up:: For Press
For a policy audience
Everything a policy piece needs, in the order it’s usually needed. Two threads carry most of the substance: cryptography has decided the outcome of conflicts for centuries and the record is documentary, and the risk currently sits with parties who never agreed to carry it.
What’s the story in one paragraph?
Multiple governments concluded independently that this is real and published dated schedules against it, so the legislative question isn’t whether to believe it. Classified material carries confidentiality horizons of 25 to 75 years, which places traffic recorded today well inside its own exposure window, and the collection is undetectable, triggers no notification duty, and supports no attribution. For critical infrastructure the threat is forgery rather than eavesdropping, meaning an attacker issuing commands that verify as authentic, and it arrives live on the day a capable machine exists. The gaps that remain are notification, liability, funding for operators with no capacity, and any requirement that long-lived equipment be updatable at all, and the last of those becomes permanently unfixable for hardware fielded while it stays open.
What are the 5 most important things?
- Whether it’s real is settled in published policy. The U.S., U.K., Germany, France, Canada, Australia, and the EU each reached that conclusion independently and published dated schedules. Three of those regimes arrived at the end of 2030 without coordinating.
- Classified material is inside its own exposure window. U.S. classification horizons run 25 years, extendable to 50 and 75 for defined categories, against a machine plausibly arriving inside 10 to 15. That arithmetic needs no forecast.
- For infrastructure the threat is forgery, and it arrives live. Nobody cares about reading an old command to open a valve. They care about issuing a new one that verifies as authentic, which is a present-tense capability the day the machine exists rather than a retroactive disclosure.
- Nobody will be notified, and no announcement is coming. Collection leaves no artifact, so no breach law is triggered and no attribution is available. Every major cryptographic break in the historical record stayed secret while it remained useful.
- What to do about it, ordered by what needs legislation. Put a post-quantum requirement into public procurement, which costs nothing and moves the whole supplier base immediately. Require an algorithm-level inventory from agencies and regulated entities, since nothing can be sequenced without it. Fund the operators without capacity, because a mandate they can’t afford produces documented non-compliance rather than migration. Require that long-lived products be updatable, which is the only gap that closes permanently now and becomes unfixable later. And close the notification gap, drafted on a records model rather than a detection model.
What does the record show about cryptography deciding outcomes?
Documentary, and it’s the part that resists dismissal as speculation.
Venona. From 1943, American codebreakers intercepted and stored Soviet diplomatic and intelligence cables. The traffic used one-time pads, which are mathematically unbreakable when used correctly, so at collection the messages were genuinely unreadable and the Soviets treated them as permanently safe. Wartime pressure caused pad pages to be duplicated, and a one-time pad reused even once stops being unbreakable. From around 1946 the project began reading the backlog. The work ran for decades and didn’t formally close until 1980, with decrypts of 1940s traffic still exposing agents years later.
Source: NSA, “Venona” historical release, nsa.gov.
That’s the exact pattern under discussion: ciphertext collected when nobody could read it, stored, and decrypted much later once a weakness was found. The only thing that changes is the weakness. Instead of a pad-reuse mistake, it’s a quantum computer solving the mathematics that public-key cryptography rests on.
Forged trust at national scale. In 2011 a Dutch certificate authority was breached and the attacker minted at least 531 fraudulent certificates, using 1 to intercept the email of roughly 300,000 people in Iran. Those were dissidents, journalists, and ordinary citizens whose correspondence was read while their browsers displayed a padlock. The certificates were mathematically valid.
Source: Fox-IT, “Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach,” 2012, enisa.europa.eu.
Who currently owns the risk?
Nobody, formally, and that’s the finding rather than an evasion.
| The party | What they’d be argued to owe | What’s settled |
|---|---|---|
| The organization holding the data | A duty of reasonable care, plus dated obligations in its own contracts and certifications | The obligations are dated. Whether missing them causes a specific later loss has never been tried |
| The vendor | Whatever the contract says, which rarely promises future cryptographic strength | Almost nothing. Most agreements predate the question |
| The insurer | Losses the policy covers, subject to exclusions and a retroactive date | No published standard clause names cryptographic obsolescence as covered or excluded |
| The person in the data | Nothing. They carry the loss | Consistently the party that absorbs the harm and recovers least |
The last row is the documented pattern. Equifax exposed 147 million people, the overwhelming majority of whom were never customers, had entered no agreement, and had no mechanism to opt out of being in the file. The settlement was at least $575 million, and the people in the file received credit monitoring against an exposure that never expires.
