Maria Korolov
Contributing writer

Aggressive federal PQE timeline prompts warnings for enterprises

News
Jun 27, 20265 mins

As the Department of War doubles down on post-quantum encryption, enterprises need to get going on plans to establish inventory and remediation programs for post-quantum cryptography, Gartner advises.

What you need to know to stay secure from the quantum threat
Credit: Shutterstock

The Department of War has recognized the national security threat posed by quantum computers and has put some teeth behind the federal government’s push for quantum-proof encryption. It announced plans for a centralized oversight structure for post-quantum encryption, scanning vulnerable systems, coordinating migration roadmaps, and developing post-quantum cryptography for defense needs.

The department has also released a strategy document which says it will update the Cybersecurity Maturity Model Certification (CMMC) to include PQC. As of this November, federal contractors will begin to be required to have third-party certification of CMMC compliance. Previously, they were allowed to self-attest, a much lower standard.

The DoW announcement comes just a day after an executive order requiring all federal contractors to comply with NIST’s post-quantum cryptography standards by the end of 2030. In addition, the president ordered the Secretary of Commerce to initiate a pilot project for PQC migration within the next 180 days — and the pilot needs to be completed by the end of 2027. (See related story: Presidential order addresses quantum computing gaps)

“Adopting PQC is imperative for both national and economic security,” says Jordan Kenyon, senior quantum scientist at Booz Allen Hamilton. “The US government just set an aggressive timeline.”

The executive order sets a deadline of December 2030 for key establishment and December 2031 for digital signatures in high-impact systems and assets.

In a report Tuesday, Gartner warned that enterprises should brace themselves for more government interventions — and the confusion and complexity that might result.

“The U.S. government’s EOs will likely spur accelerated intervention from all major governments and regional political blocs,” the firm said. “CISOs should be prepared for regulations to conflict and contain sovereignty requirements, which will complicate compliance.”

Gartner recommends that companies build a PQC inventory and remediation program in 2026 and engage vendors about their PQC timelines. In addition, companies should move to automated cryptographic bills of materials in 2027, transition to TLS 1.3 by 2028, and move all high-value and high-impact systems to PQC by 2030.

According to Gartner, fewer than 10% of organizations support post-quantum cryptography for high-value data and systems, but that is expected to increase to 80% by 2030. “Organizations that haven’t started piloting PQC by 2027 can expect to pay at least 200% more for their full PQC migration,” Gartner analysts predict.

“It’s no longer a ten-year runway,” says Garfield Jones, SVP of research and technology strategy at QuSecure, a cybersecurity vendor. “It’s two and a half years that we have to move in.”

According to QuSecure’s Jones, the hardest part of the transition will be in legacy systems.

“The cloud vendors have started to help out on that and have implemented the algorithms and implemented TLS,” he says. “But what about your on-prem solutions, your operational technology solutions, your legacy IT that can’t move to the cloud? The edge technology? Those are areas that you have to look at.”

Many OT systems are on a 20- or 30-year life cycle, he says, and organizations may not want to immediately replace them.

In some cases, old technology can be a matter of life and death. “I mean, you’ve got medical devices that carry very relevant information,” Jones says. “If your doctor is getting wrong information about you, then it’s a problem.”

One solution is to put a secure wrapper around the legacy systems, he says. “So you don’t have to take out all your OT and you can go on their natural refresh cycle.”

The Department of War recommends against this approach, however. “Proxy solutions for PQC should be avoided with a focus instead on actual network upgrades to PQC,” the department said in its post quantum cryptography strategy document.

Read more about quantum computing and HPC

Maria Korolov
Contributing writer

Maria Korolov is an award-winning technology journalist with over 20 years of experience covering enterprise technology, mostly for Foundry publications -- CIO, CSO, Network World, Computerworld, PCWorld, and others. She is a speaker, a sci-fi author and magazine editor, and the host of a YouTube channel. She ran a business news bureau in Asia for five years and reported for the Chicago Tribune, Reuters, UPI, the Associated Press and The Hollywood Reporter. In the 1990s, she was a war correspondent in the former Soviet Union and reported from a dozen war zones, including Chechnya and Afghanistan.

Maria won 2025 AZBEE awards for her coverage of Broadcom VMware and Quantum Computing.

More from this author