A couple of weeks ago, on June 22, 2026, the President signed two executive orders on quantum technology: EO 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” and EO 14413, “Ushering in the Next Frontier of Quantum Innovation.” This was a big moment! I know I had been waiting for these executive orders since the Presidential transition.
Together, the two executive orders set firm new deadlines for the federal government’s move to post quantum cryptography, including a transition of high value assets by the end of 2030 and a requirement that covered contractors meet NIST’s post quantum standards on a similar timeline.
Finally!!!
What was the excitement? For years there were mandates and timelines set, but no one moved. I used to be a cybersecurity specialist before we had the term cyber (yes, I am that old). But, in my career, when you know there is a threat, we like to eliminate it immediately. Our security posture has been threaten, we knew about, and still didn’t move. Errrr…..
So, within days of the EOs being released, I watched:
- the response unfold in real time. Job postings asking for Post-Quantum Cryptography (PQC) SMEs with 15 years of experience started appearing by the dozen.
- agencies scramble to figure out what came next.
- contractors who assumed PQC was a government only problem realize, often for the first time, that the requirement reaches them, too.
- organizations sign vendor contracts quickly, sometimes to show movement, sometimes to close out fiscal year dollars, but consistently without a clear sense of what they were actually buying.
I understand the urgency. The threat is real, and NIST has been telling us for years that one day the encryption we have gotten used to for decades will not be a strong match to power quantum computers. But as a taxpayer and as someone who spent 21 years in government service, I have also seen what happens when we buy in a hurry: shelfware, mismatched tools, mission outages, and money spent that did not solve the problem at all.
So here is where I want to start this series: it is okay to plan. It is okay to ask hard questions. It is okay to run a bake off before you sign anything. There are dozens of PQC vendors in this country, each with real strengths and real gaps, and no single one of them solves the whole problem. Rushing to a single solution because it is fast does not close your exposure. Rushing to a solution just tells the adversary which weakness to find first. I spent years on the offensive side of this work, and I can tell you plainly: attackers look for the door you did not think to check.
Over the next few weeks, I am going to walk through my thoughts on PQC. The right path might not the fastest path, but it will be even better – the responsible one. For the security across our nation, the goal should never be to spend the fastest or to hit a quota. The goal is to secure our systems against a threat we already know is coming, using the talent and resources we have as a country to get ahead of it, together. That is how we won every technology fight!