed gaps, with a sourced findings section, drafting notes, the objection each provision will face, and a one-page member summary.
  13. What about the rest of the world? India’s roadmap, with a critical-infrastructure target ahead of every Western timeline, Japan’s standards body, and how much of the world has published nothing.
  14. What can a state actually do? The levers a U.S. state holds that Congress does not, 3 of which need no legislation at all.
  15. What can a city actually do? The layer no post-quantum mandate reaches, why most of a city’s posture was never a city decision, the email lane almost nobody checks, and procurement language a city can adopt in a quarter without a council vote.
  16. What a mayor needs to know The 4 things only a city’s chief executive can do, all administrative and none costing money, what a mayor gets asked publicly and what a defensible answer sounds like, and the first-mover position no US city has claimed. First of the by-role briefings.
  17. What a governor needs to know Why a governor holds the only lever that currently reaches the uncovered municipal layer, the 5 actions available by executive authority alone, and the pass-through condition no state has used.
  18. What a member of Congress needs to know The 8 documented gaps as a legislative agenda, the existing grant program whose funding phase is ending that is the cheapest vehicle for closing the municipal gap, and 5 oversight questions where question 1 has no affirmative answer today.
  19. What a state legislator needs to know Why the breach-notification statute is the most natural home in American law for the foundational gap, the 4 things that need a statute rather than an executive directive, the one drafting trap that kills the effort, and the precedent for a state going first on exactly this category of harm.
  20. What a city council member needs to know Why a council’s power here is the record rather than the directive, the one question with no affirmative answer, what to do when the answer is “we follow federal guidance,” and why a reporting requirement outlasts every administration that would issue a directive instead.
  21. What an agency head needs to know The only role in the set that needs nobody’s permission, the 5 actions available this month without a policy or an appropriation, why the honest scope is smaller than most directors assume, and why the person who ends up answering is the one who operates the systems.
  22. What an international organization needs to know The entity type no cryptographic mandate reaches at all, why consolidation removes the independence these institutions are built to have, and the 5 actions available without any member state agreeing to anything.
  23. Are refugee records safe? The hardest case in the exposure landscape: unreissuable identifiers, a lifetime horizon, a population selected for vulnerability, and the one adversary whose motive is not speculative.
  24. What is China doing? The parallel standards track, why a country builds its own algorithms, and exactly what the evidence does and doesn’t support about harvesting.

Why this reaches beyond national policy

Encryption is the layer that lets institutions in different countries trust each other’s messages, payments, and identity documents. It’s shared infrastructure with no single owner, and it’s being replaced everywhere at once on schedules that don’t match.

That creates three problems a purely national approach leaves open. Countries migrating at different speeds lose interoperability with each other. Countries lacking the resources to migrate become the weak point everyone else routes through. And data collected today crosses borders continuously, so a nation’s exposure extends well past its own networks.

Where to go next

  • Start here if you want the underlying mechanism first, with no background assumed.
  • For business leaders covers the private-sector side, which is where most of the affected data actually sits.

Go deeper into the technical detail

The Mandates MOC is the full technical index of every regulation, with primary sources. Why Is Quantum Readiness a Governance Problem is the technical treatment of why this stalls inside organizations. The arguments collect the policy-layer cases: The Coalition Interoperability Gap on allies migrating to different requirements on different clocks, and The Quantum Capability Asymmetry on why nobody can verify who gains the ability to decrypt.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.