The Quantum Transition Has Already Begun
The question is no longer whether organizations should prepare for post-quantum cryptography. It is how quickly they can understand their exposure—and begin reducing it.
For years, the quantum threat occupied an unusual place in cybersecurity. The science was real and the implications potentially enormous, but the timeline remained uncertain enough that quantum-resistant security could comfortably remain a future planning issue.
That period is ending. The transition to post-quantum cryptography is no longer waiting for the arrival of a cryptographically relevant quantum computer. Standards have been established, federal policy is accelerating, migration timelines are taking shape, and organizations are beginning the difficult work of understanding where vulnerable cryptography exists across increasingly complex technology environments.
The Standards Now Exist
The most important change is also the simplest: organizations no longer need to wait for the first generation of post-quantum standards.
In August 2024, the National Institute of Standards and Technology finalized its first three principal PQC standards—FIPS 203 for ML-KEM, FIPS 204 for ML-DSA and FIPS 205 for SLH-DSA. NIST now explicitly encourages organizations to begin applying these standards and migrating systems toward quantum-resistant cryptography.
Additional standardization work continues, but that should not be confused with a reason to delay. The challenge has moved from determining which algorithms will become standards to figuring out how to migrate the enormous installed base of technology that relies upon today's cryptography.
That is a fundamentally different problem.
2035 Sounds Farther Away Than It Is
NIST's transition framework calls for quantum-vulnerable algorithms to be deprecated and ultimately removed from its standards by 2035, with higher-risk systems transitioning earlier. Federal requirements are becoming more concrete as well. A June 2026 Executive Order directed federal agencies to designate PQC migration leads, maintain cryptographic inventories and develop prioritized migration plans. It also established a December 31, 2030 target for High Value Assets and high-impact systems to transition to PQC for key establishment.
National Security Systems operate under their own transition requirements, including NSA's CNSA 2.0 framework. Together, these developments point toward a transition that will unfold over years rather than months.
The dates matter, but focusing exclusively on deadlines risks missing the larger issue. Cryptographic migration is not a software update. It is a multi-year transformation of security mechanisms embedded throughout modern digital infrastructure.
You Cannot Migrate What You Cannot See
Cryptography is everywhere: applications, servers, network devices, APIs, certificates, identity systems, cloud environments, embedded systems, software libraries, databases and third-party products. Much of it remains effectively invisible during ordinary operations, and large organizations may not know precisely which algorithms are being used, where they are being used, what information they protect or which systems depend upon them.
That is why cryptographic discovery and inventory are becoming foundational capabilities for quantum readiness.
The federal government recognized this challenge early. OMB Memorandum M-23-02 requires agencies to maintain prioritized inventories of systems containing cryptography vulnerable to a cryptographically relevant quantum computer, with particular attention to High Value Assets and high-impact systems.
The difficulty is that inventory cannot simply be treated as a one-time spreadsheet exercise. Cryptography is deeply embedded, technology environments continuously change, and automated tools may not identify every implementation. Effective cryptographic visibility therefore needs to become an ongoing operational capability rather than a temporary compliance project.
Inventory Is Only the Beginning
Knowing that vulnerable cryptography exists does not tell an organization what it should migrate first. Consider two encrypted datasets: one contains information whose useful life ends next month, while the other contains sensitive information that must remain confidential for twenty years. Their exposures are clearly not equivalent.
The same applies to systems. One application may be relatively straightforward to upgrade, while another depends upon legacy hardware, embedded devices, specialized applications, third-party products or mission-critical infrastructure that cannot tolerate significant downtime.
A meaningful PQC program therefore needs to move beyond inventory and establish context. Organizations need to understand what cryptography they have, where it resides, what it protects, how sensitive the underlying information is, how long that information must remain secure, who owns the system and how difficult migration is likely to be.
The objective is not simply a cryptographic inventory. It is a risk-prioritized migration map.
