The Quantum Clock Is Running

Google is targeting 2029. The federal government has established a 2030 objective for critical systems. Post-quantum cryptography is no longer a future cybersecurity problem.

For years, quantum computing occupied a comfortable category:

Important. Transformational. But distant.

That assumption is becoming increasingly difficult to defend.

McKinsey's Quantum Technology Monitor 2026 describes quantum technology as approaching a commercial tipping point, as investment, technical progress and adoption accelerate.

But there is another side of the quantum story. As quantum computing advances, so does the potential threat to the public-key cryptography protecting much of the world's digital infrastructure.

For government, the response has already begun.

The Timeline Has Changed

In March 2026, Google established an aggressive objective: complete its migration to post-quantum cryptography by 2029. Google has not declared that "Q-Day"—the arrival of a cryptographically relevant quantum computer—will occur in 2029. Its decision may be more consequential than making such a prediction.

Google wants to be protected by then.

Washington is moving quickly as well. Executive Order 14412, issued in June 2026, accelerated the federal government's transition to PQC. OMB followed with M-26-15, establishing a phased implementation roadmap and an objective of mitigating as much federal quantum risk as feasible by December 31, 2030.

For federal High Value Assets and high-impact systems, PQC key establishment is targeted for 2030, followed by digital signatures in 2031. The old conversation centered around 2035. The operational conversation now starts much sooner.

THE QUANTUM MIGRATION CLOCK

2026 → Discover & inventory
2027 → Plan & pilot
2028 → Begin prioritized migration
2029 → Google's PQC readiness target
2030 → Federal priority-system target
2031 → Digital signatures
2035 → Remaining migration

2029 isn't Q-Day. It's Google's readiness target.

2030 isn't when preparation begins. It's when major federal migration objectives arrive.

Why 2026 May Matter More Than 2030

It would be easy for government executives to look at 2030 and conclude there is still time. That misses the most important part of the federal roadmap.

The first phase is happening now.

Before an organization can migrate cryptography, it has to find it. Cryptography may be buried across:

Applications. APIs. Certificates. VPNs. Databases. Cloud environments. Network equipment. Identity systems. Third-party software. Operational technology. Industrial control systems.

For large organizations, there may be hundreds of thousands—or millions—of cryptographic dependencies. OMB M-26-15 recognizes this challenge, emphasizing cryptographic inventory, assessment and automated discovery.

The logic is simple:

You cannot migrate cryptography you cannot find.

From Inventory to CBOM

Executive Order 14412 goes further, directing CISA and NIST to develop guidance around a Cryptographic Bill of Materials, or CBOM.

Think of it as visibility into the cryptographic DNA of an organization.

What cryptography are we using? Where is it? Which algorithms are vulnerable? Which applications depend upon them? Which vendors need to act? Which systems must migrate first?

This could make cryptographic discovery and continuous inventory one of the most important cybersecurity disciplines of the next several years.

Why Government Faces a Different Problem

The challenge is particularly acute across the public sector. Federal agencies operate massive technology estates spanning modern cloud environments and decades-old mission systems.

States operate Medicaid, motor vehicle, tax, court, university, transportation and public-safety infrastructure. Cities and counties operate water, wastewater, emergency services, public buildings and increasingly connected infrastructure. Many of these assets have useful lives measured in decades.

And that creates a fundamental mismatch:

The systems with the longest replacement cycles may have the least time to prepare.

Harvest Now. Decrypt Later.

There is another reason the transition cannot wait. Adversaries don't necessarily need quantum computers today. They can steal encrypted information today and preserve it for potential decryption later.

National security information. Healthcare records. Biometric data. Infrastructure architecture. Intellectual property. Government communications.

If the information will remain valuable for another 10, 20 or 30 years, its quantum exposure doesn't begin on Q-Day.

It exists now.

2030 Is Closer Than It Looks

From 2026, the federal government's 2030 objective is only a few budget cycles away.

During that period organizations must:

Discover → Inventory → Prioritize → Procure → Test → Migrate → Verify

For complex federal agencies, state governments and critical-infrastructure operators, four years is not a particularly long time. Which leads to perhaps the most important distinction in the quantum conversation:

The quantum threat doesn't begin when today's encryption is broken. It begins when the time required to migrate becomes longer than the time remaining to protect it.

McKinsey sees quantum technology approaching a commercial tipping point. Google wants to be ready by 2029. The federal government is targeting major migration objectives by 2030.

The preparation phase is ending. The execution phase has begun.

Parkwood Intelligence

Parkwood Intelligence examines the intersection of capital, innovation, infrastructure, energy, cybersecurity and emerging technology—focusing on the structural shifts shaping the next generation of resilient infrastructure.

Primary References: McKinsey & Company, Quantum Technology Monitor 2026 · Executive Order 14412 · OMB M-26-15 · OMB M-23-02 · NIST Post-Quantum Cryptography Standards · Google PQC Migration Strategy

Next
Next

The Quantum Threat Isn't Coming. It Has Already Started.