by hannahadmin | Sep 18, 2026 | Compliance, Exodus QRN, PQC, Quantum Security, Seimless
Every quantum-security conversation eventually reaches the same fork in the road: QKD vs PQC. Do you protect your network with quantum physics — quantum key distribution over dedicated fiber — or with new mathematics, the post-quantum cryptography algorithms NIST standardized in 2024? For years, vendors on both sides blurred the answer. In 2026, the U.S. government stopped blurring it. The National Security Agency, the Pentagon, and the Office of Management and Budget have all chosen post-quantum cryptography as the foundation of the federal migration, and the Pentagon has formally barred QKD as a security mechanism for its systems.
That doesn’t make quantum networking a dead end. The same White House that set the PQC deadlines is funding quantum networks for sensing, timing, and distributed computing. For CIOs and CISOs in financial services, healthcare, insurance, and the defense supply chain, the practical question is not which camp wins. It is what to build first, what to buy with confidence, and what to hold as an option. This guide answers the QKD vs PQC question the way regulators now expect you to answer it.
Quick answer — QKD vs PQC: Quantum key distribution (QKD) uses the physics of single photons to share encryption keys over a dedicated optical link and detect eavesdropping. Post-quantum cryptography (PQC) uses new math problems — such as NIST’s ML-KEM and ML-DSA — that run in software and hardware on existing networks and resist attack by quantum computers. U.S. policy treats PQC as the required foundation. QKD, where it is used at all, is a supplementary layer on specific links and never a substitute for PQC authentication.
QKD vs PQC in Plain Terms: Two Very Different Answers to Q-Day
Both technologies exist because of one threat. A cryptographically relevant quantum computer running Shor’s algorithm would break RSA and elliptic-curve cryptography, the public-key math that protects nearly every VPN, TLS session, and digital signature in use today. Adversaries already collect encrypted traffic to decrypt later, the harvest now, decrypt later strategy that makes this a present-day risk.
How quantum key distribution works
QKD sends key material encoded in the quantum states of photons. Because measuring a quantum state disturbs it, an eavesdropper on the line introduces detectable errors. The two endpoints compare samples, discard compromised bits, and keep a shared secret. The idea is elegant: security rests on physics rather than on an assumption that a math problem is hard. As the U.S. Department of Energy explains in its primer on quantum networks, these systems rely on superposition, no-cloning, and entanglement.
How post-quantum cryptography works
PQC replaces vulnerable algorithms with ones built on problems that neither classical nor quantum computers are known to solve efficiently. In August 2024, NIST finalized its first three PQC standards: FIPS 203 (ML-KEM) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. In March 2025, NIST selected HQC as a backup key-establishment algorithm based on different math. PQC is software and firmware. It runs over the fiber, MPLS, broadband, and wireless links you already own.
What the NSA Says About QKD — and Why It Matters to Every Buyer
The clearest statement in the QKD vs PQC debate comes from the NSA. Its public guidance on quantum key distribution and quantum cryptography says the agency does not recommend QKD for National Security Systems and does not anticipate certifying or approving QKD security products unless its limitations are overcome. The NSA lists five of them:
- A partial solution. QKD produces keys but does not authenticate who is on the other end. You still need classical or post-quantum signatures to prevent a man-in-the-middle.
- Special-purpose hardware. QKD requires dedicated fiber or free-space optical equipment. It cannot be delivered as a software update or a network service.
- Cost and insider risk. Distance limits force “trusted relays,” secured facilities where keys exist in the clear and insiders become part of the threat model.
- Hard to validate. Real-world security depends on engineering, not theory. Hardware flaws can open side channels the physics never anticipated.
- Denial of service. The same sensitivity that detects eavesdropping lets an attacker disrupt the link simply by disturbing it.
The NSA concludes that post-quantum cryptography is the more cost-effective and easily maintained solution. For regulated enterprises, that statement matters beyond defense. Banking, healthcare, and insurance examiners anchor their expectations to NIST and NSA guidance, so a security architecture that cannot be mapped to those references is harder to defend in an audit.
The Pentagon Drew a Hard Line on QKD vs PQC
Defense leadership has gone further than advice. A November 18, 2025 DoD CIO memorandum, Preparing for Migration to Post Quantum Cryptography, states that components shall not use quantum confidentiality technologies — naming QKD, solutions that combine QKD with other key establishment, and quantum communications or networking — as a means of achieving confidentiality, authentication, or key distribution.
The Department of War then made the position permanent in its Post-Quantum Cryptography Strategy, announced in a June 23, 2026 release. The strategy repeats that QKD and quantum networking will not be used to achieve security, and adds a line every vendor should read twice: solutions that lack PQC authentication — migrating confidentiality only — will not be considered fully PQC. Its deadlines are blunt. All systems must support PQC by December 31, 2030 or be phased out, and all systems must use PQC by December 31, 2031. DefenseScoop reported that the strategy describes insecure communications in a quantum era as an “existential threat” to military operations.
