The encryption that today protects medical records, government communications, and banking transactions relies on a mathematical problem that no computer can solve in reasonable time. This will change. The question is no longer if, but when.

On June 22, 2026, President Trump signed Executive Order 14412, which advanced the federal deadline for migration to post-quantum cryptography by five years: from 2035 to 2030. The estimated cost is $7.1 billion over ten years. This figure says something important about the nature of the problem: the American government is spending massively to defend itself against a threat that does not yet exist.

The Essentials

  • Executive Order 14412, signed on June 22, 2026, requires American federal agencies to migrate to post-quantum cryptography by 2030, five years ahead of the previous deadline.
  • The estimated cost of the transition for the American federal sector is $7.1 billion over ten years, according to the White House.
  • NIST published its first post-quantum standards in 2024 (FIPS 203, 204, 205), providing public and private organizations with technical specifications to begin migration.
  • The so-called “harvest now, decrypt later” strategy makes the threat immediate: state actors are stealing encrypted data today to decrypt it when a sufficiently powerful quantum computer becomes available.
  • Hospitals, SMEs, and countries with low or middle incomes lack the budgets and technical teams to keep pace with this timeline, creating a lasting security divide between states capable of migrating and others.

Data Stolen Today, Readable Tomorrow

To understand why Washington is moving against a machine that doesn’t exist, you must understand the logic of “harvest now, decrypt later.” Foreign intelligence services, primarily Chinese according to assessments by the NSA and the Office of the Director of National Intelligence, have been collecting massive volumes of encrypted communications for several years. Today, this data is unreadable. In ten, fifteen, or twenty years, if a sufficiently powerful quantum computer emerges, it could be decrypted retroactively.

This is the fundamental characteristic of this threat: it is asymmetric in time. A spy who steals an encrypted medical file in 2024 has nothing of value today. But that file contains information that will remain sensitive in 2040. A psychiatric treatment, a genetic disease, an addiction: these are data points whose holders will never want exposed, regardless of the decade.

The same logic applies to trade secrets, diplomatic negotiations, and signing keys for critical infrastructure. What cryptographers call the “sensitivity lifetime” of data far exceeds the probable lifetime of the algorithms that protect it. RSA-2048, the dominant standard today, was designed assuming that no classical computer could ever factor its keys in useful time. This assumption remains correct. It becomes false if you factor in a quantum computer with millions of stable physical qubits — current estimates range from 100,000 to 20 million depending on architecture, or about 4,000 error-corrected logical qubits — what the industry calls a CRQC, for “Cryptographically Relevant Quantum Computer.”

No one knows when this threshold will be crossed. Serious estimates vary between 2030 and 2040. IBM and Google publish roadmaps pointing toward the early 2030s, even the late 2020s, for useful fault-tolerant machines. IBM aims for about 200 logical qubits by 2029 — insufficient to attack RSA — and projects a complete CRQC in the 2030-2035 period. These projections carry technical assumptions about quantum error correction that engineers actively debate. This level of uncertainty is precisely what makes the migration decision difficult: you invest today against a risk whose date remains unclear.

Washington has decided: the risk of being behind exceeds the cost of migrating too soon.

What NIST Has Built Since 2016

The Executive Order does not emerge in a vacuum. It relies on eight years of technical effort. In 2016, the National Institute of Standards and Technology launched a public selection process to identify cryptographic algorithms resistant to quantum attacks. More than 80 initial applications, several rounds of analysis, an international community of cryptographers. In August 2024, NIST published its first three standards: FIPS 203 (ML-KEM, for key exchange), FIPS 204 (ML-DSA, for digital signatures), and FIPS 205 (SLH-DSA, alternative signature based on hash functions).

These standards rely on mathematical problems different from those of RSA or elliptic curve cryptography. ML-KEM and ML-DSA use Euclidean lattices, whose difficulty of resolution resists, according to current knowledge, both classical and quantum computers. The NIST process was designed to be public and reproducible: any organization, any country, can implement these standards without paying a license fee.

