ACE Rebrand Update: The Alliance for Citizen Engagement is now the Alliance for Civic Engagement.

The Modern Y2K? The Shift to Post-Quantum Cryptography and Implications for Data Security

The Modern Y2K? The Shift to Post-Quantum Cryptography and Implications for Data Security
Editors: Francis Rogai

Key Takeaways

  • Quantum computers capable of breaking today’s RSA encryption do not yet exist, but the “harvest now, decrypt later” (HNDL) threat means adversaries can steal and store encrypted data today to decrypt once quantum computing matures.
  • The National Institute of Standards and Technology (NIST) finalized the first official post-quantum cryptography (PQC) standards in August 2024, giving federal agencies a vetted framework to begin migrating away from RSA encryption.
  • Migration is slow and expensive because encryption is embedded in hardware and legacy systems that can take 5–15+ years to replace. This creates concerns that under-resourced agencies will be left behind.
  • Experts are divided on the urgency of PQC. Some argue that HNDL operations are already underway (e.g. China’s Volt Typhoon), while others warn that rushing unproven standards could trade one security risk for another.

Why Today’s Encryption May Not Be Enough

Every time you send a text message, log into a bank account, or access a government website, encryption is working in the background to keep that information private and ensure that it isn’t stolen. The most widely used form of encryption today is called classical encryption, or RSA, which works by presenting a math problem so unbelievably difficult that no existing computer can solve it in a reasonable amount of time. Now, quantum computing threatens to change that.

Unlike traditional computers, which process information in binary (0s and 1s), quantum computers exploit the laws of quantum physics to perform certain calculations exponentially faster. A sufficiently powerful quantum computer, often called a cryptographically relevant quantum computer (CRQC), could potentially break the RSA encryption that keeps all our data safe. This would expose everything it currently protects, from financial records to personal health data and military communications.

Post-quantum cryptography (PQC) refers to new encryption methods designed to withstand attacks from quantum computers, ensuring all user data remains private. In August 2024, the National Institute of Standards and Technology (NIST) finalized the first official PQC standards, giving the government a vetted framework to begin transitioning away from RSA and requiring that federal systems take steps towards compliance. NIST’s standards release started a one-year clock for the U.S. Office of Management and Budget (OMB) to issue future migration guidance for agencies.

Should We Be Worried?

One of the most urgent reasons for action is a practice called “harvest now and decrypt later” (HNDL), by which national adversaries intercept and store encrypted data so they can decrypt it once a CRQC becomes available. Because some sensitive data including intelligence reports, financial records and classified communications must remain confidential for decades, its theft creates a risk even in the absence of a quantum computer able to crack encryption. China’s Volt Typhoon campaign is a recent example. Though the People’s Republic of China does not have access to a CRQC, the years-long access to American critical infrastructure networks which allowed them to collect sensitive data constitutes a significant security breach.

Opinions remain varied on the efficacy of PQC and how much of a priority its implementation should be. Some experts disagree on whether NIST’s newer quantum-resistant algorithms would truly hold up against a real quantum computer, expressing skepticism that quantum computing has enough practical applications to push the field beyond its foundational research stage. The cybersecurity industry is also divided on the timeline for true quantum supremacy. Providers worry that treating uncertain future threats as imminent worries can drive poor policy and the misallocation of funds, leaving other cyber security priorities underfunded.

How Urgent Is Urgent? The Debate Over Migration Speed

Migration is harder and more expensive than it looks. Most encryption is baked into physical devices–power grid sensors, medical equipment, factory machinery–that were built to last 10 to 20 years and cannot be reprogrammed. Replacing these devices means replacing their hardware entirely, a process which can take anywhere from 5 years for a small organization to over 15 years for a large one. 

Additionally, switching to new cryptographic methods before they are fully field-tested introduces a different kind of vulnerability. In many organizations, encryption is embedded across enterprise infrastructure and the inventory of where vulnerable systems exist is often incomplete. Small organizations often lack the leverage to accelerate vendor timelines and may face expensive rewrites for custom applications if they proceed without the vendor’s support. Federal agencies face similar difficulties. Their systems vary enormously in size, age, and technical capacity, and migration for a large agency takes three to five years under favorable conditions. Without centralized coordination and funding, PQC migration risks limiting agencies’ effectiveness based on the funding they already possess. A 2022 Deloitte survey found that while over 50% of respondents believed their organization was at risk from HNDL attacks, only 26.6% had completed a quantum risk assessment. This illustrates the gap between recognized risk and actual preparation: well-resourced agencies will upgrade while smaller ones lag behind, leaving exploitable gaps.

Looking Ahead

Members of government, industry, and the security research community all agree that PQC migration must happen. The active debate surrounding the issue is not about whether to act. Rather, it is about how fast, at what cost, and how to ensure that under-resourced agencies and organizations are not left behind. Decisions about which systems to prioritize, how to fund migration efforts, and how to coordinate these efforts across federal agencies will determine whether the government is protected before a cryptographically relevant quantum computer exists or scrambling to catch up after one does.

Frequently Asked Questions

Post-quantum cryptography refers to cryptographic algorithms designed to be secure against attacks from both classical and quantum computers. Unlike current RSA encryption, which relies on the difficulty of factoring large numbers, PQC algorithms are based on different mathematical problems believed to be resistant to quantum attacks. In August 2024, NIST finalized the first official PQC standards for federal use.

HNDL is a strategy where adversaries intercept and store encrypted data so they can decrypt it once sufficiently powerful quantum computers become available. This makes the threat active even before a cryptographically relevant quantum computer (CRQC) exists. Sensitive data that must remain confidential for decades is already at risk of future exposure if stolen now.

The National Institute of Standards and Technology (NIST) is the federal agency responsible for developing and publishing cryptographic standards. After a multi-year evaluation process, NIST finalized the first official PQC standards in August 2024, providing a vetted framework for federal agencies to begin transitioning away from RSA. These standards are mandatory for federal systems, and their release triggered a one-year deadline for the U.S. Office of Management and Budget (OMB) to issue government-wide migration guidance.

[pvc_stats postid="" increase="1" show_views_today="0"]

Share this post

Related Briefs

Give feedback on this brief:

Free to read. Funded by people like you. Support the Fellows making it possible.