Presented by Arqit & Carahsoft
Government agencies are preparing for a future in which sufficiently powerful quantum computers could break many of today’s encryption methods. Nick Nilan, General Manager, US at Arqit, says agencies should begin the transition to post-quantum cryptography before that capability arrives.
The Quantum Threat Is Already Here
Quantum computers capable of defeating widely used public-key encryption may still be years away, but the cybersecurity risks associated with them are already taking shape. Adversaries do not need to possess a cryptographically relevant quantum computer today to begin exploiting the opportunity it may create.
They can collect encrypted information now and retain it until technology advances enough to decrypt it. This strategy, commonly called “harvest now, decrypt later,” places sensitive information with a long operational lifespan at particular risk. Classified data, intelligence, research, intellectual property and personal information gathered today could remain valuable well into the future.
“The longer we put off moving to PQC, the longer we have exposure, because our adversaries are in our networks today,” Nilan says. “We know that they’re stealing our data today.”
For government agencies, that makes post-quantum cybersecurity a current data-protection issue rather than a distant technology concern. If migration is delayed until 2030, 2035 or 2040, the data created between now and then could remain vulnerable to future decryption.
Looking Beyond “Harvest Now, Decrypt Later”
Confidentiality is only one part of the post-quantum challenge. Digital signatures, certificates and other cryptographic mechanisms also help government systems verify identities, authenticate devices and establish trust.
“The other piece that we don’t talk about too often is ‘trust now, forge later,’” Nilan says.
An adversary with the ability to break existing cryptography may eventually be able to imitate a trusted user, system or device by forging the credentials used to verify it. That possibility has significant implications for zero trust. Agencies increasingly make access decisions based on identity, device status and continuously evaluated risk. If the cryptography supporting those decisions becomes vulnerable, the integrity of the broader security architecture could also be affected.
“Encryption doesn’t just protect our data from decryption. It also protects our authentication,” Nilan explains. Without post-quantum protections, an adversary could potentially forge certificates and gain access while appearing to be a legitimate user or system.
Post-quantum planning must therefore extend beyond protecting stored information. Agencies also need to examine the cryptographic foundations behind authentication, software updates, machine-to-machine communications and other trusted digital interactions.
The challenge becomes even more important as government adopts artificial intelligence, autonomous systems and connected operational technologies. These environments may rely on enormous numbers of interactions between human and nonhuman identities. Every interaction requires confidence that the person, device or software agent is legitimate.
Building a Cryptographic Inventory
The scale of the transition makes discovery one of the most important—and potentially most difficult—parts of the process.
“First and foremost, it’s awareness of what’s the challenge, and then within awareness, it’s: Where is my cryptography today?” Nilan says. “Cryptography exists across your enterprise.”
An agency may rely on cryptography incorporated into decades of infrastructure, including systems supplied and maintained by outside vendors. Some uses will be easy to identify, while others may be buried within applications, firmware, hardware or third-party services.
Nilan recommends using automated discovery tools to identify existing cryptography and determine whether it is secure against both current and future attacks. Agencies can then map that information against their broader IT and operational technology inventories and prioritize the high-value assets that present the greatest mission risk.
The inventory should identify which algorithms, certificates, keys and protocols are in use, what information or function they protect and how difficult each implementation will be to replace.
This visibility allows leaders to distinguish between systems that require immediate attention and those that can transition through routine modernization. It also helps acquisition teams ask vendors more precise questions about their post-quantum roadmaps, product dependencies and upgrade requirements.
Without that foundation, agencies risk discovering vulnerable dependencies only after standards, mandates or operational threats force a rapid migration.
Designing for Crypto Agility
Moving to post-quantum cryptography should not be treated as a one-time replacement project. Algorithms will continue to evolve, and future discoveries could expose weaknesses in technologies considered secure today.
Agencies therefore need crypto agility: the ability to replace or update cryptographic methods without rebuilding entire systems.
Nilan compares this preparation to developing primary, alternate, contingency and emergency plans. If certificates are forged, networks become unavailable or an encryption method is compromised, agencies should have another way to protect their systems and continue the mission.
“When we first think about crypto agile, we think of making sure that I can complete my mission and I don’t need to turn off the encryption to do so,” he says.
Software-defined approaches can help organizations separate encryption from the underlying infrastructure and make changes more quickly as standards and threats evolve. This flexibility can reduce reliance on lengthy hardware replacement cycles and make it easier to adapt protections across complex government environments.
“We’re going to have another migration in the future,” Nilan says. “How do we make sure that the work that we do today gets us to a point where the next migration is even easier?”
Software-defined encryption can provide part of that answer. When cryptography can be updated through software, agencies have greater flexibility to adopt new algorithms and respond to newly discovered risks. As Nilan explains, “If all encryption or cryptography is software, then I can move agile—and that’s where we get the word crypto agile.”
Quantum computing may ultimately produce significant benefits for government, science and national security. But agencies cannot wait for those capabilities to mature before addressing the cybersecurity consequences. Organizations that begin discovering their cryptographic dependencies and building agility now will be better positioned to protect data, preserve digital trust and adapt as the post-quantum era approaches.
Key Takeaways
- Agencies should inventory algorithms, certificates, keys and protocols across IT systems, operational technology and supply chains before beginning their post-quantum migration.
- Delaying action increases exposure to both “harvest now, decrypt later” and “trust now, forge later” threats.
- Crypto agility and software-defined encryption can help agencies adopt post-quantum protections while making future cryptographic migrations faster and less disruptive.
