Executive Order · June 2026

Securing the Nation Against Advanced Cryptographic Attacks

The White House. Signed June 22, 2026.

The executive order directing federal agencies to migrate high-value and high-impact systems to NIST post-quantum cryptography, with key establishment by December 31, 2030 and digital signatures by December 31, 2031. Agencies must name a PQC migration lead within 30 days, CISA and NIST are directed to publish the minimum elements for a cryptographic bill of materials, and a forthcoming acquisition rule will require federal contractors to meet NIST post-quantum standards by the end of 2030.

Federal Strategy · March 2026

President Trump's Cyber Strategy for America

The White House. Released March 6, 2026.

Six policy pillars guiding federal cybersecurity priorities. Pillars 3 and 5 reference post-quantum cryptography directly, naming PQC migration alongside zero-trust, cloud transition, and AI-enabled cyber tools as federal modernization priorities. The strategy is shorter and higher-level than its 2023 predecessor and does not contain PQC-specific timelines or mandates, but it places quantum risk inside national cyber strategy at the executive-branch level. Full PDF.

Federal Statute · December 2022

Quantum Computing Cybersecurity Preparedness Act

Public Law 117-260. Enacted December 21, 2022.

The federal statute requiring agencies to inventory IT systems vulnerable to quantum decryption and prepare for migration to post-quantum cryptographic standards. Provides the statutory backdrop to the executive-branch direction in the March 2026 National Cyber Strategy and to the NIST FIPS 203/204/205 standards.

Federal Standard · August 2024

NIST FIPS 203, 204, 205

National Institute of Standards and Technology

The official U.S. post-quantum cryptography standards. FIPS 203 (ML-KEM) covers key encapsulation. FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) cover digital signatures. These are the algorithms enterprises must migrate to.

Federal Mandate

NSA Commercial National Security Algorithm Suite 2.0

National Security Agency

The NSA's suite of cryptographic algorithms approved for protecting U.S. National Security Systems. CNSA 2.0 mandates the transition to quantum-resistant algorithms with specific timeline expectations for federal systems and contractors.

SEC · Rule 33-11216 · July 2023

Cybersecurity Risk Management Disclosure

U.S. Securities and Exchange Commission

The disclosure framework that increasingly shapes how public companies are expected to communicate cybersecurity risk, including, by implication, foreseeable cryptographic transition risk.

ANSSI · France · 2022, follow-up 2023

ANSSI Views on the Post-Quantum Cryptography Transition

Agence nationale de la sécurité des systèmes d'information, the French national cybersecurity agency.

France's official position on post-quantum migration. It sets out a three-phase transition roadmap and a strong recommendation for hybrid schemes that pair classical and post-quantum algorithms during the transition. Evidence that the shift to post-quantum cryptography is a coordinated international effort, aligned in direction with the UK NCSC migration timeline and the G7 post-quantum roadmap, alongside the US standards and mandates above.

Google · March 25, 2026

Quantum Frontiers May Be Closer Than They Appear

Heather Adkins, VP Security Engineering, and Sophie Schmieg, Senior Staff Cryptography Engineer

Establishes Google's internal 2029 deadline for full post-quantum cryptography deployment. The most consequential public commitment yet from a hyperscaler, and a marker for the broader migration window.

PwC · April 13, 2026

Preparing for Q-Day: The business imperative leaders can't afford to delay

Morgan Adamski, Principal, Cyber, Data, and Tech Risk, PwC US, and Rob Joyce, Cybersecurity Senior Fellow, PwC US (former Cybersecurity Director, NSA)

A strategic primer on Q-Day urgency, the harvest-now-decrypt-later threat, the NIST PQC standards, and a five-step practical migration plan: cryptographic asset inventory, crypto-agility, NIST alignment, hybrid pilots, and vendor engagement.

IBM Institute for Business Value · January 2026

The Enterprise in 2030: Engineered for perpetual innovation

Authored by Andy Baldwin, Neil Dhar, Ritika Gunnar, Rahul Kalia, James J. Kavanaugh, Salima Lin, and Joanne Wright. Survey of 2,000+ senior executives across 33 geographies and 23 industries, conducted with Oxford Economics in Q3–Q4 2025.

