Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogSecurity Leadership
The Quantum Clock Is Ticking: What Your Board Needs to Decide Before 2027

The Quantum Clock Is Ticking: What Your Board Needs to Decide Before 2027

Quantum threats aren't future risks—adversaries are harvesting your encrypted data today. Here's what your board must decide before 2027 to protect critical assets.

September 3, 202611 min readBy Adil Karam

Your board already knows the word "quantum." What most boards do not know is that the threat is not arriving in the future. It arrived quietly, years ago, the moment adversaries began intercepting and archiving your encrypted traffic with patient certainty that they will eventually own the keys. That moment is not hypothetical. It is already priced into the operational planning of nation-state intelligence services. The only question your board must answer is whether your organization will still be holding quantum-vulnerable encryption when the decryption bill comes due.

Q-Day estimates cluster around 2029 to 2033, but enterprise PQC migration takes two to five years.

That math is unforgiving. If your organization begins planning in 2027, the technical runway to complete a full cryptographic migration before the earliest credible quantum threat window closes is functionally gone. Boards that wait for certainty before acting will find that certainty arrives simultaneously with the liability.

This is not a technology refresh. It is a fiduciary decision about data that your organization holds today, encrypted with algorithms that will become breakable, protecting information whose sensitivity may span decades.

The Regulatory Clock Has Already Started

The policy environment shifted decisively in 2026, and the pressure now extends well beyond federal agencies.

On June 22, 2026, President Trump signed two executive orders to expand the use and development of quantum technology. Executive Order 14412 accelerates the adoption of post-quantum cryptography in critical federal and private sector systems to address emerging post-quantum threats.

This is not aspirational guidance.

The cybersecurity-focused executive order imposes deadlines on federal agencies to harden their information systems against quantum-enabled hacking and calls for a new procurement clause that will require federal contractors to comply with post-quantum cryptography standards by December 31, 2030.

The Administration has established aggressive timelines: each agency must designate a PQC migration lead within 30 days, OMB must issue guidance requiring agencies to review HVA inventories and develop PQC transition plans within 90 days, and NIST must initiate a PQC migration pilot project with completion by December 31, 2027.

For private sector organizations, the implications extend through the supply chain.

The order requires agencies to transition "high value assets" and "high impact systems" to post-quantum cryptographic keys by December 31, 2030, and PQC digital signatures by the end of 2031. Under the Biden administration, agencies had generally been planning to shift to the new algorithms by 2035.

That five-year compression of the federal timeline cascades directly into vendor risk assessments, procurement requirements, and contract eligibility for any organization that touches government data.

Simultaneously,

FIPS 140-2 modules moved to Historical status by NIST CMVP on September 21, 2026, meaning federal procurement now requires FIPS 140-3 validated modules, and the FIPS 140-3 validation backlog averages over 500 days.

Organizations that have not begun module validation planning are already behind the queue.

On the standards side, the technical foundation is settled.

FIPS 203, 204, and 205 are final standards. FIPS 203 specifies ML-KEM for key establishment. FIPS 204 specifies ML-DSA for digital signatures. FIPS 205 specifies SLH-DSA as a hash-based signature standard.

The algorithms are not in debate. The migration is.

The Harvest-Now, Decrypt-Later Briefing Your Board Needs

The Thales 2026 Quantum and AI Threat Report surveyed 3,120 security and IT professionals across 20 countries. 98% of respondents now weigh how AI and quantum computing affect each other. Harvest-now, decrypt-later (HNDL) is the top quantum concern, cited by 61% of respondents.

The mechanism is straightforward and already operational.

Adversaries are collecting encrypted data right now. They cannot read it yet. But they do not need to, because their strategy involves intercepting communications, storing them, and simply waiting. When quantum computers become powerful enough to break today's encryption, that archived data will potentially become readable. According to official warnings from the NSA, CISA, and NIST, it is already happening.

The relevant planning horizon is not when quantum computers will be built. It is how long your most sensitive data will remain valuable. If your data has a twenty-year sensitivity lifespan and quantum capability is fifteen years away, you are already behind.