The Exposure Window May Already Be Open
Quantum risk contains an unusual characteristic: an attacker does not necessarily need a quantum computer today to create a future compromise. Sensitive encrypted information can potentially be collected now and retained until sufficiently capable quantum computing becomes available—a threat commonly described as “harvest now, decrypt later.”
For information with a short useful life, that risk may be limited. For national-security information, intellectual property, financial records, critical-infrastructure data or other information expected to remain sensitive for many years, the calculation changes.
The relevant question becomes whether information being protected today will still need protection at the point when today's cryptography may no longer provide adequate security. If the answer is yes, the quantum-risk horizon is not simply the date on which a sufficiently capable quantum computer arrives. The exposure window may already have opened.
Migration Creates Its Own Risk
There is another reason to start early: large cryptographic transitions are inherently complex. Systems must be discovered, dependencies mapped, vendors evaluated, applications tested, certificates changed, protocols updated, hardware replaced, procurement cycles navigated and mission-critical operations protected from disruption.
For a significant period, many organizations will also operate mixed environments containing both classical and post-quantum cryptography. NIST's 2026 work on federal Personal Identity Verification provides an instructive example, contemplating approaches that preserve classical capabilities while adding PQC credentials to support backward compatibility and incremental deployment.
The implication is important. PQC migration will be a transition, not an event. Organizations that begin discovery and planning early gain the ability to migrate deliberately; organizations that wait risk eventually being forced to migrate under deadline pressure.
Quantum Readiness Is Becoming an Enterprise Issue
PQC is understandably discussed as a cybersecurity problem, but its implications extend well beyond the security organization. CIOs must consider enterprise architecture and modernization; CISOs must understand cryptographic exposure; acquisition teams need to consider PQC requirements in future purchases; legal and compliance teams must understand obligations surrounding long-lived sensitive information; and business or mission owners must consider the operational consequences of changing critical systems.
For government agencies and operators of critical infrastructure, this becomes particularly important because technology lifecycles can extend for many years. Equipment purchased today may still be operating well into the next decade, meaning quantum readiness increasingly needs to influence procurement and architecture decisions being made now.
This is also why the transition should not begin with a particular product or vendor. Technology will unquestionably play a critical role, but strategy should precede procurement.
Discovery Before Migration. Strategy Before Procurement.
A durable quantum-readiness program begins by understanding the environment before determining how it should change. Organizations first need visibility into their cryptographic estate, followed by an inventory that identifies vulnerable implementations and an assessment of the sensitivity, longevity and operational importance of what those implementations protect.
From there, organizations can prioritize systems according to exposure and migration complexity, build phased roadmaps aligned with standards and procurement cycles, introduce appropriate quantum-resistant capabilities, and establish the ongoing cryptographic visibility required to maintain crypto-agility.
That sequence is intentionally technology-neutral. It allows organizations to select technologies based upon architecture, mission requirements and risk rather than allowing a particular product to define the strategy.
It also points toward a broader lesson emerging from the PQC transition. Cryptography can no longer be treated as something permanently embedded within systems. Algorithms change, standards evolve, vulnerabilities emerge and computing capabilities advance. Organizations increasingly need architectures that allow cryptographic mechanisms to be identified and changed without rebuilding entire technology environments.
PQC may be the immediate catalyst, but crypto-agility may ultimately prove to be the more durable enterprise capability.
The Transition Has Begun
No one can say with certainty when a cryptographically relevant quantum computer will arrive. Fortunately, organizations do not need to answer that question before acting.
The important facts are already known. Today's public-key cryptography faces a future quantum threat; replacement standards now exist; migration will take years; federal requirements are accelerating; long-lived sensitive information may already face future exposure; and organizations cannot migrate cryptography they do not know they have.
The strategic question has therefore changed. It is no longer simply, When will quantum computing become a cybersecurity problem? It is:
How much time will we give ourselves to prepare?
For organizations responsible for critical systems and long-lived sensitive information, preparation can begin today with visibility, inventory, prioritization and a deliberate migration strategy.
PARKWOOD INTELLIGENCE
Parkwood Intelligence examines structural shifts across infrastructure, technology, markets and national security.