up:: For Press

For a policy audience

Everything a policy piece needs, in the order it’s usually needed. Two threads carry most of the substance: cryptography has decided the outcome of conflicts for centuries and the record is documentary, and the risk currently sits with parties who never agreed to carry it.

What’s the story in one paragraph?

Multiple governments concluded independently that this is real and published dated schedules against it, so the legislative question isn’t whether to believe it. Classified material carries confidentiality horizons of 25 to 75 years, which places traffic recorded today well inside its own exposure window, and the collection is undetectable, triggers no notification duty, and supports no attribution. For critical infrastructure the threat is forgery rather than eavesdropping, meaning an attacker issuing commands that verify as authentic, and it arrives live on the day a capable machine exists. The gaps that remain are notification, liability, funding for operators with no capacity, and any requirement that long-lived equipment be updatable at all, and the last of those becomes permanently unfixable for hardware fielded while it stays open.

What are the 5 most important things?

  1. Whether it’s real is settled in published policy. The U.S., U.K., Germany, France, Canada, Australia, and the EU each reached that conclusion independently and published dated schedules. Three of those regimes arrived at the end of 2030 without coordinating.
  2. Classified material is inside its own exposure window. U.S. classification horizons run 25 years, extendable to 50 and 75 for defined categories, against a machine plausibly arriving inside 10 to 15. That arithmetic needs no forecast.
  3. For infrastructure the threat is forgery, and it arrives live. Nobody cares about reading an old command to open a valve. They care about issuing a new one that verifies as authentic, which is a present-tense capability the day the machine exists rather than a retroactive disclosure.
  4. Nobody will be notified, and no announcement is coming. Collection leaves no artifact, so no breach law is triggered and no attribution is available. Every major cryptographic break in the historical record stayed secret while it remained useful.
  5. What to do about it, ordered by what needs legislation. Put a post-quantum requirement into public procurement, which costs nothing and moves the whole supplier base immediately. Require an algorithm-level inventory from agencies and regulated entities, since nothing can be sequenced without it. Fund the operators without capacity, because a mandate they can’t afford produces documented non-compliance rather than migration. Require that long-lived products be updatable, which is the only gap that closes permanently now and becomes unfixable later. And close the notification gap, drafted on a records model rather than a detection model.

What does the record show about cryptography deciding outcomes?

Documentary, and it’s the part that resists dismissal as speculation.

Venona. From 1943, American codebreakers intercepted and stored Soviet diplomatic and intelligence cables. The traffic used one-time pads, which are mathematically unbreakable when used correctly, so at collection the messages were genuinely unreadable and the Soviets treated them as permanently safe. Wartime pressure caused pad pages to be duplicated, and a one-time pad reused even once stops being unbreakable. From around 1946 the project began reading the backlog. The work ran for decades and didn’t formally close until 1980, with decrypts of 1940s traffic still exposing agents years later.

Source: NSA, “Venona” historical release, nsa.gov.

That’s the exact pattern under discussion: ciphertext collected when nobody could read it, stored, and decrypted much later once a weakness was found. The only thing that changes is the weakness. Instead of a pad-reuse mistake, it’s a quantum computer solving the mathematics that public-key cryptography rests on.

Forged trust at national scale. In 2011 a Dutch certificate authority was breached and the attacker minted at least 531 fraudulent certificates, using 1 to intercept the email of roughly 300,000 people in Iran. Those were dissidents, journalists, and ordinary citizens whose correspondence was read while their browsers displayed a padlock. The certificates were mathematically valid.

Source: Fox-IT, “Black Tulip: Report of the investigation into the DigiNotar Certificate Authority breach,” 2012, enisa.europa.eu.

Who currently owns the risk?

Nobody, formally, and that’s the finding rather than an evasion.

The partyWhat they’d be argued to oweWhat’s settled
The organization holding the dataA duty of reasonable care, plus dated obligations in its own contracts and certificationsThe obligations are dated. Whether missing them causes a specific later loss has never been tried
The vendorWhatever the contract says, which rarely promises future cryptographic strengthAlmost nothing. Most agreements predate the question
The insurerLosses the policy covers, subject to exclusions and a retroactive dateNo published standard clause names cryptographic obsolescence as covered or excluded
The person in the dataNothing. They carry the lossConsistently the party that absorbs the harm and recovers least

The last row is the documented pattern. Equifax exposed 147 million people, the overwhelming majority of whom were never customers, had entered no agreement, and had no mechanism to opt out of being in the file. The settlement was at least $575 million, and the people in the file received credit monitoring against an exposure that never expires.

Source: Federal Trade Commission, July 22, 2019, ftc.gov.

For a legislature the transferable point is that cryptographic decisions allocate risk durably. A deprecation date chosen today determines whether records are readable decades from now, long after the deciding organization has restructured or been acquired, and the people in those records are usually not parties to the decision and have no way to become parties to it.

Which dates and figures are sourced?

