up:: For Policymakers MOC

The one-page briefing

Print this, or send it. It’s the whole issue, sourced, on one page.


The problem

Encryption protecting government and commercial data rests on math a large enough quantum computer can undo. The method was published in 1994 and has never been overturned. No machine capable of running it exists.

That machine is not the urgent part. Encrypted data can be recorded today and stored until it can be read. CISA, the NSA, and NIST stated jointly in August 2023 that attackers “could be targeting data today that would still require protection in the future.”

Nobody will be notified. Copying encrypted traffic alters no system and triggers no alarm, so no breach law is triggered and no attribution is possible.

Why it’s a present decision

  • Classified material carries confidentiality horizons of 25 years, extendable to 50 and 75. Traffic recorded today sits well inside its own window.
  • Migration takes about a decade. The U.S. schedule for federal civilian systems runs 2025 to 2035.
  • Products sold today outlive their cryptography. Industrial and medical equipment enters service with encryption fixed at manufacture and service lives of 10 to 20 years.

What is already settled

Replacement standardsFinalized August 13, 2024. A fifth algorithm added March 2025
U.S. federal civilian deadlineFor High Value Assets and high impact systems: key establishment by December 31, 2030; signatures by December 31, 2031
U.S. national security systemsRequired in new acquisitions from January 1, 2027
EU marketFull Cyber Resilience Act obligations from December 11, 2027, binding manufacturers worldwide
AustraliaTraditional public-key cryptography out by end of 2030, 5 years ahead of most peers
Projected federal civilian costApproximately $7.1 billion, 2025 to 2035, excluding national security systems

Seven jurisdictions reached these conclusions independently. Three arrived at the end of 2030 without coordinating.

What is not legislated anywhere

  1. No notification duty. Breach law requires a detectable event, and this produces none.
  2. No updatability requirement. Nothing obliges a manufacturer to ship a long-lived device whose cryptography can be updated. This is the only gap that becomes permanently unfixable, because equipment fielded during it carries fixed cryptography for its whole service life.
  3. No private-sector inventory duty. Federal agencies have carried one since May 2023. The private entities holding most affected data carry none.

What a government can do

Needing no legislation: put a post-quantum requirement into public procurement. It costs nothing, works immediately, and moves suppliers for their private customers too.

Needing legislation: an inventory duty for regulated entities, delegated to existing sector regulators. An updatability requirement for long-lived products. A notification duty built on records rather than detection.

Needing appropriation: grants for operators with no capacity. Small water utilities, rural hospitals, and county government hold exposed systems well beyond what their budgets reach. A mandate they cannot meet produces documented non-compliance rather than migration.

What to be careful of

  • 2035 is the softest date in the field and the most quoted. It carries “as is feasible” in the operative sentence. The dates that bind land in 2027, 2028, 2030, and 2031.
  • The retirement schedule is still a draft, so its years are stated intent.
  • Nobody credible names a year for the machine. A survey of 26 specialists put the chance at 28% to 49% within 10 years. Read that as one figure with an uncertainty attached rather than as a disagreement between experts, because the width comes mostly from how coarse the survey’s answer choices are.
  • No public evidence supports any claim that encryption has been broken, or that a specific country is collecting a specific dataset.

Sources. Shor, SIAM J. Computing 26(5), 1997, arxiv.org. CISA, NSA, and NIST joint factsheet, August 21, 2023, cisa.gov. NIST, August 13, 2024, nist.gov. Executive Order 14412, June 22, 2026, whitehouse.gov. NSA CNSA 2.0 FAQ, media.defense.gov. Regulation (EU) 2024/2847, eur-lex.europa.eu. ASD Information Security Manual, cyber.gov.au. OMB Report on Post-Quantum Cryptography, July 2024, bidenwhitehouse.archives.gov. Executive Order 13526, archives.gov. Global Risk Institute Quantum Threat Timeline Report 2025, globalriskinstitute.org. Every citation with its link is at The primary documents behind every claim.

Going deeper: For Policymakers MOC · draft statutory text at Model legislative language · questions for witnesses at What should I ask in a hearing · the technical version, the upward-communication playbook for walking out with a funded program, at Brief Your Board


Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.