The race to prepare for quantum computing has a timing problem: Nobody knows exactly when a cryptographically relevant quantum computer will arrive.

But at the Intelligence and National Security Alliance’s 2026 Intelligence & National Security Summit, panelists had a clear message for government agencies, national security organizations, and their industry partners: that uncertainty is not a reason to wait.

During the “Quantum-Ready: Navigating the 2027 Mandate for National Security” session, experts from government, academia, think tanks, and industry focused less on predicting a specific quantum breakthrough and more on what organizations should be doing now to protect sensitive information, modernize cryptography, and prepare their systems for a rapidly changing technology environment. The panel included representatives from the White House Office of the National Cyber Director, CISA, the University of Maryland, CNAS, and SandboxAQ.

The standing-room-only session also underscored how much attention quantum readiness is getting across the national security community.

Stop Waiting for ‘Q-Day’

Much of the quantum cybersecurity conversation has revolved around “Q-Day,” the theoretical point when quantum computers become powerful enough to break widely used public-key cryptography.

Patrick Manley, CISA’s Lead for Quantum Security, argued that organizations may be better served by worrying less about predicting that date and more about becoming ready for it.

“I kind of want to get out of the prediction business,” Manley said.

The reason is simple: organizations already have migration targets to meet, while technological advances could change predictions about the quantum timeline. Manley also pointed to the convergence of artificial intelligence and quantum computing as an additional source of uncertainty. AI could potentially accelerate research, identify weaknesses, optimize quantum architectures, or help develop more efficient algorithms.

That makes crypto agility, the ability to replace cryptographic algorithms as threats and standards evolve, particularly important.

“Start now, be agile,” Manley said.

That theme ran throughout the discussion. The goal isn’t simply to install post-quantum cryptography (PQC), check a compliance box, and declare the problem solved. Organizations need the ability to keep adapting.

Know What You Have Before You Try to Protect It

If there was one practical starting point repeated throughout the session, it was inventory.

Organizations need visibility into where cryptography exists across their systems before they can determine what needs to be migrated first. Kathryn Wang, principal for the public sector at SandboxAQ, described inventory as one of the core priorities emerging from government guidance.

From there, organizations can prioritize based on mission importance, the sensitivity and lifespan of their data, and the vulnerability of the systems protecting it.

Will Loucks, senior director for intelligence at the White House Office of the National Cyber Director, emphasized taking that risk-based approach.

That matters because not every piece of information carries the same quantum risk. Data that loses its value in a matter of weeks is different from intelligence that could remain sensitive for decades.

It is also why “harvest now, decrypt later” remains such a concern. An adversary doesn’t necessarily need a capable quantum computer today. It can potentially collect encrypted information now with the expectation of decrypting it when the technology becomes available.

But Manley warned that confidentiality is only part of the problem.

“The authentication piece, to me, is very significant,” he said.

Compromising roots of trust, certificate authorities, code signing, firmware signing, or other pieces of an organization’s trust infrastructure could allow an adversary to masquerade as a trusted entity. That threat deserves more attention alongside the better-known risk of stolen encrypted data.

Don’t Buy Tomorrow’s Legacy Technology Today

The discussion also carried an important message for government contractors and technology vendors.

Government customers increasingly want to understand how the products they purchase today will transition to post-quantum cryptography tomorrow.

“What do we want from industry?” Manley asked. “I think from a government perspective, we want to see a clear path and a roadmap on how you’re getting to PQC-capable products.”

That means contractors should be prepared to explain their migration plans, certification paths, cryptographic dependencies, and ability to update products as standards evolve.

Wang distilled the acquisition challenge into an especially memorable line:

“Let’s not buy tomorrow’s legacy today.”

New contracts and technology purchases should not continually add systems that will have to be ripped out or extensively modified in just a few years. The supply chain, she noted, is part of the broader risk picture.

Quantum Readiness Is Also a Budget Problem

Technology may be at the center of the quantum conversation, but organizations won’t migrate without money, people, and leadership.

Manley said leaders should be asking whether they know their most critical systems, understand where cryptography resides, know what replacing it will require, and, importantly, have actually budgeted for the work.

“If you aren’t connecting a cost estimate to move to PQC for your most critical system into your resource allocation funding, you’re wrong,” he said.

That may be one of the most immediate takeaways for federal leaders and contractors alike. Quantum readiness cannot remain exclusively with cybersecurity teams. CIOs, acquisition officials, mission owners, vendors, CFOs, and other stakeholders all have a role.

The challenge isn’t predicting the precise moment quantum computing changes cybersecurity. It is making sure organizations aren’t caught flat-footed when it does.

The panel’s advice was remarkably consistent: inventory your systems, prioritize according to risk, build a migration roadmap, put resources behind it, and make crypto agility part of long-term modernization.

Or, as Manley put it, organizations need to “start now, be agile.”

Because waiting until the quantum threat fully materializes may mean waiting until the easiest opportunity to prepare has already passed.

Related News

Jillian Hamilton has worked in a variety of Program Management roles for multiple Federal Government contractors. She has helped manage projects in training and IT. She received her Bachelors degree in Business with an emphasis in Marketing from Penn State University and her MBA from the University of Phoenix.