The Government Just Started a Race Against Hackers Who Don’t Exist Yet

by Zonabia

WASHINGTON — In June, the White House ordered federal agencies to move up their deadline for switching to hacker-proof encryption by roughly four to five years. The threat driving the urgency isn’t a quantum computer that exists today. It’s the data being stolen right now, banked for later.

Why it matters:  Security officials call it “harvest now, decrypt later.” Foreign adversaries can already intercept and store encrypted American data today, then simply wait for quantum computing to catch up and crack it open years from now. For any data that needs to stay secret for a decade or more, that future threat is a today problem.

What the order actually requires

The new deadlines replace a 2022 target, National Security Memorandum 10, that gave agencies until 2035 to finish migrating. Under the June order, federal civilian agencies now have to move their highest-value systems to quantum-resistant encryption on a much faster schedule, and every agency had 30 days to name a migration lead reporting directly to its chief information officer.

The order doesn’t stop at federal networks. The Federal Acquisition Regulatory Council has 180 days to write a rule giving federal contractors until December 31, 2030 to comply. A second rule, due within 270 days, would fold cryptographic weaknesses into existing contractor vulnerability disclosure requirements.

The standards have existed for two years

None of this is coming out of nowhere. NIST finalized the actual post-quantum encryption standards back in August 2024: ML-KEM (formerly known as CRYSTALS-Kyber) for securely establishing keys, and ML-DSA and SLH-DSA for digital signatures. The government has known how to do this since 2024. What changed in June is the deadline, not the technology.

Some of the migration is already happening quietly, at massive scale. Cloudflare, Google, and Apple have all deployed hybrid post-quantum key exchange to billions of users already. This isn’t a future hypothetical for at least part of the internet’s core infrastructure. It’s already live.

Everyone else is behind

That’s the good news. The bad news: industry surveys suggest only about one in eight organizations have actually moved post-quantum cryptography into production. A majority haven’t started a real migration at all.

Part of the problem is that this isn’t a simple software patch. Post-quantum algorithms need bigger keys and more computing overhead than the RSA and elliptic-curve methods they’re replacing, which means some older hardware and legacy systems may need full replacement, not an update. Before any of that, security teams first have to build a complete inventory of every place their organization uses encryption, a task many haven’t ever fully finished, even for what they’re using today.

A May estimate put the total global cost of this migration at roughly $15 billion, a number that only grows the longer organizations wait. Emergency fixes under deadline pressure always cost more than a planned migration.

When does the clock actually run out

Nobody knows exactly when a quantum computer capable of breaking today’s RSA-2048 encryption will exist. Google has warned it could arrive as early as 2029. Most independent researchers cluster their estimates closer to 2033 to 2035.

The bottom line:  The uncertainty over exactly when doesn’t change what’s happening right now: your encrypted data, if it’s worth stealing, may already be sitting in a folder somewhere, waiting. The government just decided waiting to prepare for that isn’t an option anymore either.

Why this is harder than a normal upgrade

Post-quantum migration isn’t a patch you push out overnight. The new algorithms need bigger keys and more computing power than the RSA and elliptic-curve methods they’re replacing, which means some older hardware and legacy systems may need full replacement rather than a simple update. CISA, working jointly with the NSA and NIST, has published a migration playbook aimed at helping both federal agencies and private companies build a cryptographic inventory and prioritize which systems to convert first, a task complicated by the fact that most organizations have never fully mapped out where they use encryption in the first place.

Federal officials involved in the planning describe the 30-day deadline for naming a migration lead as a deliberate attempt to avoid the effort becoming an unfunded mandate that quietly stalls for years, the same fate that has befallen other major federal IT modernization pushes in the past.

You may also like