Source: Federal Trade Commission, July 22, 2019, ftc.gov.
For a legislature the transferable point is that cryptographic decisions allocate risk durably. A deprecation date chosen today determines whether records are readable decades from now, long after the deciding organization has restructured or been acquired, and the people in those records are usually not parties to the decision and have no way to become parties to it.
Which dates and figures are sourced?
| The figure | The accurate wording | Source |
|---|---|---|
| 25, 50, and 75 years | U.S. classification horizons, the longer 2 for defined categories | Executive Order 13526, archives.gov |
| $7.1 billion | Projected cost for priority U.S. federal civilian systems 2025 to 2035, excluding national security systems, with OMB’s own uncertainty language | OMB, July 2024, OMB report |
| ~8.5 billion federal | Estimated U.S. Y2K spending, the closest precedent for a coordinated remediation | U.S. Senate Special Committee, S. Prt. 106-42, govinfo.gov |
| January 1, 2027 | Post-quantum required in new U.S. national security system acquisitions | NSA CNSA 2.0 FAQ, media.defense.gov |
| December 31, 2030 and December 31, 2031 | U.S. federal civilian key establishment, then digital signatures, for High Value Assets and high impact systems | Executive Order 14412, whitehouse.gov |
| End of 2030 | Australia’s full exit from traditional public-key cryptography, 5 years ahead of most peers | ASD Information Security Manual, cyber.gov.au |
| December 11, 2027 | Full EU Cyber Resilience Act obligations, binding manufacturers worldwide | eur-lex.europa.eu |
| After 2030 / after 2035 | U.S. deprecation then disallowance of today’s public-key cryptography, in an initial public draft | NIST IR 8547, csrc.nist.gov |
| 2035 | The whole-of-government goal of mitigating quantum risk “as is feasible,” the softest instrument and the most quoted | NSM-10, bidenwhitehouse.archives.gov |
| June 12, 2026 | NSPM-12 rewrites cybersecurity governance for national security systems, rescinding a 1990 directive and a 2022 memorandum. It sets no post-quantum date | whitehouse.gov |
Two recent items that get cited loosely. NSPM-12 addresses cryptographic authority for national security systems and contains no explicit mention of post-quantum cryptography, so describing it as a post-quantum instrument is checkably wrong. And Anne Neuberger’s June 2026 Foreign Affairs essay, “The Coming Quantum National Security Crisis,” is the highest-profile recent policy argument on this subject, written by a former U.S. Deputy National Security Adviser; its claim that China and Russia are already harvesting encrypted data is made on the article’s own account and is uncorroborated, so it’s citable as a named argument rather than as an established finding.
Source: The White House, NSPM-12, June 12, 2026, whitehouse.gov; Anne Neuberger, “The Coming Quantum National Security Crisis,” Foreign Affairs, June 2026, foreignaffairs.com.
What will policy readers ask?
Which errors draw corrections?
- “The deadline is 2035.” That’s a policy goal with “as is feasible” in the operative sentence. The instruments with teeth land in 2027, 2028, 2030, and 2031.
- “The grid will go down on Q-Day.” The concern is an attacker forging authenticated commands, which is serious and different from automatic failure.
- “Air gaps solve it for classified networks.” They substantially address the collection half. Those networks still verify software updates and credentials using the same mathematics.
- “This is a U.S. story.” Australia is 5 years ahead of most peers, and the EU rule binds manufacturers worldwide.
- “There’ll be an announcement when it happens.” Every major cryptographic break in the record stayed secret while it remained useful.
Go deeper: the technical layer
The pages below are the version written for practitioners, with every instrument, primary source, and open dispute intact. These are what an agency’s own technical staff would be working from.
Section indexes: The Mandates MOC · The Threat MOC · Quantum Risk Models MOC · The Human & Organizational Side MOC · In the Protocols MOC
Where to go next
- For Policymakers MOC is the full legislative route, with all 11 pages.
- Every figure and where it comes from carries every number with accurate phrasing.
- The primary documents behind every claim is the annotated source index.
- For Press is the full index.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.