Five-prediction outlook for enterprise leaders. Prediction 5, "Quantum will cause the next seismic shift," establishes the board-governance baseline cited throughout this site: 72% of executives say security will be a board-level mandate equal to financial performance by 2030, while only 34% are actively preparing their organization to be quantum safe today. The chapter also frames the harvest-now-decrypt-later threat and calls for quantum-centric supercomputing architectures that pair classical, AI, and quantum capabilities.

Deloitte · World Economic Forum · Research

Managing the Quantum Cybersecurity Threat

Deloitte Global, in partnership with the World Economic Forum. Survey of 177 board members and senior executives across more than 30 countries.

A Deloitte and WEF white paper on quantum cybersecurity preparedness. Frames harvest-now-decrypt-later as a present-day threat and recommends crypto-agility, executive sponsorship, hybrid cryptographic solutions, and cross-industry coordination on third-party risk. Direct corroboration of the board-level governance framing.

Deloitte · WSJ Risk & Compliance Journal · April 9, 2026

Board Practices for the Year Ahead

Christine Davine and Caroline Schoenecker, Deloitte LLP. Published in the Wall Street Journal Risk & Compliance Journal.

Frames cybersecurity oversight as a whole-board responsibility rather than a committee assignment, with explicit emphasis on detection, response, and recovery alongside protection. Broader than quantum risk, but the governance frame applies directly: the board's fiduciary lens on cyber risk now extends to known, foreseeable cryptographic transition risk.

Radware · May 1, 2026

Post-Quantum Cryptography: What C-Level Leaders Must Do Now

Prakash Sinha, Technology Executive, Radware. 29 years across Cisco, Informatica, and Tandem Computers.

An industry voice from the security infrastructure side, confirming the governance framing. Sinha frames post-quantum migration as a multi-year transformation comparable in scope to cloud migration or zero-trust adoption, and treats it as a leadership accountability question rather than a purely technical one. References US, UK, and EU regulatory pressure in parallel.

Forrester · February 2026

The State of Quantum Computing, 2026

Forrester Research

Annual benchmarking of quantum technology maturity, enterprise readiness, and adoption posture across industries. Useful for peer benchmarking and gap analysis.

Delaware Court of Chancery · 1996

In re Caremark International Inc. Derivative Litigation

Caremark Int'l v. Caremark

The foundational case establishing the directors' non-delegable duty of oversight. Together with Marchand v. Barnhill (Del. 2019), it shapes the contemporary expectation of board engagement with mission-critical risk, including cryptographic infrastructure.

NACD-ISA · 2026 Cyber Risk Oversight Handbook

Board Discussion Guide on Quantum Computing

National Association of Corporate Directors and Internet Security Alliance. Fifth edition of the NACD-ISA Director's Handbook on Cyber-Risk Oversight.

Board-specific guidance on quantum risk oversight, with recommended questions for directors to put to management on PQC migration, NIST FIPS alignment, disclosure obligations, and committee-level accountability. A concrete board playbook from the most cited US corporate governance authority.

Routledge · February 2026

Quantum Ready: The Enterprise Guide to Post-Quantum Cryptographic Readiness

Walt Powell, Lead Field CISO at CDW. Member of the IEEE P1947 Quantum Cybersecurity Framework working group and the Cybersecurity Canon Committee.

A field-tested, vendor-neutral roadmap from one of the first Field CISOs. Chapter I.2 (pp. 2–4) frames the quantum threat in three business terms: revenue protection, cost control, and enterprise risk. Powell introduces the Q-Ready Framework, a five-phase approach covering cryptographic discovery, prioritization, migration, validation, and sustainment. A direct translation layer between cryptographic detail and the board's business-language frame.

Quantitative Framework

The Mosca Theorem (X + Y > Z)

Dr. Michele Mosca, Institute for Quantum Computing, University of Waterloo

The decision framework most widely used in PQC migration planning. If the years your data must remain confidential, plus the years required to migrate, exceed the years until cryptographically relevant quantum computers exist, you are already exposed. Used as the central anchor of the QuantaCyber Board Training framework.

Want the working bibliography?

Request the full citation set with primary-source links, current as of our latest board training cycle.

Request the library