In Part 1, we covered the basics: what post-quantum cryptography (PQC) is, how today’s encryption works, and why quantum computers are a different kind of threat. This threat is already in motion thanks to a strategy called “harvest now, decrypt later,” even before a quantum computer capable of breaking today’s encryption actually exists.

Now for the part that lit a fire under a lot of organizations that were quietly hoping this would stay someone else’s problem: a new federal executive order, where the industry actually stands today, and what your security team should be doing about it right now.

Spoiler: “wait and see” didn’t make the list.


You may have seen the term Q-Day floating around. It’s the name researchers and security professionals use for the moment a quantum computer becomes powerful enough to break today’s encryption. We don’t know exactly when Q-Day arrives, but the executive order makes it clear that the U.S. government isn’t waiting to find out.  

Where the Industry Stands Today

For a long time, PQC existed in the most dangerous category in cybersecurity: “important but not urgent.” Important-but-not-urgent things have a way of staying on the to-do list indefinitely… right up until someone puts a deadline on them. Consider a deadline officially put.

Signed on June 22, 2026, the order Securing the Nation Against Advanced Cryptographic Attacks requires U.S. federal civilian agencies to migrate to the new, NIST-approved PQC standards by December 31, 2030 for key encryption upgrades, and December 31, 2031 for digital signatures. Some of the key requirements:

  • Within 30 days, every federal agency must appoint a specific person to lead its PQC upgrade, reporting directly to the agency’s Chief Information Officer.
  • Within 90 days, agencies must begin creating a full inventory of their most important systems and data, then upgrade those systems to meet the 2030 and 2031 deadlines.
  • Companies that sell technology to the federal government will face new purchasing rules requiring their products to support the new encryption standards, also aiming for the 2030 deadline.
  • Two agencies, NIST and the Cybersecurity and Infrastructure Security Agency (CISA), are directed to publish guidance on how organizations should document exactly what encryption is running inside their own software and hardware. This is sometimes called a “cryptographic bill of materials,” which is essentially a detailed ingredients list for encryption.
  • The order specifically names “harvest now, decrypt later” as one of the main risks driving the new rules.

Now, technically, this order applies directly to federal agencies and the companies that sell to them, not to private businesses in general. So if you’re already mentally drafting your “not our problem” memo, hold that thought. As analysts at Palo Alto have pointed out, any organization that sells to the government, runs critical infrastructure, or operates in a regulated industry like energy, finance, or healthcare should expect similar expectations to show up in their own world soon (even without a law requiring it yet).

Federal cybersecurity rules have a funny way of becoming everyone’s rules. They start there, then slowly work their way into vendor contracts, client expectations and industry norms, and then suddenly, they’re just the standard. If your organization has any connection to a government supply chain, that process is already in motion.

What Security Teams Should be Doing Right Now

Waiting for a fully working quantum computer, or for a deadline that clearly applies to your organization, is the wrong approach. The upgrade itself takes years to complete, and “harvest now, decrypt later” means sensitive data may already be at risk today. Here are the first practical steps you can take to begin your quantum strategy:

  1. Build an inventory of your encryption. Find out where encryption is being used across your organization. This can be in your software, network connections, certificates, hardware, and outside tools or vendors. You can’t plan an upgrade without first knowing what you have. (Yes, this step is less exciting than deploying new algorithms. Yes, it’s non-negotiable.)
  2. Prioritize based on risk. Not everything needs to change at the same time. Lead with systems protecting your most sensitive longest-lived data, which would be the stuff most exposed to “harvest now, decrypt later” risk.
  3. Check in with your vendors and suppliers. Ask directly where they stand on supporting the new standards. “We’re working on it” is not the same as “we’re ready,” and now is a good time to find out which one you’re actually hearing.
  4. Test before you commit. Try new methods in lower-risk environments first. Larger key sizes have a way of exposing compatibility issues you didn’t know existed. Much better to find those in a test environment than at 2am on a Tuesday.
  5. Design for flexibility, not a single fix. The standards are still evolving. Build systems so that encryption methods can be updated later without full redesign. Future-you will be grateful.
  6. Treat this as an ongoing project, not a single task. This upgrade will span years and multiple rounds of new standards. Make sure someone owns it continuously, not just during an initial audit and never again.

The Best Time to Start PQC Was Yesterday

At some point, “we’re monitoring the situation” stops being a strategy, and for a lot of organizations, that point is now. The dates are on the calendar. The question is just how much runway you want to give yourself.

But if we’re being honest, the deadline is almost beside the point. Data encrypted today has a shelf life for staying secret, and quantum computers will eventually catch up to it. Upgrading isn’t something that happens overnight. Finding all your encryption, testing new methods, working with vendors, and training your team… none of that goes smoothly when it’s compressed into a last-minute scramble.

The organizations that come out ahead won’t be the ones waiting for an ambiguous “it’s time” signal. They’ll be the ones who started while there was still time to do it right.

If you missed Part 1 on what PQC is and why quantum computers change the math, you can catch up here.


PQC Frequently Asked Questions

We’re not a federal agency. Does this actually apply to us?

Technically, no. Practically, yes. If your organization sells to the government, touches a federal supply chain, handles sensitive data, or operates in a regulated industry like finance, healthcare, or energy… this applies to you. Federal mandates have a long history of becoming industry-wide expectations within a few years. Plan accordingly.

2030 is four years away. Why does this need to be on my radar right now?

Because the migration itself takes years. You need to find all the places encryption lives in your environment, prioritize what to upgrade first, test the new methods, work through vendor readiness, and roll out changes without breaking things. Four years sounds comfortable until you realize most organizations underestimate every one of those steps. Starting now means doing this right. Starting in 2028 means doing it in a panic.

Can’t we just wait for our vendors to handle this?

Vendor updates will cover some of it, but not the encryption living in your own applications, internal systems, and custom integrations. It also doesn’t give you visibility into where your risks actually are. Vendor updates are part of the solution, not a substitute for having a plan.

What is Q-Day, and should I be worried about it?

Q-Day is the moment a quantum computer becomes powerful enough to break today’s widely used encryption. Nobody knows exactly when that day arrives, but here’s the thing: “harvest now, decrypt later” means attackers don’t have to wait for it. If your data needs to stay confidential for the next decade or more, the relevant threat is already in play.

We already have strong encryption. Isn’t that enough?

Today, yes, but that’s the whole problem. Today’s strongest encryption (RSA, ECC) is exactly what a future quantum computer would target first. “Strong by current standards” and “quantum-resistant” are two different things.

Where do we even start?

Start with your security stack and ask the question most people forget to ask: are the tools you rely on to secure your infrastructure quantum-resistant themselves? For most of the industry right now, the honest answer is no. 

Pro Tip: Cimcor's CimTrak is one of the few that already is. Communications across the platform are PQC-enabled today on NIST-approved standards, so at least one thing in your environment isn't quietly contributing to your "harvest now, decrypt later" problem. As quantum threats evolve, CimTrak's integrity monitoring gives you real-time ground truth on what's changing across your infrastructure and when. While everything else is in flux, that visibility is the thing you build from. 

Custom CimTrak Demo

Get your Customized Demo of CimTrak

Post-quantum migration starts with knowing what you have. If you're ready to take the first step, we can help.