Every position we take with a board or executive team is grounded in officially stamped sources. This is the working library.
The executive order directing federal agencies to migrate high-value and high-impact systems to NIST post-quantum cryptography, with key establishment by December 31, 2030 and digital signatures by December 31, 2031. Agencies must name a PQC migration lead within 30 days, CISA and NIST are directed to publish the minimum elements for a cryptographic bill of materials, and a forthcoming acquisition rule will require federal contractors to meet NIST post-quantum standards by the end of 2030.
Six policy pillars guiding federal cybersecurity priorities. Pillars 3 and 5 reference post-quantum cryptography directly, naming PQC migration alongside zero-trust, cloud transition, and AI-enabled cyber tools as federal modernization priorities. The strategy is shorter and higher-level than its 2023 predecessor and does not contain PQC-specific timelines or mandates, but it places quantum risk inside national cyber strategy at the executive-branch level. Full PDF.
The federal statute requiring agencies to inventory IT systems vulnerable to quantum decryption and prepare for migration to post-quantum cryptographic standards. Provides the statutory backdrop to the executive-branch direction in the March 2026 National Cyber Strategy and to the NIST FIPS 203/204/205 standards.
The official U.S. post-quantum cryptography standards. FIPS 203 (ML-KEM) covers key encapsulation. FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) cover digital signatures. These are the algorithms enterprises must migrate to.
The NSA's suite of cryptographic algorithms approved for protecting U.S. National Security Systems. CNSA 2.0 mandates the transition to quantum-resistant algorithms with specific timeline expectations for federal systems and contractors.
The disclosure framework that increasingly shapes how public companies are expected to communicate cybersecurity risk, including, by implication, foreseeable cryptographic transition risk.
France's official position on post-quantum migration. It sets out a three-phase transition roadmap and a strong recommendation for hybrid schemes that pair classical and post-quantum algorithms during the transition. Evidence that the shift to post-quantum cryptography is a coordinated international effort, aligned in direction with the UK NCSC migration timeline and the G7 post-quantum roadmap, alongside the US standards and mandates above.
Establishes Google's internal 2029 deadline for full post-quantum cryptography deployment. The most consequential public commitment yet from a hyperscaler, and a marker for the broader migration window.
A strategic primer on Q-Day urgency, the harvest-now-decrypt-later threat, the NIST PQC standards, and a five-step practical migration plan: cryptographic asset inventory, crypto-agility, NIST alignment, hybrid pilots, and vendor engagement.
Five-prediction outlook for enterprise leaders. Prediction 5, "Quantum will cause the next seismic shift," establishes the board-governance baseline cited throughout this site: 72% of executives say security will be a board-level mandate equal to financial performance by 2030, while only 34% are actively preparing their organization to be quantum safe today. The chapter also frames the harvest-now-decrypt-later threat and calls for quantum-centric supercomputing architectures that pair classical, AI, and quantum capabilities.
A Deloitte and WEF white paper on quantum cybersecurity preparedness. Frames harvest-now-decrypt-later as a present-day threat and recommends crypto-agility, executive sponsorship, hybrid cryptographic solutions, and cross-industry coordination on third-party risk. Direct corroboration of the board-level governance framing.
Frames cybersecurity oversight as a whole-board responsibility rather than a committee assignment, with explicit emphasis on detection, response, and recovery alongside protection. Broader than quantum risk, but the governance frame applies directly: the board's fiduciary lens on cyber risk now extends to known, foreseeable cryptographic transition risk.
An industry voice from the security infrastructure side, confirming the governance framing. Sinha frames post-quantum migration as a multi-year transformation comparable in scope to cloud migration or zero-trust adoption, and treats it as a leadership accountability question rather than a purely technical one. References US, UK, and EU regulatory pressure in parallel.
Annual benchmarking of quantum technology maturity, enterprise readiness, and adoption posture across industries. Useful for peer benchmarking and gap analysis.
The foundational case establishing the directors' non-delegable duty of oversight. Together with Marchand v. Barnhill (Del. 2019), it shapes the contemporary expectation of board engagement with mission-critical risk, including cryptographic infrastructure.
Board-specific guidance on quantum risk oversight, with recommended questions for directors to put to management on PQC migration, NIST FIPS alignment, disclosure obligations, and committee-level accountability. A concrete board playbook from the most cited US corporate governance authority.
A field-tested, vendor-neutral roadmap from one of the first Field CISOs. Chapter I.2 (pp. 2–4) frames the quantum threat in three business terms: revenue protection, cost control, and enterprise risk. Powell introduces the Q-Ready Framework, a five-phase approach covering cryptographic discovery, prioritization, migration, validation, and sustainment. A direct translation layer between cryptographic detail and the board's business-language frame.
The decision framework most widely used in PQC migration planning. If the years your data must remain confidential, plus the years required to migrate, exceed the years until cryptographically relevant quantum computers exist, you are already exposed. Used as the central anchor of the QuantaCyber Board Training framework.
Request the full citation set with primary-source links, current as of our latest board training cycle.
Request the library