Enable breadcrumbs token at /includes/pageheader.html.twig

The Real Threat of Quantum to Cryptography

Experts see several issues to consider across national security for the so-called post-quantum cryptography era.

 

The day when quantum computers can break present-day cryptography is coming, and it is a shorter time frame than previously thought. The potential “blast radius” to the United States from code breaking is significant, post-quantum cryptography (PQC) experts say.

Just as with cybersecurity, secure cryptology is key not only to national security but also to the U.S. economy, said Will Loucks, senior director for intelligence, White House Office of the National Cyber Director, speaking at the 2026 Intelligence & National Security Summit on August 26.

The event is co-hosted annually by AFCEA International and the Intelligence and National Security Alliance.

“Quantum-ready essentially means ensuring that our sensitive communications remain insulated from both classical and quantum cryptanalysis,” Loucks said. “The United States has to continue to remain a leader in quantum information, science and technology, and to harness quantum computing, sensing, networking and other technologies and their associated scientific applications. But while quantum technologies continue to advance, we also have to prepare for the advent of a cryptographically relevant quantum computer that could threaten the public key cryptography, that has been for decades critical to our economic and national security.”

Loucks and other quantum experts warned at the summit that the United States needs to act today to prepare.

“Getting ready for an eventual cryptographically relevant quantum device is one of the most important things that we can do over the next several years,” confirmed John Beieler, executive director, Applied Research Laboratory for Intelligence and Security, University of Maryland.

Constanza Vidal Bustamante, fellow, Technology and National Security Program, Center for a New American Security, urged organizations to avoid thinking that they do not need to act now.

“I think a super common question that people will say is, ‘Should we really be focusing on this problem right now? I have a million other things I need to take care of. Why should I be worried about this right now?’" Bustamante said. “But we are seeing pretty credible signs that the timelines for quantum computing are compressing across hardware and quantum error correction and the algorithms themselves that would break cryptography. So, we don’t need any more information before we start acting.”

This means organizations should begin surveying systems, budgeting, testing and implementing PQC solutions such as the National Institute of Standards and Technology’s PQC standards.

“That is especially true for national security systems, including the commercial technologies and algorithms that support them,” Loucks emphasized. “But it is also more generally true for federal networks and commercial systems more broadly.”

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

President Donald Trump’s executive order on quantum issued last month does accelerate the federal government’s timeline to migrate to post-quantum cryptography, with a deadline of moving critical systems to PQC protections by the end of 2030.

And preparing for the so-called “Q-day,” the day when code-breaking capabilities are available and in adversaries’ hands, is not just a one-and-done exercise, the experts warned.

Bustamante advised a holistic approach to migrating to PQC protections.

“I think the importance of crypto-agility is extremely important,” she stated. “Understanding that this is a capability that you have to build and upkeep. Then you need to be thinking holistically about this and not thinking that there’s going to be any super easy solutions, as the threat landscape evolves. This is something that we need to be planning for, as a process and a capability, not just as a one-off checkbox exercise.”

In addition, she said, organizations need to understand what the time frame involves.

“There are two timelines happening here,” Bustamante emphasized. “There’s one about the threat materializing, and the other one of the migration of what it takes to be quantum safe. And those are two interrelated things, but the migration piece is the piece that we need to really be paying closer attention to.”

In considering migrating critical data, organizations should first determine if they even have accounted for the need to address the problem and if they have the budget set aside for this process, advised Patrick Manley, lead for quantum security, Cybersecurity and Infrastructure Security Agency (CISA).

Next, organizations need to assess and prioritize which data to protect first.

“Especially in the national security space, you have got to think about what is most sensitive, what is the most critical data that is key to your operations,” Manley said. “Whether that is intelligence systems, whether that is sources and methods. What are the most critical systems that are housing that data and information?”

In addition, organizations should consider the life cycle of their data that needs to be protected in the PQC era.

“Is it 10 years, 20 years, 50 years?” he asked. “Or is it six months or two weeks? You have to walk down that path and understand what is most critical to your mission and what is most critical to your operators.”

Image
Constanza Vidal Bustamante
We are seeing pretty credible signs that the timelines for quantum computing are compressing across hardware and quantum error correction and the algorithms themselves that would break cryptography.
Constanza Vidal Bustamante
fellow, Technology and National Security Program, Center for a New American Security

Manley cautioned that not all data should be migrated to new PQC protections; it may be too expensive or cumbersome. Instead, replacement options should be considered.

He also noted that the "harvest now and decrypt later" threat continues, where adversaries are storing crucial stolen data from the United States until they can use quantum computing to break the code protections and leverage the sensitive information.

Also important to be wary of is the "trust now, forge later" threat, he continued.

“The authentication piece to me is very significant,” Manley stated. “It may not be something that we see until Q-day, whenever Q-day may be, but compromising your roots of trust, your certificate authorities, that trust infrastructure that you rely on, I think could be way more impactful when PQC is here because you won't know that the trust chain is compromised. You could have an adversary masquerading through that, and you would have no clue that it has actually been compromised.”

Organizations should evaluate their public key infrastructure, roots of trust, code and firmware, the panelists said.

Kathryn Wang, principal of the public sector at SandboxAQ, advised organizations to observehow the financial sector is adjusting for the PQC era. The efforts of the highly regulated industries in PQC can also benefit the government.

“The financial sector, they have a very high threat vector,” Wang noted. “J.P. Morgan, it is really interesting where they are putting their money. They are actually investing in data centers on their own because that’s how they are controlling the security aspect of it. So, I would take a look at some of the larger, more well-funded industries and how they are approaching post-quantum.”

In addition, Manley noted that the U.S. Treasury created a PQC-related task force, and its solutions or outputs could be helpful to the intelligence community and the greater defense industrial base. “Watch for what comes out of the U.S. Treasury,” he said.

Lastly, organizations also need to consider the threat of artificial intelligence and quantum computing.

“What keeps me up at night is the convergence of AI with quantum,” Manley said. “We have seen some research papers recently. Anthropic is using frontier models for cryptanalysis and is identifying weaknesses in previous candidate algorithms that NIST had found weaknesses in over time, but this was able to do it in an accelerated rate. We are going to see the convergence of AI and quantum from a cryptanalysis perspective, but also from a development perspective.”

The 2026 Intelligence & National Security Summit is co-hosted by AFCEA International and INSA. SIGNAL Media is the official media of AFCEA International.

Comments

The content of this field is kept private and will not be shown publicly.

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.