This is as much a political choice as a technical one. Cryptography is an infrastructure whose robustness depends on its universal adoption. A standard used by ten countries protects the world less well than a standard used by a hundred. NIST has built something analogous to what IETF does for internet protocols: open specifications, subject to international scrutiny, adoptable without friction.

The European Union is following a parallel trajectory. ENISA, the European cybersecurity agency, has published its own post-quantum migration recommendations and is preparing harmonization with NIST standards. Germany, France, and the Netherlands have launched national migration programs for their critical infrastructure. The United Kingdom published a government roadmap in 2023. This is not a race between Washington and Brussels: it is a convergence, with different paces.

$7.1 Billion to Migrate Federal Systems

The figure of $7.1 billion deserves to be broken down. It covers the migration of American federal information systems over ten years. It does not include the private sector, federated states, municipalities, or non-governmental critical infrastructure. According to Cloud Security Alliance estimates, the total cost of migration for the entire American economy could reach several additional billions when integrating the financial, medical, and telecommunications sectors.

This cost is explained by the depth of the current implementation of RSA and associated protocols. TLS, SSH, S/MIME, digital certificates, software code signatures, authentication systems: asymmetric cryptography is everywhere, often invisible, often embedded in software layers whose technical managers are themselves unaware of its presence. Migrating does not simply mean changing an algorithm in a configuration file. It requires first an inventory, then a prioritization of systems by criticality, then compatibility testing, then phased deployment with transition periods in which both systems coexist.

The NSA published its recommendations in 2022 for national security systems: migrate first-level protocols (key exchange, signatures) by 2025, complete systems by 2030. The June 2026 Executive Order aligns the rest of the federal government with this horizon. In doing so, it also sends a signal to the market: suppliers who want to sell to federal agencies will need to demonstrate post-quantum compliance. This is a mechanism for diffusion through public procurement that states regularly use to accelerate technological transitions.

Computing power is at the heart of this transition, and its relative scarcity is beginning to reshape state priorities: investing in quantum resistance also means betting on infrastructure that will have to run on 2035 machines.

Hospitals and SMEs Will Not Migrate by 2030

The American announcement raises a question that the decree does not directly address: what happens to those who cannot keep pace?

A regional French hospital, an SME subcontractor in the aerospace sector, a development bank in sub-Saharan Africa: these actors all depend on the same cryptographic infrastructure. But they do not have the budgets, information security teams, or supplier ecosystem that enable migration on schedule. The American Cybersecurity and Infrastructure Security Agency estimates that a significant portion of private sector organizations will not have migrated by 2030, due to lack of resources or awareness of the problem.

This divide will not reduce spontaneously. It reproduces a well-documented pattern in cybersecurity: large organizations and wealthy states provide themselves with the best defenses, which directs attacks toward the weakest targets. A hospital that keeps patient records under RSA in 2035 will become a prime target for anyone who then has a quantum computer or access to its computing power. Health data constitutes one of the most valuable categories on illicit markets, and its sensitivity does not decrease over time, as the debate around athlete biometrics reminds us in another context.

The question of international governance then becomes central. Should post-quantum migration be treated as a global public good, with mechanisms for technical and financial aid to less advanced countries? Or should each organization manage at its own pace, with the inequalities that entails?

The comparison with the IPv6 transition is instructive. The internet officially began migrating from IPv4 to IPv6 in the 1990s. In 2026, migration is still not complete: according to Google data, approximately 45% of global traffic still uses IPv4, but entire swaths of global infrastructure remain on the old protocol, particularly in low-income countries. Post-quantum migration presents a far greater urgency, because the issue is not a matter of addressing capacity but of irreversible data confidentiality.

What the Long Arc Reveals

Projecting the quantum threat over twenty years requires distinguishing two distinct horizons.

The first, at ten years, is that of technical transition. By 2035, several major powers will likely have access to quantum computers capable of processing real cryptographic problems. Data collected today by malicious state actors will potentially be readable. Organizations that have not migrated will be exposed. It is on this horizon that the American Executive Order acts, and this is where the competition between states is playing out right now.

