up:: For Policymakers MOC

What should I ask in a hearing or briefing?

The useful questions have factual answers that either exist or don’t, which means you can evaluate the response without being technical.

The unproductive ones invite a witness to describe their commitment to security, and every witness can do that indefinitely. Asking when a quantum computer will arrive produces a discussion nobody can settle. Asking whether an inventory exists and when it was last updated produces either a date or a visible gap.

A truthful “we haven’t done that yet” is the most useful answer available, because it’s the one that makes the next appropriation defensible.

The short version:

  • Ask for the inventory first. It exists with a date attached, or it doesn’t, and everything downstream depends on it.
  • Ask which systems can’t be updated at all, because that answer converts a software question into a capital budget.
  • Ask what proportion sits inside vendor products, since that’s the share no internal effort can compress.
  • Ask what’s in the next procurement, because it’s the fastest lever and it’s free.
  • Never ask when quantum computers will arrive. No witness can answer it and the exchange consumes your time.
  • The universal follow-up is “as of what date?” It separates a real answer from a description of intent.

What do you ask an agency or department witness?

Five questions, in this order, because each one earns the next.

  1. Can you produce an algorithm-level inventory of where cryptography is used across your systems, and when was it last updated? Federal civilian agencies have been required to submit one annually since May 2023, so this is a compliance question rather than a technical one.
  2. Which of the data you hold has a confidentiality lifetime longer than your migration deadline? This is answerable by records officers rather than engineers, and it’s what sets priority.
  3. What proportion of your cryptography sits inside vendor products you can’t modify, and what dated commitments do you hold from those vendors? A verbal roadmap is a promise. A contract term is an obligation.
  4. Which systems in your estate can’t be updated at all, and what’s the plan for those? This converts the discussion from software to capital replacement, which is where the real money is.
  5. Does your next procurement carry a post-quantum requirement? Free, immediate, and it moves the supplier base beyond your own agency.

Source: Office of Management and Budget, Memorandum M-23-02, OMB M-23-02.

How do you tell an answer from a deflection?

What you askedA substantive answerA deflection
Do you have an inventory?Names the systems covered, names what’s still out of scope, gives the date it was refreshed”All our data is encrypted” or “we follow federal guidance”
What’s your deadline?A date and the instrument it comes from”2035,” which is the softest instrument and the most quoted
Which data is long-lived?Categories with confidentiality lifetimes attached”All of our data is sensitive,” which produces no priority order
What about vendors?A short list with dated commitments and contract renewal dates”Our vendors are handling it”
What can’t be updated?A count, a sector, and a replacement plan”We’re assessing that”
Who owns this?One named official with it in their objectivesA committee, or a working group

The pattern across all 6 is the difference between a fact and a posture. Facts carry dates, counts, and documents. Postures describe how seriously an organization takes security, which is a different subject and an unfalsifiable one.

The universal follow-up is “as of what date?” Applied to any answer, it separates something that has happened from something that’s intended.

What do you ask a vendor or contractor witness?

Four questions, and the last one is the one their competitors would want asked.

  1. Which of your products support the finalized post-quantum standards today, and which don’t? The standards were finalized on August 13, 2024, so this has a factual answer.
  2. What dated commitments have you given customers in writing, rather than in a roadmap? The distinction is the whole answer.
  3. For products already in the field with cryptography fixed in firmware, what’s the path for existing customers? Frequently there isn’t one, and saying so is the honest answer.
  4. Which requirement is your schedule answering to? A supplier whose roadmap can’t name the instrument it’s built against has built it out of intentions.

Source: NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024, nist.gov.

What do you ask a sector regulator?

Three questions that establish whether anything reaches the private sector at all.

  1. What have you asked the entities you supervise about their cryptographic inventory, and what did they answer? No U.S. instrument requires a private company to inventory or migrate, so the sector regulator is the only route that reaches them without new legislation.
  2. Which entities in your sector would be unable to fund this, and what’s the estimate? Small water utilities, rural hospitals, and county government are the recurring categories. See Who pays for this.
  3. What would you need in order to require it? Sometimes existing authority is sufficient and unused. Sometimes it isn’t, and that answer is a legislative finding.

What do you ask a researcher or technical witness?

Four questions that produce calibration rather than a forecast.

  1. What would have to be demonstrated before you’d revise your own estimate? This produces the indicators worth watching, which is more durable than any date.
  2. What’s the strongest argument that this won’t happen? A witness who can state the skeptic case well is a witness worth trusting on the rest. The credible version is that fault-tolerant quantum computing may never be engineered at scale.
  3. Which parts of the field are genuinely contested? Parameter strength, whether to pair the new algorithms with the old, and whether the published timelines survive contact with real estates.
  4. What’s the difference between the qubit count in the press release and the threshold that matters? A headline number counts noisy physical qubits, and the threshold is stated in error-corrected logical qubits, each of which takes many physical ones.

Source: G. Kalai, “How Quantum Computers Fail,” arxiv.org; C. Gidney and M. Ekerå, 2021, arxiv.org; C. Gidney, 2025, arxiv.org.

Which questions waste the hearing?

Four, and each one hands the exchange to the witness.

  1. “When will quantum computers break encryption?” Nobody can answer it. The witness will either guess, which is unhelpful, or explain why they can’t, which consumes your time. The sourced range is 28% to 49% within 10 years from a survey of 26 experts, and no witness improves on that.
  2. “Are we secure?” Unfalsifiable, and every witness answers yes with qualifications.
  3. “Is this a real threat or hype?” Invites a debate rather than a fact. Multiple governments have published dated schedules against it, which settles the premise without the argument.
  4. “How much will it cost?” Before an inventory, no honest witness has a number. Asking whether the inventory is funded is the productive version.

What answer should end the hearing?

Three specific things, and their absence is itself the finding.

  1. A date the inventory will be complete, or the reason it can’t be.
  2. A named accountable official, rather than an office or a committee.
  3. A return date with the inventory results, the funding requirement, and the list of systems that can’t be updated.

Those 3 are the same outputs a well-run organization produces internally, which makes them a reasonable thing to require rather than an unusual demand.

Questions people ask

What’s the single best question? Whether an algorithm-level inventory exists and when it was last updated. An organization with a current one has almost certainly done the rest, and one without it hasn’t started regardless of the other answers.

What if every answer is “we’re working on it”? Apply the universal follow-up. “As of what date?” and “what will exist by when?” convert intention into a commitment on the record.

Is it fair to expect this to be finished? No, and expecting completion is the wrong bar. The standards were only finalized in August 2024 and the federal schedule itself runs to 2035. The reasonable bar is whether it has started, whether somebody owns it, and whether it’s funded.

How do I question a witness on something this technical? Every question above has a factual answer with a date or a count attached, so evaluating it needs no cryptography. The technical detail lives behind the answer rather than in it.

Should I ask about quantum key distribution? Only to test whether a witness distinguishes it from post-quantum cryptography. It addresses key exchange on a dedicated physical link and addresses none of the signature and authentication half, and several national authorities have declined to recommend it as a general replacement.

What if a witness quotes 2035? Ask which instrument that comes from. The 2035 in the founding U.S. directive carries “as is feasible” in the operative sentence, and the dates that bind land in 2027, 2030, and 2031.

Who should be in the room that usually isn’t? The records officer and the procurement lead. The first knows the confidentiality lifetimes and the second holds the fastest lever.

Where to go next

Go deeper into the technical detail

The technical version of the agency-facing questions is The Four Questions and The Binding-Date Questions.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.