If you sell to the defense industrial base, this is not an abstract debate. QKD does not count toward your PQC obligations, and a QKD-first architecture could be one you have to re-engineer.
OMB M-26-15 and Executive Order 14412: The Civilian Clock Is Running
On the civilian side, Executive Order 14412, signed June 22, 2026, set the federal PQC calendar we analyzed in our Executive Order 14412 deadline guide. Two days later, OMB issued Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography. It gives agencies 120 days — roughly October 22, 2026 — to submit PQC migration plans, calls for TLS 1.3 support by January 2, 2030, and targets completion of prioritized migrations by December 31, 2030.
Notice what the memo does not contain: any reference to quantum key distribution. The execution guidance is built entirely on NIST’s lattice-based and hash-based algorithms. The joint CISA, NSA, and NIST quantum-readiness factsheet takes the same path, focusing on inventory, vendor engagement, and PQC roadmaps. For federal contractors and the regulated industries that follow federal guidance, the QKD vs PQC decision has effectively been made for the compliance baseline.
Quantum Networking Isn’t Dead — Washington Is Funding It for Other Jobs
Here is the nuance most QKD vs PQC articles miss. The companion order, Executive Order 14413, Ushering in the Next Frontier of Quantum Innovation, directs agencies to prioritize research, testing, and evaluation of quantum sensing and quantum networking. Commerce is tasked with quantum-network-enhanced timing, Energy with networking for distributed quantum computing, and NASA with space applications.
The National Science Foundation describes the same direction in its June 2026 feature on quantum networks: linked sensors, GPS-free positioning, and pooled quantum processors, supported by regional test beds and quantum repeater research. So the federal message is consistent once you see it clearly. Quantum networks are a strategic technology for measurement and computation. For protecting data today, the government’s answer is post-quantum cryptography.
As FedTech Magazine’s 2026 federal QKD guide summarizes, CISA remains focused on the PQC migration and the DoD CIO’s post-quantum director has said QKD “does not meet our security requirements.” Infrastructure — dedicated links, endpoint hardware, and repeaters — remains the core obstacle for dispersed networks.
QKD vs PQC Side by Side: An Enterprise Comparison
| Factor |
Quantum Key Distribution (QKD) |
Post-Quantum Cryptography (PQC) |
| Security basis |
Physics of photons; security depends heavily on hardware engineering |
Math problems believed hard for quantum and classical computers |
| Authentication |
None on its own — needs signatures |
Built in (ML-DSA, SLH-DSA) |
| Infrastructure |
Dedicated fiber or free-space optics; trusted relays over distance |
Runs on existing networks, devices, and clouds |
| Standards status |
Not approved for NSS; barred as a security mechanism in DoD |
NIST FIPS 203, 204, 205 final; HQC in progress |
| Compliance credit |
Does not satisfy federal PQC mandates |
Required under EO 14412, M-26-15, and DoW strategy |
| Scale and cost |
Point-to-point; high cost per link |
Scales like software; cost driven by inventory and upgrades |
| Best fit today |
Research, specialized dedicated links, defense-in-depth where policy allows |
Every enterprise WAN, data center, cloud, and endpoint |
PQC has real costs too. Keys and signatures are larger — an ML-KEM-768 encapsulation key is 1,184 bytes versus 32 bytes for X25519 — which affects handshakes, constrained devices, and certificate chains. That is why crypto-agility, not a one-time swap, is the goal. Our certificate lifecycle management guide covers the operational side.
Where QKD Can Still Add Value — Honestly Scoped
The QKD vs PQC framing implies a winner-takes-all choice. It isn’t. Outside the Department of War’s systems and National Security Systems, an organization may choose to add physics-based key exchange as an extra layer — for example, between two owned data centers linked by dark fiber or wavelength services. Used this way, QKD is defense-in-depth on top of PQC, never a replacement for it.
Ask three questions before spending on it:
- Is PQC authentication already in place on this link? If not, fix that first. Keys without authenticated endpoints are an open door.
- Who controls the trusted nodes? Any relay where keys exist in the clear becomes a crown-jewel facility.
- What happens during an outage? If an attacker can force the link down, your failover path must be PQC-protected, not legacy RSA.
A PQC-First Roadmap for Financial, Healthcare, and Insurance Networks
For most enterprises, resolving QKD vs PQC comes down to sequencing. We recommend a five-step path aligned with the federal timeline and our post-quantum cryptography migration playbook:
- Inventory your cryptography. Identify every protocol, certificate, key, and library — including in medical devices, branch appliances, and third-party SaaS.