Analysis of more than 100 primary sources indicates that 98 to 100% of healthcare records and 95 to 100% of government-classified data encrypted today are likely to face retroactive decryption under the HNDL attack model.

For commercial organizations, the exposure categories include M&A strategy, intellectual property, pricing data, litigation records, and personnel files held under legal retention requirements.

DigiCert's 2026 Quantum Readiness Outlook found that 85% of IT and security leaders believe quantum computing will break today's encryption standards within a decade, yet only 7% have deployed quantum-safe certificates at scale.

That gap between belief and action is exactly where your board's accountability question lives.

Three papers published between May 2025 and March 2026 reduced the estimated quantum resources needed to break RSA-2048 from 20 million qubits to fewer than 1 million. A February 2026 study described a new fault-tolerant architecture factoring RSA-2048 with fewer than 100,000 physical qubits, an order of magnitude below previous estimates.

The technical barrier to Q-Day is shrinking faster than enterprise migration programs are advancing.

Where Organizations Actually Stand: A Readiness Comparison

According to industry surveys and reports from consulting firms, most large enterprises are in Phase 1 (Discovery) or Phase 2 (Planning) as of early 2026. Some early adopters in finance and government are in Phase 3 (Hybrid deployment). No major organization has publicly claimed to be in Phase 4 (Full migration).

The table below frames the four postures boards are likely to encounter when asking their CISO "where do we stand?":

Readiness PostureCryptographic InventoryMigration RoadmapRegulatory ExposureBoard Accountability Status
ReactiveNoneNoneHigh (FIPS 140-3, EO 14412)Unquantified liability
AwarePartial, manualConceptual onlyModerate to HighCannot attest readiness to auditors
PlanningAutomated discovery underwayPhased roadmap draftedModerateCan report progress, not posture
TransitioningComplete, maintainedActive hybrid deploymentLowBoard-reportable with metrics

Most organizations reading this post are in the "Aware" row. The honest answer to a board that asks "how are we thinking about post-quantum transition?" cannot come from that posture.

Framework Alignment: What Governance Looks Like in Practice

Three established frameworks provide the structural scaffolding for a defensible PQC governance posture.

NIST's Post-Quantum Cryptography resources define the algorithm standards and provide migration guidance that maps directly to NIST CSF 2.0's Identify and Protect functions. A cryptographic inventory is a CSF Identify function activity. Hybrid PQC deployment maps to Protect. Neither is optional under the current regulatory environment.

CISA's Post-Quantum Cryptography Initiative establishes the operational expectations for critical infrastructure organizations, including automated cryptographic discovery and inventory tooling.

Although quantum computing technology capable of breaking modern public-key encryption does not yet exist, government agencies and critical infrastructure entities, including both public and private sector organizations, must begin preparing now.

ISO 27001:2022 Annex A control A.8.24 (Use of Cryptography) now requires documented cryptographic policies and key management procedures. An organization that cannot produce a cryptographic inventory cannot demonstrate conformance with this control under audit. CIS Control 3 (Data Protection) and CIS Control 16 (Application Software Security) both require cryptographic algorithm governance that most organizations have not formally documented.

Agencies must establish or update an internal governance structure to oversee PQC migration. This migration is not only the responsibility of the agency-level CIO and CISO. Successful migration requires accountability and responsibility for each member of an agency's leadership team, both in the front office and in agency components.

That governance model applies equally to private sector boards.

Cryptographic Agility as a Procurement Requirement

Organizations in financial services, healthcare, and critical infrastructure are beginning to embed cryptographic agility requirements into vendor assessments.

Establishing cryptographic agility principles in development standards ensures new systems are built to support algorithm replacement without major refactoring.

Within 18 months, RFPs in regulated industries will routinely require vendors to attest to PQC migration status. Organizations without a documented posture will face procurement disqualification before regulatory deadlines arrive.

The Cyber Insurance Reckoning

Underwriters are developing quantum exposure questionnaires modeled on the same pattern as ransomware readiness questions circa 2019. Organizations that cannot answer "have you completed a cryptographic inventory?" will face exclusions or premium surcharges on data breach coverage. The absence of a cryptographic inventory is the new absence of MFA: a clear signal of unmanaged, known risk.