The figureThe accurate wordingSource
25, 50, and 75 yearsU.S. classification horizons, the longer 2 for defined categoriesExecutive Order 13526, archives.gov
$7.1 billionProjected cost for priority U.S. federal civilian systems 2025 to 2035, excluding national security systems, with OMB’s own uncertainty languageOMB, July 2024, OMB report
~8.5 billion federalEstimated U.S. Y2K spending, the closest precedent for a coordinated remediationU.S. Senate Special Committee, S. Prt. 106-42, govinfo.gov
January 1, 2027Post-quantum required in new U.S. national security system acquisitionsNSA CNSA 2.0 FAQ, media.defense.gov
December 31, 2030 and December 31, 2031U.S. federal civilian key establishment, then digital signatures, for High Value Assets and high impact systemsExecutive Order 14412, whitehouse.gov
End of 2030Australia’s full exit from traditional public-key cryptography, 5 years ahead of most peersASD Information Security Manual, cyber.gov.au
December 11, 2027Full EU Cyber Resilience Act obligations, binding manufacturers worldwideeur-lex.europa.eu
After 2030 / after 2035U.S. deprecation then disallowance of today’s public-key cryptography, in an initial public draftNIST IR 8547, csrc.nist.gov
2035The whole-of-government goal of mitigating quantum risk “as is feasible,” the softest instrument and the most quotedNSM-10, bidenwhitehouse.archives.gov
June 12, 2026NSPM-12 rewrites cybersecurity governance for national security systems, rescinding a 1990 directive and a 2022 memorandum. It sets no post-quantum datewhitehouse.gov

Two recent items that get cited loosely. NSPM-12 addresses cryptographic authority for national security systems and contains no explicit mention of post-quantum cryptography, so describing it as a post-quantum instrument is checkably wrong. And Anne Neuberger’s June 2026 Foreign Affairs essay, “The Coming Quantum National Security Crisis,” is the highest-profile recent policy argument on this subject, written by a former U.S. Deputy National Security Adviser; its claim that China and Russia are already harvesting encrypted data is made on the article’s own account and is uncorroborated, so it’s citable as a named argument rather than as an established finding.

Source: The White House, NSPM-12, June 12, 2026, whitehouse.gov; Anne Neuberger, “The Coming Quantum National Security Crisis,” Foreign Affairs, June 2026, foreignaffairs.com.

What will policy readers ask?

The questionThe page that answers it
”Give me one page”The one-page briefing
”What laws already exist?”What laws already exist
”What can a state do?”What can a state actually do
”What are other countries doing?”What are other countries doing
”What is China doing?”What is China doing
”What about India and everyone else?”What about the rest of the world
”Is my information current?”What changed recently
”Is anyone coordinating this?”Is anyone coordinating this internationally
”What isn’t legislated yet?”What is not legislated yet
”What would a law actually say?”Model legislative language
”Who pays for it?”Who pays for this
”What infrastructure is exposed?”What critical infrastructure is exposed
”What should a government do?”What should a government actually do
”How do you make anyone comply?”How do you make it worth doing
”What about poorer countries?”What happens to countries that cannot afford this
”What does history show?”What does history tell us about broken codes
”What do I ask in a hearing?”What should I ask in a hearing
”How does this work technically?”What is technically happening to national systems

Which errors draw corrections?

  1. “The deadline is 2035.” That’s a policy goal with “as is feasible” in the operative sentence. The instruments with teeth land in 2027, 2028, 2030, and 2031.
  2. “The grid will go down on Q-Day.” The concern is an attacker forging authenticated commands, which is serious and different from automatic failure.
  3. “Air gaps solve it for classified networks.” They substantially address the collection half. Those networks still verify software updates and credentials using the same mathematics.
  4. “This is a U.S. story.” Australia is 5 years ahead of most peers, and the EU rule binds manufacturers worldwide.
  5. “There’ll be an announcement when it happens.” Every major cryptographic break in the record stayed secret while it remained useful.

Go deeper: the technical layer

The pages below are the version written for practitioners, with every instrument, primary source, and open dispute intact. These are what an agency’s own technical staff would be working from.

Section indexes: The Mandates MOC · The Threat MOC · Quantum Risk Models MOC · The Human & Organizational Side MOC · In the Protocols MOC

If you needThe technical pages
The U.S. instruments themselvesNSM-10 · Quantum Computing Cybersecurity Preparedness Act (PL 117-260) · OMB M-23-02 · OMB M-26-15 · Executive Order 14306 · Executive Order 14412 · NSA CNSA 2.0 · NIST IR 8547
U.S. guidance and programsCISA NSA NIST Quantum-Readiness Joint Guidance · CISA Post-Quantum Cryptography Initiative · NIST SP 1800-38 (Migration to Post-Quantum Cryptography) · FedRAMP and PQC · NIST Cybersecurity Framework (CSF)
Other jurisdictionsEU Cyber Resilience Act (CRA) · EU Quantum Act · UK NCSC Quantum-safe Cryptography · BSI · ANSSI Cryptographic Mechanisms · CCCS (Canada) · ACSC (Australia) · CRYPTREC (Japan) · ENISA
Who sets the international standardsISO IEC 18033 · IETF PQUIP WG · ETSI · PQC Coalition (PQCC) · PKI Consortium · The NIST PQC Competition
The 2 threat modelsHarvest Now, Decrypt Later (HNDL) · Forge-Later Attack · PKI Collapse · Store-Now-Decrypt-Later Actor Landscape · The No-Warning Problem
Critical infrastructurePQC for OT, ICS, and SCADA · PQC in Satellites and Space · PQC in 5G and Mobile Networks · PQC in Medical Devices · PQC in Automotive and V2X · GSMA PQ.1 (Post-Quantum Telco Network Impact Assessment)
Where the risk landsWhen Crypto Fails, Who Actually Pays · Cyber Insurance · Why Is Quantum Readiness a Governance Problem · Quantum Risk Beyond Cryptography
The historical recordDid We Know the Quantum Threat Was Coming · Lessons from Past Crypto Migrations · What Came Before Digital Trust
The QKD questionQuantum Key Distribution (QKD) · QKD vs PQC · The Three QKD Questions
How far the machines areQuantum Resource Estimation · Quantum Hardware Roadmaps · Logical vs Physical Qubits · Cryptographically Relevant Quantum Computer (CRQC) · Is the Quantum Threat Overhyped

Where to go next


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.