The quantum deadlines aren't new. The US has had a 2035 migration target, and a duty to inventory federal cryptography, since 2022. What changed in four weeks is that the target was pulled forward, given procurement teeth, and matched abroad. For the people who own cryptographic risk, the shift is subtler than a new threat: you can now be asked, at any moment, to prove where you stand. And every framework asks for the same thing first.
From a distant deadline to a pressing one
For years, post-quantum cryptography lived in the conditional tense. If a large enough quantum computer arrives, the encryption protecting the internet will need replacing. The threat itself is old news. Peter Shor showed how a quantum computer would break RSA and elliptic-curve cryptography back in 1994, and the deadlines have been on the books for a while too. The US has had a 2035 target for moving off vulnerable cryptography, and a standing requirement for agencies to inventory what they run, since 2022. What changed in the four weeks to June 22, 2026 is that the distant target became a near-term, enforceable one.
The anchor was a single day. On June 22 the US issued two quantum executive orders at once: EO 14413, to build American quantum computing, sensing, and networking, and EO 14412, to defend against the cryptographic threat that quantum computers create. The defensive order is the one security leaders should read, and it sharpens an existing mandate rather than inventing one. One order accelerates the threat, the other accelerates the defense, and the same government is now funding both sides of the race.
If you own cryptographic risk, the science matters less than the change in what is expected of you. The question is no longer whether the threat is real, or whether you have a plan to reach 2035. It is whether you can prove where you stand today, when a board, an auditor, or a regulator asks. And the first step named in nearly every one of these documents is the one it has been since 2022: know what cryptography you actually have.
The United States: deadlines pulled forward
EO 14412 keeps the 2035 destination but moves the milestones that matter much closer. Federal high-value and high-impact systems now have to convert to NIST's standards for key establishment by the end of 2030 and for digital signatures by the end of 2031, with national-security systems on their own track toward 2035. A proposed Federal Acquisition Regulation rule will extend the same expectation to contractors by 2030. The order carries no funding of its own, so its real lever is that contract: comply, or lose the business. After a 2025 order had pared back prescriptive procurement rules, this puts the teeth back. The order even sequences the two deadlines on purpose. Encryption comes first, because data harvested today can be decrypted once a machine exists, and signatures follow a year later.
The newer requirement is structural. Within 270 days, CISA and NIST have to publish the minimum elements for a cryptographic bill of materials, or CBOM, so that the cryptographic assets inside any piece of hardware or software can be assessed automatically. The duty to inventory is not itself new; agencies have had to name a migration lead and submit a prioritized inventory since the 2022 guidance from the Office of Management and Budget (OMB). What the CBOM adds is machine-readable form, and its arrival in a binding order is the signal that a structured cryptographic inventory is moving from good practice to baseline expectation.
None of it is cheap. The OMB has estimated that civilian federal agencies alone need roughly $7.1 billion between 2025 and 2035 to migrate their priority systems. Progress is uneven, with better-resourced departments ahead and smaller ones short of staff and expertise, and the hardest part is the oldest: legacy and embedded systems, among them the weapons systems the Pentagon has ordered off legacy algorithms by 2030.
Europe: certification as the lever
Europe is heading the same way by a different route, and its earliest hard date arrives sooner than Washington's.
France moved first and hardest. At the France Quantum conference, ANSSI said it would stop certifying security products that are not quantum-safe from 2027, with businesses expected to buy only quantum-safe products by 2030. Because ANSSI approval is required to sell into French government and critical-infrastructure markets, withdrawing it amounts to a phase-out of older encryption across the supply chain, and 2027 is the earliest product-certification cut-off among these national roadmaps. The lever is procurement rather than legislation, the same instinct now at work in Washington. The rest of the continent is close behind. The UK, Germany, the Netherlands, and the EU as a whole have all published dated roadmaps or detailed migration guidance, most clustering on 2030 for critical systems and 2035 for the rest. For regulated firms the pressure is already live rather than waiting for 2035: DORA, NIS2, and the Cyber Resilience Act are increasingly read to require crypto-agility and the monitoring of cryptographic risk, even before any of them names quantum outright.
European law is not letting signatures wait. A qualified electronic signature under eIDAS carries the legal weight of a handwritten one, and documents like deeds and wills have to stay trustworthy for decades, with no chance for the signer to sign again later. Once the signature algorithm becomes forgeable, an attacker can manufacture a record that looks as though you validly signed it years ago. At the same conference, the firm QPerfect warned that ECDSA, the elliptic-curve signature standard that Bitcoin and Ethereum rely on, could be among the first schemes to fall. For long-lived signed records, then, the part treated as less urgent is the part you can never undo.