- Protect data in transit first. Harvest-now attacks target traffic, so start with quantum-resistant tunnels for data in motion across your WAN and SD-WAN, and plan the exit from legacy links through MPLS replacement.
- Centralize key management. Crypto-agility depends on knowing where keys live and rotating them on demand. Exodus Key Management provides centralized generation, distribution, storage, and rotation.
- Secure stored data. Long-retention records — loan files, patient histories, claims — need protection for data at rest and database-level transparent encryption.
- Evaluate QKD last, and only where policy permits. Treat it as an optional layer on specific dedicated links once PQC coverage is proven.
How Exodus QRN Resolves the QKD vs PQC Dilemma
ibm/SEIMless spent two decades as a vendor-agnostic integrator before becoming an OEM, and that history shapes how Exodus QRN approaches quantum security. The platform is built around crypto-agility — the memory, compute, and flexibility to add post-quantum algorithms as standards mature — with quantum random number generation for high-quality key entropy and centralized encryption and policy management across physical, virtual, and cloud environments.
Where a client has the dedicated optical infrastructure and a policy environment that allows it, quantum key distribution can be layered in. But our design principle mirrors federal guidance: post-quantum cryptography carries the compliance and authentication load, and nothing depends on QKD alone. Paired with the Exodus NxtGen Firewall and zero-trust content security, Exodus QRN protects today’s traffic while keeping your options open for tomorrow’s quantum networks. You can read more about the architecture in our Exodus QRN infrastructure overview.
We believe security is ultimately about people: patients whose records must stay private for decades, families whose savings depend on trusted banking rails, and teams who deserve infrastructure that won’t be obsolete before it is paid off. Choosing well now protects all of them.
QKD vs PQC: Frequently Asked Questions
What is the main difference in QKD vs PQC?
QKD uses the physics of photons to share keys over dedicated optical links. PQC uses new mathematical algorithms, standardized by NIST, that run on existing networks and devices and resist quantum attacks.
Does the NSA approve quantum key distribution?
No. The NSA does not recommend QKD for National Security Systems and does not anticipate certifying QKD security products unless its limitations — authentication, hardware, trusted relays, validation, and denial of service — are resolved.
Can the Department of War or its contractors use QKD for security?
Not as a security mechanism. The DoD CIO’s November 2025 memo and the 2026 DoW PQC Strategy state that QKD and quantum networking will not be used to achieve confidentiality, authentication, or key distribution.
Does QKD satisfy Executive Order 14412 or OMB M-26-15?
No. The federal migration is built on NIST PQC algorithms. OMB M-26-15 does not mention QKD, and agency migration plans are due about 120 days after June 24, 2026.
Is quantum key distribution completely obsolete?
No. Executive Order 14413 prioritizes quantum networking for sensing, timing, and distributed computing. Where policy allows, QKD can add defense-in-depth on dedicated links, but only on top of PQC.
Where should an enterprise start with post-quantum security?
Start with a cryptographic inventory, then protect data in transit with quantum-resistant networking, centralize key management, and secure long-retention data at rest. Evaluate QKD only after PQC coverage is in place.
Contact Us | Our Blog | Our Services | See Previous Post…
Related reading: The Impact of Quantum Computing on IPsec · IBM and Cisco’s Quantum Networking Partnership · Why Quantum-Resistant Networking Is a Business Necessity · All ibm/SEIMless insights
by hannahadmin | Sep 16, 2026 | blog, Quantum Security, Seimless
On June 22, 2026, the White House signed Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks. That order turned post-quantum cryptography from a research topic into a compliance deadline. Under Executive Order 14412, federal high value assets must use quantum-resistant key establishment by December 31, 2030 and quantum-resistant digital signatures by December 31, 2031. Federal contractors come next. The first big milestone, implementation guidance from the Office of Management and Budget, falls due on or about September 20, 2026, 90 days after signing.
For more than 20 years, ibm/SEIMless has helped organizations build networks that protect people as well as data: patients, account holders, policyholders and employees who trust us with their information. Our view is that a quantum deadline is really a promise to those people. This guide explains what Executive Order 14412 requires, who it reaches beyond federal agencies, and what your organization can do in the next 270 days to get ahead of it.
| QUICK ANSWER
What is Executive Order 14412? Executive Order 14412 is a U.S. presidential order signed June 22, 2026 (91 FR 38483). It requires federal agencies to move high value assets and high-impact systems to NIST-approved post-quantum cryptography (PQC). Key establishment must be quantum-safe by December 31, 2030 and digital signatures by December 31, 2031. The order also directs the FAR Council to propose a rule requiring covered federal contractors to comply with NIST’s PQC-inclusive FIPS standards by December 31, 2030. |
Key Takeaways
- For the most sensitive federal systems, the target moves from the 2035 goal to 2030 (encryption) and 2031 (signatures).
