
istock.com/MaxxaSatori
One of the most common questions I hear from federal leaders is, "Where are we supposed to find the budget for post-quantum cryptography?"
For years, quantum security was treated as something on the horizon. Agencies could acknowledge it, monitor standards development, and assume there would be time to figure out funding later.
Executive Order 14144 established quantum-resistant cryptography as a federal cybersecurity priority. More recently, new Executive Orders reinforced that the federal government expects agencies to move from planning to execution. The timeline for modernization is no longer 2035, and neither is the expectation that agencies begin making measurable progress.
The timeline according to the newest EO 14412 has shifted to 2030 for key establishment and 2031 for digital signatures. The new industry consensus regarding the availability of a cryptographically relevant quantum computer (CRQC) is 2029.
The good news is that many agencies don't need to build an entirely new program to get started. They need to recognize that much of the foundation already exists within the cybersecurity modernization initiatives they are funding today.
Post Quantum Cryptography Is Not Separate From Cybersecurity
One of the biggest misconceptions surrounding post-quantum cryptography (PQC) is that it requires standing up an entirely new cybersecurity program.
In practice, quantum readiness is another architectural requirement that should be incorporated into the modernization efforts already underway.
Federal agencies have spent the last several years investing in Zero Trust Architecture (ZTA), identity modernization, secure communications, continuous diagnostics, enterprise visibility, and cyber resilience. Those investments are not competing with PQC. They create many of the conditions that make successful migration possible.
The modernization work already being funded can also establish the operational foundation for future cryptographic transitions, reducing the need for large-scale modernization each time cryptographic standards evolve.
Solving Different Problems
It is equally important not to confuse Zero Trust (ZT) with PQC. The ZT concept says that users, devices, and workloads cannot be trusted. It focuses on identity, authorization, segmentation, and continuous verification.
PQC is about protecting those trusted communications that still need to be secure when quantum computers become capable of breaking today's public key algorithms. ZT governs who should communicate and PQC protects how assets can communicate without fear of adversaries acquiring and decrypting data.
Because an organization has implemented several pillars of ZT based on NIST 800-207 or the CISA ZT model does not mean that PQC is not required. Sensitive data in ZT will still need to be transmitted securely within and outside of an organization. Furthermore, PQC cannot replace the elements resident in ZT. Together, they create a stronger security architecture.
The Overlap Is Larger Than Many Realize
Although the objectives differ, the operational work overlaps considerably. Both ZT and post-quantum migration depend on understanding where cryptography exists across the enterprise. Both require centralized policy, continuous visibility, lifecycle management, and the ability to evolve security controls without rebuilding every application.
Viewing PQC as a compliance effort that supports your already funded efforts, agencies and organizations can accelerate and measure progress by incorporating PQC requirements into modernization initiatives already receiving investment. This means modernizing network encryption as part of ZT architecture, building enterprise cryptographic inventories alongside existing asset discovery efforts, and updating certificate and key management practices to support future cryptographic algorithms.
It also means establishing centralized cryptographic policy, rather than relying on application-by-application configuration. As agencies modernize, they should prioritize infrastructure that supports cryptographic agility, so algorithms can evolve without costly wholesale rip and replacement of existing technology. Each of these activities strengthens ZT posture today while systematically preparing agencies for tomorrow's cryptographic requirements.
This also changes how agencies should approach implementation. Agencies do not need to complete every inventory or planning activity before beginning migration. The most effective modernization efforts allow discovery, prioritization, and implementation to progress together, enabling agencies to reduce risk, demonstrate measurable progress, and refine migration plans as their understanding of the environment grows.
What Is Different About Post-Quantum Cryptography?
Post-quantum migration introduces new technical requirements. Organizations need visibility into where vulnerable public key cryptography is used across networks, applications, devices, certificates, VPNs, APIs, and operational technology so they can prioritize migration efforts, begin with their highest-value systems, and refine implementation as their understanding of the environment grows.
As agencies gain that visibility, they can identify cryptographic dependencies, determine which systems can transition to NIST-standardized algorithms, and continuously evolve migration strategies that minimize operational disruption.
Perhaps most importantly, agencies need infrastructure that supports cryptographic agility. This is where PQC differs from previous algorithm transitions. Cryptographic agility is not simply about the ability to replace algorithms, it is building the ability to change cryptography as standards evolve, threats mature, and mission requirements change over time.
That flexibility becomes a long-term cybersecurity capability, versus one-time compliance exercise. In addition, it allows for maintainability, sustainability, and affordability of already operational systems. There is minimal enterprise systems rip-and-replace cost and operational downtime.
Executive Orders Have Shortened the Timeline
Recent Executive Orders, combined with existing federal guidance, make clear that agencies are expected to inventory cryptographic assets, understand their exposure, and begin implementing migration plans now. Agencies and organizations cannot wait until an error correcting quantum computer capable of breaking public key encryption arrives because the cryptographic debt that will be due is going to be extreme and cannot be covered in time to protect loss of sensitive data.
Enterprise-scale cryptographic modernization takes years, and many federal systems are expected to remain operational well into the 2030s. The consensus of most of the larger quantum computer vendors is that a cryptographically relevant quantum computer (CRQC) will arrive by 2029. This leaves agency and organizational sensitive data vulnerable to decryption by the CRQC.
NIST has finalized the first generation of post-quantum algorithms. Agencies have to execute and begin implementation. Federal cybersecurity leaders should resist the temptation to treat every new requirement as another standalone program.
Agencies that integrate quantum readiness into their modernization work already planned and in progress, will more than likely complete their PQC migration work by 2029.
If you're implementing ZT, improving visibility, modernizing network security, strengthening cryptographic governance, or investing in cyber resilience, you are already building many of the capabilities needed for the PQC migration.
The next step is ensuring the cryptography beneath those investments is ready for the deadlines that are now measured in years, not decades. The goal of a PQC migration should be to help agencies modernize the security programs they already have in place, not create new ones.






















