-0.63%
+0.13%
+0.33%
-3.92%
+2.30%
-0.22%
harvest now, decrypt laterattacks makes PQC a present-day problem, not a future one.
The Timeline Agencies Are Racing Against
The deadlines are complex and vary by system type. By January 1, 2027, all new national security system acquisitions must include PQC capabilities, covering everything from firewalls to cloud servers. The broader mandate requires PQC to be usable by 2030 to 2031 for critical federal infrastructure, and all legacy cryptography must be fully removed from environments by 2035.
The urgency comes from a specific threat model. Data encrypted today with traditional algorithms is vulnerable to future quantum computer attacks, and Orrin noted that harvest now, decrypt later
attacks are already happening. Sensitive data captured now could be decrypted the moment a sufficiently powerful quantum computer exists, which is what pushed the National Security Memorandum and related executive orders to treat this as a current risk rather than a distant one.
Intel Is Building the Fix Into Silicon
Intel has taken a long-term view, embedding PQC capabilities directly into chips across five generations. That includes algorithms like XMSS and LMS for firmware signing. Hardware takes years to develop and deploy, unlike software patches, which is why Orrin argues early integration matters more here than in most security transitions.
He also stressed that crypto agility matters as much as the algorithms themselves. Today’s PQC standards could eventually be broken too, so systems need to be built in a way that lets algorithms get swapped out without a full redesign.
The Inventory Problem Nobody Talks About
Before any agency can migrate to PQC, it has to know what it’s actually running. A standard Windows laptop can contain around 20,000 cryptographic assets, roughly 5,000 unique packages, and most organizations have no clear map of where all of that lives.
Not everything needs to migrate immediately though. Orrin explained that only cryptography an organization actually relies on for its security posture falls under the deadline. Unused legacy features like Telnet or HDCP video anti-piracy protocols don’t count. But building that distinction requires a genuine cryptographic inventory, one that extends into firmware and networked peripherals that most IT teams never think to check.
No One Is Handing Out a Certificate
The mandate has widened beyond national security systems to cover all federal agencies and the defense industrial base, including high value assets. Contractors and integrators supporting federal work now need to start their own PQC migration plans to hit the 2030 to 2031 deadlines.
There’s no shortcut to compliance either. As Orrin put it, There is no certification process, so it’s not like you’re going to get a stamp from some government agency that blesses your system.
Agencies have to meet PQC standards through their own information assurance processes, without a single body signing off.
Hashlytics Take
The deadline conversation obscures the actual bottleneck here. Nobody is struggling to pick an algorithm. They’re struggling to find out what cryptography they even have running across firmware, peripherals, and legacy systems nobody has audited in a decade. A 2027 or 2030 date is meaningless if an agency can’t produce an accurate inventory of what needs to change. Intel building PQC into silicon years ahead of the mandate is the right instinct, but it only helps organizations that know which of their systems are running that silicon in the first place.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



