up:: For Policymakers

What happens to countries that can’t afford to migrate?

They become the part of the system nobody fixed, and everybody routes through.

Almost every serious discussion of this transition is a discussion among wealthy countries with mature national cyber agencies, published schedules, and the budget to enforce them. That list is short. Most of the world isn’t on it, and won’t be by 2035.

This is the dimension a purely national approach can’t reach, and it’s the one where multilateral bodies have a role nobody else can fill.

The short version:

  • The countries with published deadlines are wealthy ones with national cyber agencies. Most countries have neither.
  • 6 billion people now use the internet, and the guidance shaping this transition was written by and for a small fraction of the world.
  • Encryption is negotiated between both ends, so a country that finishes early inherits the exposure of every partner that hasn’t.
  • The scarce resource is people rather than money, and expertise can’t be bought quickly at any price.
  • Migrating late is expensive. Migrating never is the actual risk, and it’s the likely outcome without deliberate support.

Who exactly is being left out?

The countries with published post-quantum schedules are the United States, Australia, Canada, Germany, France, Japan, and the EU bloc, with a handful of others. Those nations share three things: a national cyber-security agency with technical staff, a domestic technology sector, and the budget to compel their own institutions.

Most countries have none of those. A ministry of 10 people, no domestic cryptographic expertise, systems purchased from foreign vendors, and infrastructure operated under contracts with no leverage in them.

Meanwhile, 6 billion people, 74% of the world’s population, are now online, and internet use in low-income countries is growing quickly. The transition being planned in a handful of capitals affects all of them.

Source: ITU, Measuring digital development: Facts and Figures 2025, itu.int.

Why is this everybody’s problem?

Three mechanisms, and none of them respect borders.

Encryption is negotiated between both ends. When 2 systems connect, they use what they both support. A bank in a country that finished its migration, connecting to a counterparty in one that hasn’t, falls back to the older method. The country that did the work gets the security of the country that didn’t.

Data crosses everywhere. Traffic between any two points routes through infrastructure in many jurisdictions. A nation’s exposure isn’t bounded by its own networks, which means unprotected infrastructure anywhere is a collection opportunity for traffic originating everywhere.

Weak points attract. Any system that keeps operating on broken cryptography after a machine exists becomes the obvious path into everything connected to it. That’s true of an organization, and it’s true of a country.

So a transition that succeeds in 30 countries and fails in 150 leaves a system with permanent, well-known weak points rather than a partial success.

What’s actually scarce?

Not the algorithms, which is the encouraging part.

The replacement standards are published, free to use, and available in mainstream open-source software. There’s no licensing cost and no technology to purchase. A country isn’t blocked by the price of the cryptography.

What’s scarce is people who can lead the work. Somebody has to inventory national systems, evaluate vendor claims, write procurement requirements, and sequence a migration. Those skills are scarce everywhere right now, and every country needs them simultaneously.

Vendor dependency is the second constraint. A country whose critical systems run on purchased foreign products can’t migrate faster than those vendors choose to, and has little leverage to demand it.

And there’s no forcing function. Wealthy countries move because regulators compel their institutions. A country without that regulatory capacity has nothing driving the work internally.

Who has a program, and who doesn’t?

Countries with published deadlinesMost of the world
National cyber agency with technical staffYesOften no
Published migration scheduleYesNo
Domestic cryptographic expertiseYesRare
Leverage over foreign vendorsSomeVery little
Regulator able to compel institutionsYesOften no
Share of the 6 billion people onlineA minorityThe majority

What would actually help?

Ordered by how much difference it makes relative to effort.

  1. Shared expertise rather than shared funding. The binding constraint is people. Regional centers of expertise, secondments, and training programs address it far better than grants do.
  2. Procurement leverage exercised collectively. Smaller countries have no individual leverage over global vendors. Acting as a bloc changes that, and it costs nothing but coordination.
  3. Translated, freely available guidance. Most authoritative material exists in English and assumes an audience of specialists. That’s a solvable barrier.
  4. Regional shared services. One capable team serving many small states is far more achievable than each building its own.
  5. Vendor obligations that reach everywhere. If manufacturers are required by their largest markets to ship post-quantum capability, every customer benefits, including those with no regulator of their own. This is the highest-leverage lever wealthy countries hold.
  6. Don’t make the standards a trade good. The algorithms came from an open competition and are free. Keeping them that way, and resisting any move to make readiness a licensed product, matters enormously.

That fifth item deserves emphasis. When a large market compels vendors to build something, the whole world receives it. That’s how a small number of regulators can protect billions of people who have no regulator.

What’s the honest risk of doing nothing?

A slow failure rather than a dramatic one.

The likely outcome is a two-tier internet, where systems in well-resourced countries are protected and systems everywhere else keep running the old cryptography for decades because nobody replaced them. Collection concentrates on the unprotected paths, and every organization connecting to them inherits the risk.

The people most affected would be the ones with the least ability to know or object: patients whose national health records ran on unmigrated systems, citizens whose identity documents were issued under old cryptography, populations whose governments never had the capacity to act.

That’s the equity argument, and it’s also a straightforward security argument for the countries doing the work.

Questions people ask

Isn’t this just a funding problem? Money helps, and the binding constraint is expertise, which can’t be purchased quickly at any price.

Do the algorithms cost anything? No. They’re published standards, free to implement, and available in mainstream open-source libraries.

Which body should own this? No single one does today, and it sits naturally with international standards bodies, development organizations, and regional cyber-security groupings. The absence of an owner is the actual gap.

Would a country be better off skipping the old encryption entirely? In some ways, yes. Countries building infrastructure now can specify post-quantum requirements from the start and avoid the migration entirely, which is a genuine advantage of building later.

Is anyone doing this well? Regional cooperation exists in several groupings, and it’s early. This is a place where a country or an institution could lead and there’s currently room to.

Where to go next

Go deeper into the technical detail

The technical index of regulations worldwide is The Mandates MOC.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.