- Contractors should expect a proposed FAR rule within 180 days of signing (around December 19, 2026), with a 2030 compliance date.
- Within 270 days, CISA and NIST are to define minimum elements for a cryptographic bill of materials (CBOM).
- Banks, hospitals and insurers are not directly bound, but their regulators, auditors and customers will likely treat Executive Order 14412 as the new benchmark.
Start with data in motion. Traffic captured today can be decrypted once a capable quantum computer exists.
Why Executive Order 14412 Arrived Now
The federal government has been preparing for this moment for years. National Security Memorandum 10 (May 2022) set a goal of mitigating as much quantum risk as feasible by 2035. OMB Memorandum M-23-02 required agencies to inventory quantum-vulnerable cryptography every year. Congress then wrote inventory duties into law with the Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260).
The standards arrived in August 2024. NIST published FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures and FIPS 205 (SLH-DSA) for
hash-based signatures. In March 2025, NIST selected HQC as a backup key-encapsulation algorithm. Its draft NIST IR 8547 proposes deprecating RSA and elliptic-curve algorithms after 2030 and disallowing them after 2035.
The timeline got shorter
Two developments pushed the government to move faster. First, the industry’s own estimates changed. On March 25, 2026, Google announced a 2029 target for its own PQC migration. It pointed to progress in quantum hardware, advances in error correction and new resource estimates for quantum factoring. Second, oversight bodies found gaps. A June 2025 GAO report concluded that the national quantum cybersecurity strategy lacked clear objectives and performance measures.
Behind both sits the threat we have written about in our harvest now, decrypt later analysis: adversaries record encrypted traffic today and wait for the quantum capability to read it. If your data has to stay confidential for ten years or more, it is already at risk. For the math behind that risk, see Shor’s algorithm explained.
What Executive Order 14412 Requires: The Deadline Calendar
The White House fact sheet gives a summary, but the order text sets the milestones. Here they are on one calendar. Dates shown as “on or about” are counted from the June 22, 2026 signing date. Official agency dates may differ.
| When |
Milestone |
Who |
| On or about Jul 22, 2026 (30 days) |
Each agency names a PQC migration lead who reports to the CIO |
All agencies |
| On or about Sep 20, 2026 (90 days) |
OMB guidance: agencies review their inventories of high value assets and high-impact systems and submit migration plans |
OMB, National Cyber Director, CISA |
| On or about Dec 19, 2026 (180 days) |
NIST starts a PQC pilot on its own systems and speeds up module validation. The FAR Council proposes the contractor compliance rule. |
NIST, FAR Council |
| Jan 1, 2027 |
New National Security System acquisitions must comply with CNSA 2.0 (a separate NSA track) |
NSA / NSS owners |
| On or about Mar 19, 2027 (270 days) |
Guidance on minimum elements of a cryptographic bill of materials. The FAR Council proposes adding cryptographic vulnerabilities to contractor disclosure programs. |
CISA, NIST, FAR Council |
| Dec 31, 2027 |
NIST pilot migration complete |
NIST |
| Dec 31, 2030 |
PQC key establishment on high value and high-impact systems. Covered contractors comply with PQC-inclusive FIPS. |
Agencies, contractors |
| Dec 31, 2031 |
PQC digital signatures on high value and high-impact systems |
Agencies |
Sources: Federal Register, EO 14412; NSA CNSA 2.0 FAQ.
“High-impact” means systems rated high under FIPS 199. “High value assets” are the systems designated under OMB M-19-03. These are the systems whose compromise would hurt the most.
Two deadlines, two different problems
Executive Order 14412 splits the migration in two for a reason. Key establishment (the handshake that protects data in transit) comes first because it is the target of harvest-now-decrypt-later attacks. Much of that work can happen at the network layer, often without touching applications. Digital signatures come a year later because they run through certificate authorities, code-signing pipelines, firmware and identity systems. Post-quantum signatures are also larger, and that affects handshake performance. If certificates already strain your team, read our guide to certificate lifecycle management in 2026 before you plan the signature phase.
Who Executive Order 14412 Really Reaches
The order is written for federal agencies, but its effects spread outward through contracts, supply chains and regulators.
Federal contractors and the FAR flow-down
Contractors already handle federal information under clauses such as FAR 52.204-21. Executive Order 14412 directs the FAR Council to propose a rule requiring covered contractors to comply with NIST’s FIPS standards, including the PQC algorithms, by December 31, 2030. A second proposed rule would require contractor vulnerability disclosure programs to cover cryptographic weaknesses, including “the use of non-FIPS approved algorithms.” Neither rule has been proposed yet. Expect flow-down clauses to pass these obligations from prime contractors to subcontractors and managed service providers.
