In August 2024, the National Institute of Standards and Technology published three federal standards for post-quantum cryptography: FIPS 203, FIPS 204, and FIPS 205. These standards establish algorithms designed to resist attacks from quantum computers, which could break today's widely used encryption methods. Federal agencies must begin transitioning to these standards, and organizations that handle federal data—contractors, healthcare entities processing Medicare or Medicaid information, financial institutions with federal obligations—face the same requirement.
The immediate business consequence is not technical. It is a question of accountability: leadership is responsible for a security outcome that crosses system boundaries, vendor contracts, and technical domains, without a clear owner or method for tracking progress. The supplied sources do not specify binding migration deadlines for contractors, but federal procurement and compliance expectations follow agency timelines, typically within 18 to 36 months of NIST publication.
What Post-Quantum Cryptography Means in Practice
Quantum computers process certain calculations exponentially faster than conventional machines. Once sufficiently powerful, they could decrypt data protected by RSA, Elliptic Curve Cryptography, and other algorithms that secure everything from HTTPS connections to digital signatures. NIST's standards establish replacement algorithms that remain secure against both classical and quantum attack.
FIPS 203 covers key encapsulation, used when two systems establish a shared secret for encrypted communication. FIPS 204 specifies digital signatures for authentication and data integrity. FIPS 205 provides an additional signature scheme optimized for different use cases. Organizations must identify every system component that performs encryption, key exchange, or signature verification, then determine which components can be upgraded, which require replacement, and which dependencies block migration until vendors release compatible versions.
Which Systems Are Affected
Any system that encrypts data in transit or at rest, verifies digital signatures, or manages cryptographic keys falls within scope. This includes:
- Web servers and application programming interfaces that terminate TLS connections
- Virtual private networks and remote access infrastructure
- Email gateways and encrypted messaging platforms
- Database encryption and hardware security modules
- Code signing and software update mechanisms
- Document signing and electronic health record systems
- Payment processing and financial transaction systems
Cloud services present particular complexity. Organizations must determine whether their cloud providers support post-quantum algorithms, when those capabilities will be available, and how migration affects shared responsibility boundaries. The sources do not provide cloud-specific migration guidance.
The Governance Gap
Post-quantum migration is not a project IT can execute in isolation. It requires executive decisions about risk tolerance, vendor selection, budget allocation, and regulatory positioning. Most organizations lack a single role accountable for cryptographic inventory, let alone migration strategy.
The CTO or CIO typically owns infrastructure but may not have visibility into every application's cryptographic dependencies. The Chief Information Security Officer owns security outcomes but may not control procurement or vendor roadmaps. Compliance leadership answers to auditors and regulators but may not understand technical implementation constraints. Without executive ownership, migration stalls at the inventory stage.
What Leadership Must Inventory Now
The first step is a cryptographic inventory. This is not a penetration test or vulnerability scan. It is a catalog of every system component that uses cryptography, which algorithms it employs, who maintains it, and what dependencies block change. The inventory must document:
- Current cryptographic algorithms in use across all systems
- Vendor upgrade timelines for commercial off-the-shelf software
- Custom applications that implement cryptography directly
- Hardware dependencies such as network appliances and HSMs
- Third-party integrations and API connections
- Long-lived data that must remain accessible after algorithm transition
Many organizations discover that they do not know which algorithms their systems use, which vendors control upgrade paths, or which applications will never receive updates. This information gap becomes a compliance and security liability as migration deadlines approach.
The Federal Timeline and Contractor Implications
The sources do not specify binding migration deadlines for federal contractors. However, federal agencies typically incorporate new NIST standards into procurement requirements and security control baselines within 18 to 36 months of publication. Organizations that wait for explicit contract language will find themselves behind vendors who began migration planning in 2024.
Healthcare entities that handle Medicare or Medicaid data, financial institutions with federal oversight, and defense contractors all operate under security frameworks that reference NIST standards. The NIST Cybersecurity Framework and the NIST Privacy Framework both establish risk management approaches that require addressing cryptographic obsolescence as a known threat. Waiting for regulatory enforcement before beginning inventory is a strategic error.
How This Relates to Cloud Security and Governance
Post-quantum migration intersects directly with cloud security architecture. Most organizations rely on cloud providers for encryption services, key management, and certificate infrastructure. Migration requires understanding which cryptographic responsibilities belong to the provider, which belong to the customer, and where dependencies create blocking conditions.
For example, a healthcare organization using AWS for electronic health records must determine whether AWS Key Management Service supports post-quantum algorithms, when those capabilities will be generally available, and whether their application code can adopt new algorithms without breaking integrations. The answers require both technical analysis and governance decisions about acceptable risk during the transition period.
Organizations with meaningful [virtual CISO leadership](/vciso/) establish cryptographic governance as part of overall cloud security strategy. This includes defining who approves algorithm changes, how migration testing occurs without disrupting production systems, and what documentation satisfies auditor requirements. Without this governance layer, cloud teams make cryptographic decisions in isolation, creating compliance gaps that surface during audits.
Who Owns Post-Quantum Migration
Adequate ownership requires a role with authority to make risk decisions, allocate budget, direct vendors, and report to the board. This is rarely the IT director or the security engineer. It is an executive function.
In organizations with a Chief Information Security Officer, that role often owns cryptographic strategy. In organizations without dedicated security leadership, the responsibility falls to the CIO or CTO, who must balance migration against other infrastructure priorities. The problem is that cryptographic migration is invisible until it becomes a compliance failure. It competes poorly for resources against projects with obvious business value.
Organizations that bring in [virtual CISO services](/vciso/) create executive accountability without hiring a full-time role. The vCISO owns the migration strategy, defines the governance model, coordinates across technical and business stakeholders, and reports progress in terms leadership can act on. This is distinct from the work MSPs or technical consultants perform. It is the difference between having someone who can configure a firewall and someone who decides which risks to accept.
Practical Next Steps for Leadership
Leadership should take three immediate actions:
- Assign executive ownership of cryptographic inventory and migration strategy. Document who has authority to make decisions, allocate budget, and report to the board.
- Begin cryptographic inventory across all systems, including cloud services, vendor software, and custom applications. Identify blocking dependencies and vendor upgrade timelines.
- Establish governance that connects cryptographic decisions to business risk. Define risk tolerance for hybrid periods when both legacy and post-quantum algorithms coexist, document residual risks, and prepare reporting for auditors and regulators.
Organizations that lack internal security leadership or that need to accelerate migration planning may benefit from a confidential consultation to assess current cryptographic posture, identify governance gaps, and establish a migration roadmap. Heights Consulting Group provides virtual CISO services that create executive accountability for outcomes like post-quantum readiness, without the cost or delay of a full-time hire. If a conversation would be useful, [schedule a confidential consultation](/vciso/).
The worst outcome is not choosing the wrong algorithm. It is discovering in 2026 that your organization never inventoried its cryptographic systems, never assigned ownership, and cannot demonstrate progress when auditors or federal procurement officers ask. That gap closes now or it closes under pressure. Leadership determines which.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Cloud Security Architecture and Governance
Design and governance for cloud environments: what the provider secures, what remains yours, and how you keep track of a platform that changes underneath you.