The Defense Industrial Base as the First Mover Forcing Function

Any global vendor selling into the US defense or intelligence supply chain effectively has a 2026 to 2027 readiness deadline.

The NSA's CNSA 2.0 guidance requires new National Security System acquisitions to support ML-KEM-1024 and ML-DSA-87 starting January 1, 2027. That requirement will flow to second and third-tier suppliers through contract clauses, not public announcements.

The Intersection of AI and Quantum Risk

98% of respondents now weigh how AI and quantum computing affect each other, as both are converging on one target: enterprise data.

AI systems that process sensitive data often rely on encrypted model weights, API communications, and training datasets. Those assets carry the same HNDL exposure as any other encrypted enterprise data and require the same cryptographic inventory and migration planning.

Board-Level PQC Readiness Checklist

This checklist is designed for the conversation between a board member and their CISO. Every "No" or "Unknown" is a material gap requiring a remediation timeline.

Cryptographic Inventory

  • [ ] Has the organization completed an automated cryptographic discovery across all environments (cloud, on-premises, SaaS, OT)?
  • [ ] Are all uses of RSA, ECDH, ECDSA, Diffie-Hellman, and DSA identified and catalogued?
  • [ ] Is the inventory mapped to data sensitivity classifications and regulatory retention requirements?
  • Regulatory Posture

  • [ ] Has the organization assessed its obligations under EO 14412 as a federal contractor or critical infrastructure operator?
  • [ ] Does the organization have FIPS 140-3 validated modules in its procurement pipeline?
  • [ ] Has the organization's legal team assessed HNDL exposure against current data retention policies?
  • Migration Planning

  • [ ] Is there a board-approved PQC migration roadmap with phased milestones through 2030?
  • [ ] Has the organization designated a PQC migration lead with defined accountability to the CISO?
  • [ ] Are vendor contracts being updated to require PQC compliance attestation?
  • Governance and Reporting

  • [ ] Can the CISO present quantum risk in financial terms (potential exposure value, not just technical severity)?
  • [ ] Is PQC readiness included in the annual board cybersecurity report?
  • [ ] Has the board received a formal HNDL threat briefing framed against the organization's specific data categories?
  • A study published in Computers (MDPI) estimated realistic migration timelines of five to seven years for small enterprises, eight to twelve years for medium enterprises, and twelve to fifteen or more years for large enterprises.

    If your checklist has more than three "No" responses, your organization's migration timeline and your regulatory deadline are already in conflict. The NIST Post-Quantum Cryptography FAQ provides additional technical context for communicating these gaps to non-technical stakeholders.

    How I Help

    My Board Advisory work exists precisely for this conversation. I translate PQC risk into the financial and governance terms that boards can act on: quantified HNDL exposure mapped to your specific data categories, Caremark-aligned governance documentation, and board-ready reporting that converts cryptographic complexity into material risk disclosures. I have built this presentation for boards across financial services, healthcare, and defense contracting sectors, and I know how to get a room of non-technical directors to a decision in a single session.

    For organizations that need the architectural foundation to support that board conversation, my Security Architecture practice builds the cryptographic inventory and migration roadmap that makes your board report defensible. My Compliance work addresses the FIPS 140-3 transition, EO 14412 contractor obligations, and ISO 27001 cryptographic control alignment. For organizations managing AI infrastructure alongside PQC exposure, Secure AI Deployment addresses the intersection of model security and quantum-vulnerable encryption. And for organizations that need ongoing executive security leadership without a full-time hire, my vCISO engagement provides the sustained oversight that a one-time assessment cannot.

    See if I should be in the room

    #Quantum Computing#Post-Quantum Cryptography#Board Governance#Cybersecurity Strategy#Harvest Now Decrypt Later#CISO Leadership
    PDFShare:

    Adil Karam

    Security & AI Governance Advisor

    Helping organizations navigate security leadership and AI governance challenges.

    Ready to Put These Insights Into Action?

    Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.