The defense industrial base
One day after the order, the Department of War released its Post-Quantum Cryptography Strategy. The strategy says every system must support PQC by the end of 2030 or be phased out, and must use PQC by the end of 2031. It also commits to moving the defense industrial base to PQC through the CMMC program, whose own rollout schedule is still changing. For National Security Systems, NSA’s CNSA 2.0 advisory keeps its own timeline.
Cloud, SaaS and technology vendors
Providers authorized through FedRAMP should expect PQC questions in authorization packages. CISA has already published a list of product categories that use PQC standards (January 2026). The list signals where federal buyers will look first: cloud services, web software, endpoint security and networking. If you sell technology, PQC support is quickly becoming a requirement to be considered at all.
Financial services, healthcare and insurance
These sectors are not named in Executive Order 14412, but they sit close to it. Public companies already report material cyber incidents under the SEC’s 2023 disclosure rules. New York’s NYDFS Part 500 now requires asset inventories. Banks follow FFIEC cybersecurity guidance, and healthcare organizations protect patient data under the HIPAA Security Rule. All of these frameworks draw on NIST. In our experience, once the federal government sets a date, examiners, auditors and cyber insurers start using it as the benchmark for “reasonable” security. For AI-driven risk in the same sectors, see our analysis of blind agent transfer in financial services.
The Inventory Problem Executive Order 14412 Exposes
You cannot migrate cryptography you cannot find. Federal agencies have had inventory duties since 2023, and CISA published a strategy for automated PQC discovery and inventory tools to help. The NIST National Cybersecurity Center of Excellence runs a Migration to Post-Quantum Cryptography project focused on the same problem. Even so, most private organizations still cannot produce a complete cryptographic inventory when asked.
That is why the order’s CBOM milestone matters. A cryptographic bill of materials lists the algorithms, key lengths, libraries, certificates and protocols inside a product or system. Once CISA and NIST define its minimum elements, expect CBOMs to show up in procurement questionnaires next to software bills of materials.
Where quantum-vulnerable cryptography hides
- WAN and VPN tunnels: IPsec and TLS overlays in SD-WAN deployments and site-to-site links. See how quantum computing affects security protocols.
- Carrier transport: traffic that is assumed to be private but is often unencrypted. Ask whether your MPLS traffic is safe.
- Edge devices: firewalls, load balancers and TLS terminators. These are the attack surface we covered in network edge security in 2026.
- Stored data: backups, archives and databases encrypted with keys protected by RSA or ECC.
- Identity and signing: PKI, code signing, firmware updates, SSO tokens and machine identities.
- Third parties: SaaS APIs, payment processors and managed service providers whose cryptography you do not control.
Crypto-Agility: The Capability Executive Order 14412 Quietly Demands
The PQC algorithms will keep changing. HQC is still being standardized, and implementation guidance keeps evolving. NIST’s CSWP 39 on crypto-agility, updated in June 2026, describes how to design systems so algorithms can be replaced without rebuilding them. NIST SP 800-227 gives recommendations for using key-encapsulation mechanisms such as ML-KEM.
Validation matters too. Executive Order 14412 directs NIST to speed up the Cryptographic Module Validation Program, and federal buyers will increasingly ask for modules validated under FIPS 140-3. Adoption is already underway: Cloudflare reports that more than two-thirds of browser traffic to its network uses post-quantum encryption. The network layer is where many enterprises can move fastest, because a quantum-safe transport protects every application that runs over it. That idea is the basis of our post-quantum cryptography migration playbook.
A 270-Day Executive Order 14412 Readiness Plan
This plan follows the order’s own 30/90/180/270-day structure, adapted for private-sector organizations. It fits contractors, regulated enterprises and any company that holds long-lived sensitive data.
Days 0–30: Assign ownership
- Name a PQC migration lead who reports to the CIO or CISO, as the order requires of agencies.
- Brief the board on Executive Order 14412, the 2030 and 2031 dates, and your harvest-now-decrypt-later exposure.
- List the data that must stay confidential beyond 2030: patient records, financial records, intellectual property and legal files.
Days 31–90: Build a quantum impact inventory
- Run automated discovery across networks, endpoints and cloud. Rank systems by impact rather than waiting for a perfect audit.
- Send vendors a PQC questionnaire covering their algorithm roadmap, FIPS 140-3 validation status and whether they can supply a CBOM.
- Map your cryptography to the CISA PQC initiative categories so reports use a consistent vocabulary.
Days 91–180: Protect data in motion first
- Put quantum-resistant protection on your highest-risk WAN links, data center interconnects and cloud on-ramps.
- Pilot hybrid (classical plus PQC) key exchange and measure latency and compatibility.
- Track the FAR Council’s proposed rule and comment on it if you are a federal supplier.
Days 181–270: Prepare for CBOMs, disclosure and signatures
- Get your inventory into a form that can meet the coming CBOM requirements.