Coordination is happening above the national level, too. Under France's G7 presidency, the group's cybersecurity working group published a joint statement on PQC migration, aimed squarely at the technical leaders of medium and large enterprises, the people who will actually have to do the work.
The same first move, everywhere
The pattern is not confined to the Atlantic. The UAE has launched a national crypto-discovery tool to inventory embedded cryptography across the country and feed a central readiness index, a whole national program built on discovery first. China runs both sides on one platform, offering quantum computing services alongside post-quantum defenses in what it openly calls a “spear-and-shield” model. Different systems, same opening move: find out what you have.
That is the thread under all of it. These mandates describe a gap many organizations already feel: clear ownership of cryptographic risk, but no structured view of where vulnerable cryptography actually sits. The "inventory" most teams hold is some combination of CMDB entries, certificate spreadsheets, and institutional memory, which works until an auditor asks for evidence and it has to be rebuilt by hand. The numbers bear that out. In a 2025 survey commissioned by DigiCert, 69% of organizations said they recognized the quantum risk, yet only 5% had deployed any quantum-safe encryption. That the duty has existed for years and most still cannot answer the question on demand is the real point. As NIST's Bill Newhouse has observed, no cryptographic migration is ever truly finished; scan a mature network and you will still find long-deprecated algorithms in use. What survives the auditor's question is a baseline you can run again, not one you assemble once.
There will be no starting gun
The timing is the uncomfortable part, and we have set out our own view of it separately. As we argued in Quantum's Hard Takeoff, quantum risk is not driven by qubit counts alone. Progress in hardware, error correction, and cryptanalysis compounds, so the curve can bend sharply instead of climbing on a gentle, predictable schedule. For a defender, the moment that counts most is invisible by design, because an adversary quietly decrypting harvested data has no reason to announce it, and the sharper the takeoff, the less warning anyone gets. A public milestone will not help either. Many who track the field argue that by the time a quantum computer openly out-factors classical methods, the gap to a cryptographically relevant machine is a few years, not a comfortable decade. On harvest-now-decrypt-later logic, waiting for a public signal is already waiting too long.
What it asks of you now
June 2026 changed the question for everyone who carries cryptographic accountability. It is no longer "is the threat real" but "can you show, on demand, where you stand, without commissioning a fresh assessment every time someone asks." The deadlines are external now, the procurement gates are closing, and the first thing everyone wants to see is an inventory. Four moves follow from that.
Inventory and prioritize. It needs to be human- and machine-readable. Map the cryptography across your estate (cloud, on-premises, hybrid, and the edge) into a standards-based CBOM you can hand to a board or auditor and run again later. Do not wait for it to be exhaustive; a full inventory can take a procurement cycle to assemble and be stale by the time it is finished, so begin with the systems that are most exposed and longest-lived. A working test: if you cannot say which systems rely on RSA or ECDSA, and roughly when each becomes vulnerable, in minutes rather than weeks, you are behind.
Treat the procurement gate as your real deadline. For most organizations the binding date is not 2035. It is the nearest certification or contracting cut-off, ANSSI's in 2027 and the FAR rule's in 2030, and, if you are regulated, the crypto-agility expectations increasingly read into DORA, NIS2, and the Cyber Resilience Act. Any security product you buy for delivery in 2027 or later should specify post-quantum capability now.
Push the requirement into your supply chain. Most of your cryptographic exposure sits in software and hardware you did not build. Ask vendors for a CBOM and a migration roadmap in writing, and treat legacy equipment that cannot produce one as a risk-acceptance or replacement decision rather than a blind spot.
Re-rank your long-lived signed records. For deeds, wills, qualified e-signatures, notarial and land-registry records, and the code- and firmware-signing roots that sit beneath everything else, plan for a conservative, hash-based signature scheme such as SLH-DSA (FIPS 205) or the stateful LMS and XMSS, together with long-term preservation and quantum-safe timestamps. What should trigger action is how long the record must stay trustworthy, not anyone's guess at Q-day.
Terra Quantum's Post-Quantum Readiness Program is built for exactly that: automated discovery that produces a centralized, standards-traceable cryptographic inventory and a structured CBOM export, so the evidence is something you hold rather than something you rebuild each time the question comes around.