up:: For Policymakers MOC

What an agency head needs to know

Every other page in this series is about someone who could require you to act. This one is about being the person who can just do it.

You run a department, a bureau, an authority or a district. You hold systems, contracts, and vendor relationships. Nothing on this page needs a policy, a statute, an appropriation or anyone’s approval.

Not legal advice

This is general education rather than legal advice, and it applies at any level: a federal bureau, a state department, a city agency, a school district, a transit authority or a public hospital system.

What is the situation in 5 sentences?

Encryption protecting data in transit today can be recorded now and decrypted years later, once a sufficiently capable quantum computer exists, so records with long confidentiality lives are exposed the day they travel rather than the day the machine arrives. Federal civilian agencies carry a dated migration mandate under OMB M-26-15. If you are not a federal civilian agency, nothing requires this of you. Your agency almost certainly holds records that stay sensitive for decades. And most of your current cryptographic posture was set by vendors rather than by anyone who reports to you.

Why is the honest scope smaller than it looks?

Because you cannot fix what you do not operate, and that is most of it.

Two independent measurement studies published in 2026 found the same result at different scales: which infrastructure provider operates a service predicts its post-quantum support far better than anything about the organization that owns it. For email, once organizations sharing a mail provider are accounted for, a provider-only model reached an AUC of 0.994 against 0.156 for an organization-only model, which is below chance.

Source: Loizou and Ghadafi, arXiv 2608.02147, 2026, corroborated at global scale by Wickramasinghe et al., arXiv 2607.29005, 2026.

Read plainly for your estate: where your public services look ready, that is usually your content delivery network or your cloud provider rather than a decision anyone made. Where they do not, that is usually a vendor too.

This is good news for scoping and bad news for anyone promising a migration. The set you can act on directly is small enough to name, and naming it is the single most useful thing you can produce. Everything outside it is a vendor conversation rather than a project.

What are the 5 things you can do this month?

1. Name what you operate, as distinct from what you buy. Not a full inventory of everything. A list of the systems your agency runs itself, where a decision by you changes the answer. Most agencies cannot currently produce this list, and producing it takes days rather than a program.

2. Ask your vendors in writing, today, without waiting for a procurement policy. You do not need a purchasing standard to send a letter to a vendor you already contract with. Three questions, written so a roadmap is not an answer:

Which post-quantum key-exchange groups do your production endpoints supporting our services support today, by name? If none, on what date does that change, and is that date contractual or aspirational? And does your answer depend on a decision made by an infrastructure provider rather than by you?

A vendor that cannot support it yet answers honestly and you have a dated record. A vendor that will not answer has told you something more useful than a yes.

3. Check your email lane, because it is almost certainly worse than your web. Published measurement across 4,665 organizations found 44.0% of reachable web endpoints supporting a post-quantum key exchange against 6.4% of email endpoints, and one provider accounted for 98.4% of all supporting email endpoints. Your mail provider is visible in public DNS records, which requires no scan of anything.

4. Find what cannot be updated at all. Operational equipment, medical devices, industrial controllers, anything with a service life past 10 years. This is the category that becomes permanently unfixable rather than merely late, because a device fielded now with fixed cryptography carries that decision for its whole life.

5. Write down what you found, and date it. A dated page beats an undated program. It is what makes the next conversation start from evidence, and it is what you will want if you are ever asked when you knew.

Why does this pay off for you?

Because you are the person who ends up answering, and you are also the only one who can.

When this surfaces, it surfaces at you. A mayor, a governor or a legislator explains policy. An agency head explains their own systems, by name, in a hearing, with the records in question on the table. Every other role in this series can point at someone. The person operating the system is where pointing stops.

A dated page is a complete answer and it takes days to produce. “We identified what we operate, we asked our vendors in writing on this date, here is what they said, and here is the equipment that cannot be updated” is a defensible position at any hearing. It is not a migration and it does not pretend to be, which is exactly why it survives follow-up questions.