- Update your vulnerability disclosure policy to accept reports of cryptographic weaknesses.
- Draft the PKI and code-signing roadmap for the 2031 signature deadline, and budget for 2027–2031.
How ibm/SEIMless Helps You Meet Executive Order 14412
ibm/SEIMless combines more than 20 years of vendor-agnostic carrier, cloud and communications experience with its role as OEM of Exodus QRN quantum-resistant networking. That combination lets us work at the layer where Executive Order 14412 can be met fastest.
We encourage every buyer to ask each vendor, ibm/SEIMless included, for its exact algorithm list, validation status and CBOM plan. We are glad to walk you through ours. To see how the pieces fit, explore Exodus QRN infrastructure for the post-quantum era and why quantum-resistant networking is becoming a business necessity.
Frequently Asked Questions About Executive Order 14412
What is Executive Order 14412?
Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” was signed June 22, 2026. It requires federal agencies to move high value assets and high-impact systems to NIST-approved post-quantum cryptography, and it starts rulemaking that will extend PQC requirements to federal contractors.
When do the Executive Order 14412 deadlines take effect?
Agencies had 30 days to name migration leads. OMB guidance is due at 90 days (on or about September 20, 2026). The contractor rule is due to be proposed at 180 days, and CBOM guidance at 270 days. PQC key establishment is required by December 31, 2030 and PQC digital signatures by December 31, 2031.
Does Executive Order 14412 apply to private companies?
Not directly, with one major exception. Federal contractors will be covered once the FAR Council finalizes its rule, which proposes compliance by December 31, 2030. Other private organizations will feel the order through supply-chain flow-downs, customer requirements and regulators that rely on NIST standards.
What is a cryptographic bill of materials (CBOM)?
A CBOM is a machine-readable inventory of the cryptographic algorithms, keys, certificates, libraries and protocols in a product or system. Executive Order 14412 directs CISA and NIST to define its minimum elements so cryptographic risk can be assessed automatically.
How is Executive Order 14412 different from NSM-10 and OMB M-23-02?
NSM-10 set a 2035 goal, and M-23-02 required annual inventories. Executive Order 14412 adds binding 2030 and 2031 dates for the most sensitive federal systems, a named migration lead in every agency, procurement rules for contractors and CBOM guidance.
What should my organization do first?
Assign an executive owner, identify data that must stay confidential beyond 2030, and protect data in transit on your highest-risk links. Network-layer quantum-resistant protection can deliver results in months while application and PKI work continues.
Don’t Wait for the FAR Rule. Start Your Quantum-Safe Transition Today.
Executive Order 14412 sets the dates, but the people who depend on your organization need protection now. ibm/SEIMless and Exodus QRN can help you inventory your cryptography, protect data in motion and build a practical migration plan for your board.
Contact Us
More resources: About ibm/SEIMless · FAQs · Blog · Agentic AI security meets Q-Day
by hannahadmin | Sep 8, 2026 | blog, QRN, Seimless
Crypto-Agility & Compliance
Three separate clocks are converging on the same overloaded team. Here is what changes on September 21, what changes again in March, and how to automate your way out before an expired certificate takes down a payment rail.
ibm/SEIMless Communications Technologies, Inc.
For most enterprises, certificate lifecycle management has never been a strategic conversation. It was a spreadsheet, a shared mailbox, and a calendar reminder that someone set three years ago and nobody has looked at since. That arrangement is about to fail — not gradually, but on specific, published dates that are already on the federal record.
| 13 DAYS REMAINING
September 21, 2026. Every FIPS 140-2 validated cryptographic module moves to the NIST Historical List. From that point forward, those modules are supported for existing systems only — not for new federal procurements, and not for the compliance attestations your customers are about to start asking for. |
At the same time, the maximum lifetime of a public TLS certificate has already dropped to 200 days, on its way to 100 days in March 2027 and 47 days in March 2029. And NIST has formally scheduled the retirement of the RSA and elliptic-curve cryptography that virtually every certificate in your estate depends on today.
Individually, each of these is a project. Together, they are a structural change in how networks have to be built. This post explains all three, shows which one hits your industry first, and lays out the certificate lifecycle management playbook we use at ibm/SEIMless to get enterprises from manual renewal to genuine crypto-agility.
What Is Certificate Lifecycle Management?
| DEFINITION
Certificate lifecycle management (CLM) is the discovery, issuance, deployment, monitoring, renewal, rotation, and revocation of every digital certificate and cryptographic key across an organization’s network — servers, load balancers, VPN concentrators, firewalls, APIs, containers, IoT endpoints, and machine-to-machine identities. Mature certificate lifecycle management is automated, inventoried, and algorithm-agnostic, so that a cryptographic standard can be swapped out without re-architecting the network. |
The critical word in that definition is algorithm-agnostic. Historically, certificate lifecycle management was about not letting things expire. In 2026, it is about being able to change what your certificates are made of — quickly, at scale, and more than once. NIST’s National Cybersecurity Center of Excellence calls this property crypto-agility, and it now drives every serious network design conversation we have.
