The United States is in a race to develop its quantum capabilities and to migrate critical systems to post-quantum cryptography before standard encryption practices become obsolete. That’s because AI is merging with quantum computing and rapidly accelerating the timeline to Q-day. Frontier models can allow technologists to identify more efficient ways to design, architect, and scale quantum computers. In fact, it is now estimated that previous timelines predicting Q-day’s arrival in 2031 are even further compressed.
Quantum Progress Is Outpacing Expectations
Google’s ‘Willow’ quantum chip project has demonstrated significant advancements in quantum computation, and Microsoft’s “Majorana 2” developments have reportedly accelerated the company’s projected timeline for deployable use to 2029. These developments don’t mean that Q-Day has arrived, but they do demonstrate why organizations can’t afford to treat quantum risk as a problem that can wait until the technology becomes operational.
Adversaries are already deploying “harvest now, decrypt later” (HNDL) strategies that involve collecting encrypted data today with the expectation that future quantum capabilities will allow them to decrypt it. Information with a longer shelf life, including personal information, classified material, financial records, private communications, and intellectual property, will retain value long after it’s stolen. Agencies are now being forced to seriously consider and mitigate the risks of the US government’s most sensitive, classified secrets being exposed and exploited.
The Longer-Term Risk: Trust Now, Forge Later
While HNDL attacks may seem like the primary concern to be addressed leading up to Q-Day, one of the more underappreciated risks of the arrival of Q-Day is “Trust Now, Forge Later” (TNFL). Rather than targeting encrypted data, an adversary could target the systems that establish digital trust, including certificate authorities, code signing certificates, public key infrastructure, and other roots of trust. If those trust mechanisms are broken, an attacker could masquerade as a trusted individual with malicious intent within a system or forge digital signatures without detection. Beyond just leaking sensitive data, these attacks would undermine the authentication and trust mechanisms we have in place. While HNDL attacks are a legitimate concern leading up to Q-day, TNFL raises a longer-term concern about how organizations will ensure trust across their systems.
Federal Policy Sets a 2031 Target for PQC
Federal policy reflects the urgency of preparing for quantum capability. On June 22nd, the White House issued two landmark Executive Orders aimed at accelerating the United States’ transition to post-quantum cryptography (PQC) and strengthening domestic scientific capabilities. By directing federal agencies to migrate their high-value assets and high-impact systems toward quantum resilience by 2031, the federal government is signaling the importance of leading the charge in quantum readiness as both a national security requirement and a strategic economic priority.
Executive Order 14412 “Securing the Nation Against Advanced Cryptographic Attacks” establishes a coordinated federal approach to transitioning IT systems to post-quantum cryptographic standards developed by the National Institute of Standards and Technology (NIST), including FIPS 203, 204, and 205. The Office of Management and Budget and the Office of the National Cyber Director will play important roles in establishing the broader timeline and strategy.
Executive Order 14413 “Ushering the Next Frontier of Quantum Innovation” is also worth noting. While the Quantum Innovation EO does not explicitly focus on PQC, it does tie into PQC readiness through its focus on technology protection. Securing the quantum innovation ecosystem is critical to preventing adversaries from acquiring the intellectual property, research, and technologies needed to close the gap.
Why PQC Migration Reaches Beyond Government
While federal agencies accelerate their PQC efforts, the effects will not remain contained within the government. Oversight bodies, including CISA, NIST, and the NSA, are already shaping the technical guidance, standards, and procurement expectations for quantum-resistant migration, but they can’t transition alone. Agencies depend heavily on industry partners, particularly across critical infrastructure and interconnected supply chains. The speed at which the government can migrate its cryptographic assets will depend on how ready vendors are to incorporate PQC algorithms into their architectures and to meet evolving procurement requirements.
While vendor-led solutions can accelerate implementation and give organizations a clearer path through evolving requirements, overreliance can also come with long-term architectural consequences. Most large organizations operate complex environments containing legacy systems, embedded firmware, third-party products, operational technology, industrial control systems, and long-life-cycle hardware. Some of these systems may not be easily upgraded without significant hardware refreshes or vendor support, which creates a visibility problem. Ultimately, organizations can’t migrate everything at once, and they certainly can’t migrate what they can’t see.
Organizations need to understand exactly which cryptographic assets they have, where those assets are located, and which pose the highest risk and therefore need to be prioritized for migration. Some data may have a short enough shelf life or be insignificant enough that migrating it would be more costly than losing it to decryption. The goal of a successful migration isn’t simply to move every single asset into compliance; it’s to understand and continuously mitigate the greatest risks.
Prioritizing Cryptographic Risk Over Total Migration
A vendor-neutral approach does not necessarily mean delaying migration or rejecting vendor expertise; it means ensuring that technology decisions are driven by the highest level of up-to-date security possible. PQC is not a product that can be purchased once and considered compliant; computing capabilities will continue to evolve, and regulation standards will evolve with them. Locking into one vendor would limit an organization’s ability to adapt to this ever-evolving risk without operational disruption.
Visibility is an important step in every PQC migration. Every organization needs an accurate and comprehensive understanding of what exists across their environments and where the cryptographic risks are located. Forescout can support this process by providing that inventory and the critical context required to prioritize migration efforts and measure risk reduction over time. This is especially important at the endpoint and across internal network traffic, where outdated or weak encryption may otherwise go unnoticed.
Speed Alone Is Not the Goal
Ultimately, organizations cannot protect or migrate assets they don’t know exist.
The transition to quantum capability is creating enormous pressure on both government and industry. Federal agencies are working to rapidly accelerate timelines, technology vendors are adapting their products to meet government demand, and security leaders are being asked to make decisions about critical systems and data that affect the privacy and national security of an entire nation. In an environment where policy urgency, technological change, and market pressure are accelerating rapidly, speed alone is not the goal.
The organizations that successfully navigate the quantum transition will not necessarily be the ones that transition the fastest, but rather those that understand their risks, establish visibility across their environments, prioritize their most critical assets, and maintain sufficient flexibility to adapt to the evolving technology and threat landscape.
Go deeper: Explore Forecout’s PQC Intelligence Center for research, real-world data, and practical migration and planning guidance.
Blogs:
PQC Adoption Gaps: 90% of Systems Are Still Not Quantum-Safe
Before Q‑Day, Visibility Is the First PQC Move
Countdown to Q-Day: What PQC Ciphers Are You Using Today?
G7’s Post‑Quantum Cryptography Roadmap in Plain English
Q-Day Countdown: New Data on Post-Quantum Cryptography Adoption Across Devices and Industries
Post Quantum Cryptography: An Urgent Global Cybersecurity Imperative