up:: For Policymakers MOC
What an international organization needs to know
You are the one entity type in this Guide that no cryptographic mandate reaches anywhere in the world.
A federal agency has a dated migration directive. A bank has a regulator. A city has nothing, which this Guide covers at What can a city actually do. An intergovernmental organization has less than nothing, because there is no jurisdiction whose rules apply to you by default.
Not legal advice
This is general education rather than legal advice. What a particular organization may do is a determination for its own counsel and its own governing instruments.
What is the situation in 5 sentences?
Encryption protecting data in transit today can be recorded now and decrypted years later, once a sufficiently capable quantum computer exists, so records with long confidentiality lives are exposed the day they travel rather than the day the machine arrives. National governments have published dated migration mandates for their own systems. None of them reaches an international organization. Many international organizations hold personal data with some of the longest confidentiality horizons anywhere, on populations who cannot choose a different provider. And most of any organization’s current cryptographic posture was set by an infrastructure provider rather than by anyone on its staff.
Why does no mandate reach us?
Because every published instrument is written by a jurisdiction, for the systems that jurisdiction controls.
OMB M-26-15 is addressed to the heads of US federal executive departments and agencies. National timelines elsewhere bind national systems the same way. An organization established by treaty or by resolution, hosted in one country, staffed from many, and governed by its member states sits outside all of them by construction.
This is not an oversight and no instrument was going to reach you. It does mean the question of who asks has no current answer, which in practice means the organization asks itself or nobody does.
Why is our posture probably not our decision?
Because for most services it belongs to whoever operates the infrastructure.
Two independent measurement studies published in 2026 found the same result at different scales: which infrastructure provider operates a service predicts its post-quantum support far better than anything about the organization that owns it. On the email lane, once organizations sharing a mail provider are accounted for, a provider-only model reached an AUC of 0.994 while an organization-only model reached 0.156, which is below chance.
Source: Loizou and Ghadafi, arXiv 2608.02147, 2026, corroborated at global scale by Wickramasinghe et al., arXiv 2607.29005, 2026.
The finding applies regardless of an organization’s technical expertise, which is worth saying plainly because it is easy to assume otherwise. Institutions that work on technology standards and on emerging-technology security get the posture their providers give them, the same as everyone else. Expertise is not the variable. Procurement and platform are.
Why does shared infrastructure matter more for us than for others?
Because the independence these institutions are built to have does not extend below the application layer.
International organizations are deliberately separate. Distinct mandates, distinct governing bodies, distinct memberships, distinct data, often deliberate separation from any single national system. Underneath, at the layer that determines whether communications resist future decryption, organizations that share an infrastructure provider share a posture.
A single provider decision then moves many mandates at once, in the same direction, without any of those organizations meeting. For a system designed around institutional independence, that is a structural fact worth knowing rather than a failure by anyone.
None of this is an argument against consolidation. Managed infrastructure buys real security benefits and most organizations are safer for it. It is an argument for knowing where the decision now sits, and for having a way to ask about it collectively rather than one organization at a time.
Which of our data makes this urgent?
The test is confidentiality horizon rather than sensitivity today.
| Data | Why it’s the hardest case |
|---|---|
| Registration and biometric records | Unreissuable identifiers on people who may have fled a state. See Are refugee records safe |
| Beneficiary and assistance records | Identify who received help, where, and from whom |
| Human rights documentation | Witnesses, victims and sources, protected for lifetimes |
| Health and epidemiological data | Clinical sensitivity at population scale |
| Staff and duty-of-care records | Personnel in hostile environments |
| Diplomatic and negotiation traffic | Confidentiality horizons measured in decades |
The distinguishing feature is the absence of an exit. A bank customer can bank elsewhere. A registered refugee has one registry, chosen for them, and stays in it.
What can we do without any member state agreeing to anything?
Five actions, all administrative, none requiring a governing-body decision or a new budget line.
1. Ask the infrastructure providers, in writing, and date the answer. Three questions, written so a roadmap is not an answer: which post-quantum key-exchange groups do your production endpoints support today, by name; if none, on what date does that change and is that date contractual; and does your answer depend on a decision that is not yours. “Not currently supported” is a complete answer. A refusal to respond is not.
2. Name what the organization operates itself. Not everything. The systems run in-house are the only ones an internal decision changes, and for most organizations that set is small enough to list in a quarter.
3. Look at the email lane specifically. Published measurement finds it running far behind the web on the same estates, and it is where case coordination, referrals and partner correspondence actually travel.
4. Find what cannot be updated at all. Field equipment, registration hardware, anything deployed with a service life past 10 years. This is the category that becomes permanently unfixable rather than merely late.
5. Ask the question collectively. An organization asking a global provider alone is one customer. A group of organizations sharing that provider asking together is a different conversation, and the inter-agency mechanisms to do it already exist for other purposes.
6. Publish a security contact. RFC 9116 defines security.txt, a short file at /.well-known/security.txt naming where to send a security concern. Checked on 10 August 2026, none of 7 major UN bodies published one, which means a researcher who finds something has no route in and usually gives up.
This costs one file and it closes a real gap. US federal, state and local entities in the .gov registry all publish a security contact, so there is an established practice to point at. An international organization publishing one is doing something its national counterparts already do.
Action 5 is the one available to international organizations and to almost nobody else. Action 6 is the cheapest thing on this page.
Why does this pay off for the organization?
Because the asymmetry is unusually clean, and because nobody else is positioned to act.
All 5 actions cost staff time and no money. There is no appropriation to seek from member states and no governing-body decision to schedule.
Nobody is defending the gap. There is no constituency opposed to asking a provider what it supports.
It is answerable to the people in the records. For an organization holding data on populations who cannot choose a different provider, being able to say what was asked and when is a duty-of-care position rather than a technical one.
And it is unclaimed. No international organization appears to have published a dated post-quantum position on its own estate. First at something checkable, for the cost of a few letters and a list.
Claim the position, never the readiness
“We asked our providers on this date, here is what they said, and here is what we operate ourselves” is checkable and defensible. A claim about being quantum-ready is neither, and it will be tested by the first competent person who asks what was actually migrated.
What should I ask our technology lead?
- Which systems do we operate ourselves, as opposed to buy?
- For our largest services, who actually operates the infrastructure underneath them?
- What does our email run through, and have we ever asked that provider this question?
- Which of our field systems or equipment cannot receive a cryptographic update at all?
- Which of our records stay sensitive for more than 10 years, and where do those travel?
Questions people ask
Is this urgent, or is it a 2035 problem? The exposure that matters is records with long confidentiality lives, and those are traveling now. See Harvest Now Decrypt Later.
Shouldn’t our host country’s rules apply? Host-country instruments generally bind national systems rather than the organization, and privileges and immunities usually make that explicit. Check with counsel rather than assuming either way.
Aren’t our providers handling this? Many will, on their own schedule, and the organization will not know which until it asks. That is the entire reason action 1 exists.
Does this commit us to a migration? No. All 5 actions produce information. What to do with it is a later decision made with better facts.
We have no cryptographers. None of the 5 requires one. Writing to a provider, listing what you operate, and reading public records are administrative tasks.
Who should be asking this on our behalf? Nobody currently is, which is the finding on this page. See What is not legislated yet.
Where to go next
- Are refugee records safe covers the hardest data category in this space.
- Is anyone coordinating this internationally covers standards bodies and national divergence.
- What an agency head needs to know is the closest operational equivalent.
- What is not legislated yet documents the coverage gaps this sits inside.
- For Policymakers MOC is the full policy route.
Go deeper into the technical detail
The Vendor-Claims Checklist is the tool for evaluating what action 1 produces.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.