Deadline One: FIPS 140-2 Validation Sunsets This Month
The Cryptographic Module Validation Program, jointly run by NIST and Canada’s cyber centre, is the arbiter of whether a cryptographic module can be used in U.S. federal systems. Its transition schedule has been public for years, and it lands this month.
- April 1, 2022: CMVP stopped accepting new FIPS 140-2 validation submissions. Everything issued since has been FIPS 140-3.
- September 21–22, 2026: All remaining FIPS 140-2 certificates move to the Historical List. Per the CMVP program page, agencies may continue using those modules for existing systems only. The FIPS 140-3 Transition Effort page documents the same milestone.
- After that date: New procurements, FedRAMP packages, CMMC assessments, and downstream vendor questionnaires increasingly require FIPS 140-3 validated modules.
Here is the part that catches people out: this is not only a government problem. FIPS validation is written into commercial contracts across banking, insurance, and healthcare because it is the cheapest available shorthand for “this crypto was independently tested.” When your module drops to the Historical List, your customer’s procurement team sees it in their next vendor review — and the burden of proof lands on you.
The practical question is not “are we compliant today.” It is: can you produce, on request, a list of every module in your environment and its current validation status? Most organizations cannot, which is precisely the certificate lifecycle management gap. Federal agencies have been under an explicit cryptographic inventory mandate since the White House issued OMB Memorandum M-23-02; the private sector is simply arriving at the same requirement through contracts instead of memos. If your organization sells into the defense supply chain, the same evidence is expected under CMMC and, for cloud services, under FedRAMP.
Deadline Two: TLS Certificate Lifetimes Are Collapsing Toward 47 Days
In April 2025, the CA/Browser Forum passed Ballot SC-081v3, which sets a staged reduction in the maximum validity of publicly trusted TLS certificates. The schedule is not a proposal. It is in force.
| Effective period |
Max certificate validity |
Max domain validation reuse |
Renewals per year |
| Through March 14, 2026 |
398 days |
398 days |
~1 |
| March 15, 2026 – March 14, 2027 |
200 days (current) |
200 days |
~2 |
| March 15, 2027 – March 14, 2029 |
100 days |
100 days |
~4 |
| March 15, 2029 onward |
47 days |
10 days |
~8 |
Read the right-hand column again. An enterprise that renews 400 public certificates once a year today will be executing roughly 3,200 renewal events per year by 2029 — plus domain revalidation every ten days. No staffing model absorbs that. This is the single clearest argument for automated certificate lifecycle management ever put in front of a CFO, because the labor math stops working long before the security math does.
It also changes the blast radius of a mistake. When certificates lasted over a year, a missed renewal was an embarrassment. When they last 47 days, a broken automation pipeline silently expires your entire estate inside two months. NIST’s TLS Server Certificate Management project (SP 1800-16) documents exactly this failure pattern, and NIST SP 800-52 Rev. 2 remains the federal baseline for TLS configuration itself.
Deadline Three: NIST Has Scheduled the Retirement of RSA and ECC
The third clock is the one this company was built around. In NIST IR 8547, NIST published a transition timeline for the classical algorithms underpinning today’s certificates:
- After 2030: RSA, ECDSA, ECDH, and finite-field Diffie-Hellman at 112-bit security strength are deprecated
- After 2035: those algorithms — including their 128-bit-and-above variants — are disallowed
Replacements are already standardized: ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures, finalized by NIST in August 2024. The NSA’s Commercial National Security Algorithm Suite 2.0 sets an even more aggressive posture for national security systems — see the CNSA 2.0 FAQ and the broader NSA cybersecurity guidance library.
Post-quantum certificates are also structurally different: ML-DSA signatures and public keys are substantially larger than their ECC equivalents. That changes handshake sizes, MTU behavior, load balancer buffers, and embedded device storage. You do not discover those problems in a policy document — you discover them the first time you try to deploy a real certificate through your real network. Which is why the inventory has to come first, and why we cover the underlying mathematics in our explainer on quantum computing and encryption.
Why Certificate Lifecycle Management Is Really a Quantum-Resistance Problem
Treat these as three unrelated compliance chores and you will run three unrelated projects, three times, over the next decade. Treat them as one problem and the answer is singular: build a network that can change its cryptography on demand.
That is the whole thesis of crypto-agility, and every U.S. authority now converges on it. CISA’s Post-Quantum Cryptography Initiative makes cryptographic discovery and inventory the first step in its migration model; its Strategy for Migrating to Automated PQC Discovery and Inventory Tools is explicit that manual inventories do not scale. The NIST Cybersecurity Framework 2.0 puts asset identification ahead of protection for the same reason. Automated certificate lifecycle management is how that identification stays true from one week to the next.
