Washington’s quantum orders put trust infrastructure on the clock

Quantum computing may eventually break today's cryptography, but it has already broken the assumption that trust can remain static.

The White House’s latest quantum actions mark a turning point. Post-quantum cryptography (PQC) has moved from research programs and standards discussions into operational planning and execution. Federal mandates rarely remain federal mandates. They become procurement requirements, supplier expectations, compliance benchmarks, and eventually market expectations across entire industries.

For years, quantum computing has been discussed in the future tense. It was framed as a breakthrough technology still sitting somewhere over the horizon, important to watch but not yet urgent enough to reshape infrastructure decisions. That waiting period is over.

The White House’s June executive orders accelerate both sides of the quantum era at once. One order pushes the country toward next-generation quantum innovation, including quantum sensing efforts targeted for 2028. The other moves the federal government more aggressively toward PQC, requiring agencies to identify migration leadership, review high-value and high-impact systems, and prepare plans to transition critical cryptographic functions in the years ahead.

We are already seeing the operational edge of this mandate. The Defense Department recently released its official PQC Strategy, establishing strict timelines for defense industrial base (DIB) compliance and moving to harden critical systems from the enterprise cloud down to the tactical edge.

The quantum risk is already operational

While these directives establish clear timelines, quantum computing is usually framed by what it may make possible. For security leaders, the harder question is what it could break.

That does not mean encryption breaks tomorrow. A cryptographically relevant quantum computer remains beyond today’s systems. But the risk window has already opened because adversaries do not need to wait. They can collect encrypted data now and attempt to decrypt it later once quantum capabilities mature.

For defense, healthcare, infrastructure, financial services, and other sectors managing sensitive data with long lifespans, “harvest now, decrypt later” is not a theoretical concern – it is a strategic planning problem.

That is why the federal government’s push toward PQC matters.

The National Institute of Standards and Technology’s initial standards, including Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) and Module-Lattice-Based Digital Signature Algorithm (ML-DSA), have moved the market from research to implementation. Federal systems are now expected to move toward migration by the end of the decade, leaving agencies only a few years to re-engineer cryptographic infrastructure at scale.

At the same time organizations are preparing for post-quantum migration, they are experiencing an explosion of machine identities across cloud workloads, application programming interfaces (APIs), connected devices, software pipelines, autonomous systems and AI agents.

Post-quantum readiness is a governance test

Post-quantum readiness is often misunderstood as an algorithm migration project. In reality, it is a trust lifecycle challenge. Organizations must discover, inventory, govern, migrate, validate and continuously manage trust across certificates, keys, software signing systems, machine identities, devices, supply chains and operational infrastructure.

The real question is whether agencies, contractors, and critical infrastructure operators can manage cryptography as a lifecycle problem, ensuring systems can adapt seamlessly as standards evolve. Today, cryptography is embedded across software updates, firmware, connected devices, hardware roots of trust, cloud workloads, machine identities, operational technology, supply chains and AI-enabled environments.

The trust problem is expanding beyond human users. Machine identities, autonomous systems, and AI agents increasingly participate in decisions and transactions that require cryptographic trust. Many of these systems were designed to operate for years or decades, which means they must remain trustworthy in a cryptographic environment that will not stay the same.

The technical realities are significant. Post-quantum algorithms can require larger keys and signatures, more compute and deeper integration work across protocols and infrastructure. In some cases, digital signatures can add tens of kilobytes to certificates, creating performance, bandwidth and storage challenges for constrained devices, embedded systems and networking protocols.

Trust must evolve continuously

Ultimately, cryptographic agility is now becoming a national resilience issue. In practice, it requires true trust lifecycle management: knowing where trust exists, understanding how it is enforced, proving that it remains valid and adapting it as standards, threats and technologies evolve.

For federal leaders, the near-term priority should be visibility. Agencies cannot migrate what they cannot see. They need accurate inventories of cryptographic assets, clear ownership of trust dependencies, migration roadmaps tied to mission risk, and evidence that systems remain trustworthy through transition.

The same principle applies to contractors, original equipment manufacturers (OEMs), suppliers and critical infrastructure operators. Organizations that wait for final deadlines before modernizing trust infrastructure will find themselves trying to retrofit agility into systems that were never designed for it.

Quantum computing may eventually break today’s cryptography, but it has already broken the assumption that trust can remain static. That’s why the White House’s quantum actions should be treated as an early warning and an opportunity – not only do they help secure post-quantum algorithms, they help build the capacity to govern trust continuously across complex digital ecosystems.

The organizations that succeed in the post-quantum era will not be those that simply deploy new algorithms. They will be the organizations that can continuously discover, govern, adapt and enforce trust across their digital ecosystems. In other words, post-quantum readiness is not just a cryptography challenge. It is a trust lifecycle management challenge.

David Sequino is co-founder and CEO of OmniTrust.

Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.

Related Stories