up:: For Policymakers MOC
What a mayor needs to know
5 minutes of reading, and 4 decisions that cost nothing.
What can a city actually do is the operational version of this page, written for a chief technology officer. This one is for the person who appoints them.
Not legal advice
This is general education about available authority rather than legal advice. What a particular city may do is a determination for its own counsel and its own charter.
What is the situation in 5 sentences?
Encryption protecting data in transit today can be recorded now and decrypted later, once a sufficiently capable quantum computer exists, so records with long confidentiality lives are exposed the day they travel rather than the day the machine arrives. Federal agencies are under a dated migration mandate. No such mandate reaches a city. The systems your residents actually touch, meaning schools, public hospitals, benefits, courts, transit and vital records, sit in that uncovered space. And most of your city’s current cryptographic posture was never decided by anyone who works for you.
Why is no mandate reaching my city?
Because the federal instruments were written for federal agencies and say so.
OMB M-26-15, the executive branch’s migration directive, is addressed “TO THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES” and carries exactly one explicit exclusion, for national security systems. The words local, tribal, municipal and territorial appear zero times in the document.
Your city is not carved out of the federal mandate. It was never inside the universe the mandate addresses.
Source: OMB, M-26-15, June 24, 2026, M-26-15 PDF.
One federal requirement does reach you, and it arrives through data rather than through your city’s status. Criminal Justice Information carries cryptographic obligations that follow the data into any agency handling it, including local police. The practical result is a split inside your own government, where your police systems can carry a federal cryptographic duty while your schools and hospitals carry none.
Why isn’t this my CTO’s decision already?
Because for most services, it is not your city’s decision at all.
Two independent measurement studies published in 2026 found the same result at different scales: which infrastructure provider operates a service predicts its post-quantum support far better than anything about the organization that owns it. For email, once organizations sharing a mail provider are accounted for, a provider-only model reached an AUC of 0.994 while an organization-only model reached 0.156, which is below chance.
Source: Loizou and Ghadafi, arXiv 2608.02147, 2026, corroborated at global scale by Wickramasinghe et al., arXiv 2607.29005, 2026.
Read plainly: if your city website is in good shape, that is probably your content delivery network rather than a decision anyone made. If your email is not, that is probably your mail provider. Your CTO can only fix what the city itself operates, which is a much smaller set than most executives assume and is the reason the actions below are shaped the way they are.
What are the 4 things only a mayor can do?
All 4 are administrative in most charters. None requires a council vote, an appropriation, or a new position.
1. Direct that technology purchases ask the question. Your city already reviews technology procurements somewhere. Adding a requirement that vendors state their post-quantum position in writing, at contract and at renewal, creates a dated record where none exists. The obligation is disclosure rather than capability, which is what makes it adoptable immediately. A vendor that cannot support it yet answers honestly. A vendor that will not answer has told you more than a yes would have.
2. Direct an inventory of what the city operates itself. Not everything. The systems the city runs directly are the only ones a city decision changes, and they are usually a small enough set to list in a quarter.
3. Ask for the measurement, because it takes an afternoon. Your public posture is measurable from outside by anyone, using nothing but public records and ordinary connections. That means the answer already exists whether or not you have looked at it.
4. Decide who owns it. This work sits across incident response, privacy and IT operations while belonging to none of them, which is exactly why it drifts. Naming an owner is the difference between a directive that lands and one that circulates.
Why does this pay off for you?
Because the risk here is asymmetric in a way that almost nothing else on a city agenda is.
It costs nothing, so it cannot be attacked as spending. All 4 actions are directives and purchasing language. There is no appropriation to defend, no program to name, and no headcount to justify at the next budget hearing.
There is no organized opposition. Nobody lobbies against asking vendors to disclose what they support. That is rare enough to be worth noticing on its own.
It reads as technical competence without requiring technical staff. Every action is administrative. What it demonstrates is that the city knows the difference between what it operates and what it buys, which is the distinction most public bodies get wrong in public.
It outlives your administration, because it lives in procurement rather than in a program. A named initiative ends when the person who named it leaves. A purchasing condition keeps running, and keeps producing dated vendor answers, through every subsequent administration.
