The quantum security deadline just got harder to ignore

President Donald Trump shows an executive order he signed in the Oval Office of the White House on June 22, 2026 in Washington, DC. President Trump signed two orders on quantum computing.

President Donald Trump shows an executive order he signed in the Oval Office of the White House on June 22, 2026 in Washington, DC. President Trump signed two orders on quantum computing. Andrew Harnik/Getty Images

COMMENTARY | Quantum security is a national defense priority, not a future planning exercise.

Once viewed as just a research topic and future concern, quantum security is now an operational priority for the U.S. federal government. Recent executive orders from President Donald Trump, paired with a quantum defense strategy from the Department of War (DoW), reiterate the Administration’s commitment to “safeguard America’s most sensitive data, critical infrastructure and the digital economy” and lay out concrete steps for organizations to adopt post-quantum cryptography and protect their systems.

The reason is simple. Large-scale quantum computers aren’t here yet, but the risk already is. Adversaries can capture encrypted data today, store it and decrypt it later when quantum capabilities mature. This “harvest now, decrypt later” threat turns quantum from a future computing problem into a present-day cybersecurity one. And it's exactly the kind of long-tail risk that should worry anyone protecting mission-critical systems, sensitive data or long-lived corporate assets. 

Speed is of the essence

The White House’s executive order underscores this urgency by supercharging the national effort to develop a large-scale quantum computer and directing agencies to deploy quantum-enabled networks within the next five years. By driving a whole-of-government strategy that coordinates commerce, energy and intelligence capabilities, the administration has signaled that the timeline for quantum disruption is moving much faster than many realize. 

Major hardware developers like Google, IonQ, IBM and Intel have also reported material progress in recent months, with Google's Willow chip and its quantum error-correction advances chief among them. That momentum is already translating into concrete action: the NSA and the DEVCOM Army Research Office recently launched the QuantumEAGLe initiative, a collaborative program built to accelerate the domestic quantum computing ecosystem, secure critical supply chains and fast-track fault-tolerant quantum capabilities.

The Pentagon signals an urgent need to secure communications, data and command and control systems 

This cross-agency mobilization directly informs the DoW’s companion directives and it sharpens the operational stakes for national defense specifically. This is less an alarm for immediate systemic failure and more a strategic marker signaling that the runway for cryptographic adaptation has officially begun to shrink. 

Communications, data, command-and-control systems and other high-impact environments must move toward quantum-resistant cryptography on an actual timeline. Not someday. Not after the next budget cycle. Now.

The regulatory runway backs this up. NIST finalized its post-quantum cryptography standards in August 2024. CNSA 2.0 sets a January 2027 deadline for U.S. National Security systems to be PQC-compliant. And frameworks like CSF 2.0 and the EU's NIS2 are already pushing critical sectors – finance, healthcare, energy, government – toward "state-of-the-art" cryptography well ahead of that. By 2030, post-quantum readiness will be the baseline every organization is expected to meet. 

Start with visibility, not a rip-and-replace

For organizations that haven’t started their quantum journey, this can sound overwhelming. The good news: the first step isn’t ripping out every system they own; it’s building visibility. Where does the most sensitive data live? How long does it need to stay confidential? Which systems rely on cryptography that may not survive the quantum era? 

Security teams are increasingly formalizing that step with a Cryptographic Bill of Materials (CBOM): a full inventory of every algorithm, protocol, certificate and key in use. Layered on top is a Quantum Bill of Materials (QBOM), which flags which of those systems are actually exposed to quantum risk and maps the organization's quantum attack surface, so security teams know what to protect first. As organizations assess their quantum readiness, they're also asking: Which vendors are prepared for the post-quantum transition, and which are still treating it as someone else's problem?

The next step: crypto-agility 

Visibility is the foundation. What comes next is crypto-agility: infrastructure that can absorb new cryptographic standards as they emerge, rather than needing a rebuild every time one does. Many of the systems that inventory turns up – hardware-locked appliances, brittle VPNs, manually configured networks – are already difficult to manage. In the quantum era, they become harder to defend and more expensive to retrofit under deadline pressure. 

The organizations furthest ahead are addressing that in two ways. They're running classical and post-quantum encryption together rather than swapping one for the other overnight, so if a new algorithm turns out to have a flaw, the older method is still there as a backstop. And they're replacing hardware-locked, manually configured networks with software-defined ones, so the next round of standards arrives as a software update rather than another hardware refresh. 

Security isn’t the only consideration. Upgrades that slow networks down or only work in one environment won't survive real operations. The strongest post-quantum strategies pair security with performance at scale and enough flexibility to run across cloud, on-prem and air-gapped environments alike, because a defense agency and a regional bank are on the same regulatory clock but rarely share the same infrastructure.

This is the part leaders must take seriously. Waiting for a quantum computer to arrive before protecting sensitive data is like deciding to install a lock on a front door only after a burglar walks off with the TV. The damage is already done. 

Quantum readiness is the new operational baseline 

The White House and DoW announcements make it clear that quantum security is a national defense priority, not a future planning exercise. Securing this frontier is the new operational baseline. Quantum readiness starts with visibility, planning and networking infrastructure that can keep up, not waiting for the deadline to move first. 

Andrew Gault is the CEO of ZeroTier, where he leads the company’s work building secure, software-defined networking for distributed teams, enterprises and mission-critical environments. The company recently introduced ZeroTier Quantum to the market, the world’s only software-defined, end-to-end, post-quantum networking platform, designed to protect organizations of all sizes and types from the coming quantum threat.