It costs nothing and needs no approval. All 5 actions are within ordinary operational authority. There is no appropriation to request and no policy to wait for, which also means there is nobody to blame if it does not happen.

It reads as competence in the specific way public technology leadership rarely does. Knowing the difference between what you operate and what you buy is the distinction most public bodies get wrong in public. Demonstrating it is a credential inside government that transfers.

And it is currently unclaimed at your level. As far as this Guide can establish, no public agency outside the federal mandate has published a dated post-quantum position on its own estate. First at something checkable, for the cost of a few days of staff time.

Claim the position, never the readiness

“We have identified what we operate, asked our vendors in writing, and dated the answers” is checkable and defensible. “We are quantum-ready” is neither, and it will be tested by the first competent person who asks what was actually migrated. The undersell is the durable version.

What will I be asked, and what does a good answer sound like?

The question arrives as “what is your agency doing about quantum risk,” usually in a budget hearing or from a reporter, and usually with no warning.

A weak answer describes the threat and names a distant date. An answer that holds up is specific about what you operate against what you buy, what your vendors have said in writing, and when you last looked.

“Most of our cryptography sits inside vendor products rather than in systems we run, so we started by listing what we actually operate, which is a smaller set than people assume. We wrote to our vendors and asked which post-quantum groups they support today and on what date that changes, and we have those answers dated. We identified the equipment that cannot receive a cryptographic update at all, because that is the category that gets worse rather than later. We are not claiming to be migrated, and I would not trust anyone at my level who did.”

The last sentence is the one that buys you credibility with a technical audience, and it costs nothing because it is true.

What should I ask my own technology lead?

  1. Can you produce a list of the systems we operate ourselves, as opposed to buy?
  2. For our biggest services, who actually operates the infrastructure underneath them?
  3. What does our email run through, and have we ever asked that provider this question?
  4. Which of our systems or equipment cannot receive a cryptographic update at all?
  5. Which of our records stay sensitive for more than 10 years, and where do those travel?

Question 1 reveals the most, because the answer to it determines what every other question is even about. An agency that can name what it operates can sequence everything else. One that cannot is guessing.

Which of my records are the exposed ones?

The test is confidentiality horizon rather than sensitivity today.

Record typeWhy it’s the worst case
Clinical and behavioral healthSensitive for the patient’s lifetime and beyond
Student recordsHeld from childhood forward, including health and disciplinary files
Benefits and eligibilityHousehold financial and status data on vulnerable people
Sealed, juvenile and protected-identity filesDisclosure risk is the whole point of the protection
Biometric and identity dataCannot be reissued after exposure
Vital recordsPermanent by definition
Personnel and retirement filesSpan whole careers and continue afterward

Anything on this list that travels between systems is the part that matters, because the exposure is created in transit rather than at rest.

Questions people ask

Is this urgent or is it a 2035 problem? The exposure that matters is records with long confidentiality lives, and those are traveling now. The migration is slow, which argues for starting the parts that cost nothing. See Harvest Now Decrypt Later.

We have no cryptographers. None of the 5 actions requires one. Listing what you operate, writing to vendors and reading public DNS records are administrative tasks. The work that needs specialists begins after those produce a picture.

Won’t our vendors handle it? Many will, on their own schedule, and you will not know which until you ask. That is the entire reason action 2 exists.

Should I wait for a policy? No policy currently reaches most public agencies, and nothing indicates one is coming soon. See What is not legislated yet.

What if the answer is embarrassing? A dated honest answer is a far better position than an undated one, and every agency that looks at this finds the same thing, because the picture is set by a small number of providers rather than by anyone’s diligence.

Does any of this commit us to a migration? No. All 5 actions produce information. What to do with it is a later decision made with better facts.

Where to go next

Go deeper into the technical detail

The Vendor-Claims Checklist is the tool for evaluating the answers action 2 produces.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.