The first-mover position is unclaimed. As far as this Guide can establish, no US city has published a post-quantum baseline of its own infrastructure or adopted a procurement condition for this. First at something checkable, for the cost of one directive.
And the downside of inaction lands on a person rather than on an institution. If long-lived city records surface later as having traveled under retired cryptography, the question asked will be what was known and when. An executive with a dated inventory, a dated procurement change and a dated measurement has an answer. One without them has a news cycle. Acting is cheap and never looks bad in hindsight. Not acting is free right now and only right now.
What will I be asked, and what does a good answer sound like?
The question is some version of “what is the city doing about quantum risk,” and it usually arrives from a reporter or at a hearing.
A weak answer describes the threat and names a distant date. An answer that holds up is specific about three things: what the city operates itself against what it buys, whether the buying now asks the question, and when the city last measured.
A defensible answer, in the shape it should take:
“Most of our public-facing cryptography is operated by our vendors rather than by the city, so we’ve changed what we ask for at procurement and we’re requiring a written position from vendors at contract and renewal. We’ve inventoried the systems we run ourselves, which is where a city decision actually changes the answer, and we measured our public posture on a dated basis so we can show movement rather than intentions.”
What not to claim. Do not say the city is migrating, unless it is. Do not quote a completion date owned by vendors. And do not describe this as compliance with a federal mandate, because no federal mandate applies to you, and saying so invites the correction publicly.
What should I ask my CTO?
Five questions, answerable without technical background, and a deflection is audible in each.
- Which systems that we operate ourselves hold records that stay sensitive for more than 10 years?
- For our most important services, who actually operates the infrastructure, and is that written in the contract?
- What does our email run through, and have we ever asked that provider about post-quantum support?
- Which of our systems or equipment cannot receive a cryptographic update at all?
- Does our next technology procurement ask the vendor to state its position in writing?
Question 3 is the one most likely to surface something. Published measurement finds the email lane running far behind the web on the same estates, and it is the lane almost nobody checks.
A fuller version, with what a substantive answer and a deflection each sound like, is at What should I ask in a hearing.
Is there a first-mover position here?
Yes, and as far as this Guide can establish it is unclaimed.
No US city has published a post-quantum baseline of its own infrastructure or adopted a procurement condition for this. A city that does both is first at something checkable, at a cost of one directive and one line in a purchasing review.
The credible version of that claim is narrow and factual. “First US city to publish a post-quantum baseline and require vendor disclosure” is verifiable. A broader claim about being quantum-safe or quantum-ready is not, and it will be tested by the first competent reporter who asks what the city actually migrated.
The measurement is what makes the claim survive
A favorable posture with no measurement behind it is an accident of vendor choice. A dated baseline plus a second measurement later is a record of a decision, and it is the only version that supports a leadership claim under scrutiny.
Questions people ask
Is this urgent, or is it a 2035 problem? The exposure that matters is records with long confidentiality lives, and those are traveling now. The migration is slow, which is the argument for starting the cheap parts rather than for waiting. See Harvest Now Decrypt Later.
What does this cost? The 4 actions above cost staff time and no money. The migration itself is a multi-year program, and nothing on this page commits the city to one.
We have no cybersecurity staff. All 4 actions are administrative. Asking a vendor a written question, listing what you operate, and reading public records do not require a cryptographer. The work that does begins after those produce a picture.
Won’t our vendors handle it? Many will, on their own schedule, and you will not know which unless you ask. That is the entire reason action 1 exists.
Should we wait for the state or federal government? No current instrument reaches this layer and nothing indicates one is coming. See What is not legislated yet.
Can one city change anything? A requirement appearing in many cities’ purchasing changes what suppliers build, and every other customer of that supplier benefits without asking.
Where to go next
- What can a city actually do is the operational version, with the actual procurement language.
- What should I ask in a hearing covers the oversight questions in depth.
- What is not legislated yet places the municipal gap among the others.
- What can a state actually do covers the level above, including how a state reaches its municipalities.
- For Policymakers MOC is the full policy route.
Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.