The second horizon, at twenty years and beyond, is that of stabilization. If NIST standards are widely adopted and if no fundamental vulnerability is discovered in Euclidean lattice-based algorithms, the post-quantum world will resemble our current world: solid cryptographic infrastructure, regularly audited, with known review processes. This is not a prophecy; it is a cautious extrapolation based on the history of modern cryptography since the 1970s.

Between these two horizons lies a critical period: approximately 2028 to 2038, according to assumptions about the pace of quantum progress. This is the window during which data stolen today will begin to become decryptable, during which unprepared organizations will be most vulnerable, and during which international governance standards must take shape.

There is a precedent for managing this risk window. When DES, the American encryption standard of the 1970s, began showing signs of weakness in the 1990s, the international cryptographic community organized a transition to AES in a relatively orderly manner, with open standards, announced timelines, and technical support. Post-quantum migration is more complex, because the scale is larger and systems older, but the coordination mechanisms exist and function.

The fact that the NIST process took eight years and involved teams worldwide, including cryptographers whose work enabled the elimination of several failed candidates, is a positive signal about the robustness of the result. ML-KEM is not an American solution imposed on the rest of the world: it is a standard built under international scrutiny.

What 2030 Concretely Requires

The Executive Order imposes a timeline. It does not guarantee success.

For American federal agencies, the next steps are known: inventory of critical cryptographic assets, prioritization, phased deployment with annual milestones. The Cybersecurity and Infrastructure Security Agency has published detailed technical guides. The Bureau of Management and Budget will monitor agency compliance. The supervision mechanism exists.

For the rest of the world, the American 2030 horizon creates indirect but real pressure. Technology suppliers who want to maintain access to the American federal market, which represents several hundred billion dollars in annual information technology orders, will need to align their products. This concerns Microsoft, Google, Amazon Web Services, but also thousands of smaller hardware and software suppliers. Through a cascade effect, their consumer and professional products will integrate post-quantum standards, making the transition more accessible for organizations using these platforms without managing their own cryptography.

This is the mechanism that made the transition to HTTPS massive: when Google and Mozilla decided their browsers would mark HTTP sites as “not secure,” HTTPS adoption reached 95% in a few years. American public procurement could play a similar role for post-quantum cryptography.

The open question is that of coverage for the excluded. Small organizations, embedded systems, aging industrial infrastructure, countries without autonomous technical capacity: for them, neither markets nor regulation will suffice. An initiative comparable to the Green Climate Fund, oriented toward strengthening post-quantum cybersecurity capacity, remains to be built. The ITU, UIT, and organizations like the Internet Society have begun framing the terms of debate, but no concrete financing mechanism yet exists for this transition in the Global South.

Washington has made its bet. Migration will begin, the private sector will follow in part through contagion, and a persistent divide will remain between organizations that have migrated and those that cannot. Reducing this divide before the first relevant quantum computers arrive: this is the work the American decree does not open, and that no one yet really carries at the international scale.


Sources

  1. Executive Order 14412 — The Hacker News
  2. NIST FIPS 203, 204, 205 — National Institute of Standards and Technology (publications.nist.gov)
  3. NSA Cybersecurity Advisory on Post-Quantum Cryptography — National Security Agency, 2022
  4. ENISA — Post-Quantum Cryptography: Current State and Quantum Mitigation, European Cybersecurity Agency
  5. Cloud Security Alliance — Post-Quantum Cryptography Migration Challenges, 2023
  6. Google IPv6 Statistics — google.com/intl/en/ipv6/statistics.html
  7. EO 14412 – White House (primary source)
  8. Federal Register – Publication FIPS 203/204/205 (primary source)
  9. OMB/ONCD Report July 2024 – $7.1 Billion Cost (primary source)
  10. NIST CSRC – PQC Standardization Process (primary source)
  11. NSA CNSA 2.0 – Algorithms and Migration Milestones
  12. Cloud Security Alliance – Q-Day Clock Whitepaper (2026)