And the urgency is not theoretical. Adversaries are already capturing encrypted traffic today to decrypt once a cryptographically relevant quantum computer exists — the pattern we covered in Harvest Now, Decrypt Later. Data with a ten-year confidentiality requirement is already exposed. Certificates are simply the control plane you use to fix it.
What Breaks First, by Industry
Financial Services and Insurance
Payment rails, trading systems, and claims platforms carry the highest density of machine identities and the lowest tolerance for downtime. Examiners are already asking. The FFIEC IT Examination Handbook covers encryption and key management directly; New York institutions face NYDFS Part 500, which mandates encryption controls and annual review; and public companies must disclose material incidents under the SEC’s cybersecurity disclosure rules. An outage caused by an expired certificate is an operational event you will be explaining in writing.
Healthcare
Medical records carry decades-long confidentiality obligations, which makes healthcare the most exposed vertical to harvest-now-decrypt-later. The HIPAA Security Rule requires encryption of ePHI in transit and at rest, and clinical environments are dense with long-lived embedded devices that were never designed for 47-day certificate rotation. Those devices are where certificate lifecycle management programs quietly fail.
Carriers, MSPs, and Multi-Nationals
Providers inherit their customers’ obligations. If you operate infrastructure on behalf of regulated clients, every one of these three deadlines arrives as a contractual question from a client procurement team — often all three in the same questionnaire. Consumer-facing firms should also review the FTC Safeguards Rule, which sets encryption expectations for non-bank financial institutions.
The ibm/SEIMless Certificate Lifecycle Management Playbook
This is the sequence we run with clients. It is deliberately ordered — each step makes the next one cheaper.
1. Build a cryptographic bill of materials
Discover every certificate, key, algorithm, key length, module, and expiry across data centers, cloud, branch, and remote endpoints. Include internal PKI, not just public certificates — internal estates are typically three to ten times larger and far less governed. Correlate findings against the National Vulnerability Database and the CISA Known Exploited Vulnerabilities Catalog so cryptographic debt and exploitable debt are ranked on one list.
2. Automate issuance and renewal — with no exceptions
Any certificate that a human renews by hand is a certificate that will expire. At 200 days it is a risk; at 47 days it is a certainty. ACME-based automation should be the default path, and every exception should carry a named owner and a documented reason.
3. Re-validate every module against FIPS 140-3
Map each cryptographic module to its validation certificate and its status after this month’s Historical List transition. Where a vendor has no FIPS 140-3 path, that is a procurement decision, not an engineering one — escalate it now, while you still have runway.
4. Test hybrid and post-quantum certificates in a real lab
Deploy ML-KEM hybrid key exchange and ML-DSA certificates against representative load balancers, firewalls, and clients. Measure handshake size, latency, and failure modes. Our data in motion and data at rest practices exist for exactly this validation work.
5. Centralize key custody
Certificate lifecycle management fails when keys live in a dozen places under a dozen policies. Consolidate custody, rotation, and escrow under a single governed service — the role our Exodus key management platform plays.
6. Rehearse the emergency rotation
Assume a certificate authority is compromised, or an algorithm is broken, on a Friday afternoon. How many hours to rotate everything? If the answer is unknown, it is too long. Run the drill, measure it, shorten it, repeat annually.
7. Write crypto-agility into contracts
Every renewal from here forward should require FIPS 140-3 validation, a published post-quantum roadmap, and automated certificate lifecycle management support. Buying it into the estate is cheaper than retrofitting it.
How Exodus QRN Makes This Operational
ibm/SEIMless has spent more than twenty years as a vendor-agnostic integrator, which is how we saw the flaw in SD-WAN and SASE early enough to build past it. Exodus QRN was designed on the assumption that cryptographic standards will keep changing — so certificate and algorithm changes are configuration, not reconstruction.
Because we manufacture as an OEM and remain carrier- and cloud-agnostic, we can rebuild the cryptographic layer without forcing a wholesale hardware refresh — the difference between a migration and a rip-and-replace. Our earlier post-quantum cryptography migration playbook covers the algorithm-selection layer that sits beneath this certificate work.
Frequently Asked Questions
What is certificate lifecycle management in simple terms?
It is the end-to-end process of finding, issuing, deploying, renewing, rotating, and revoking every digital certificate and key in an organization. Modern certificate lifecycle management is automated and algorithm-agnostic so cryptography can be replaced without redesigning the network.
What happens to FIPS 140-2 certificates on September 21, 2026?
They move to the CMVP Historical List. Per NIST, agencies may continue using those modules for existing systems only. New procurements and most compliance attestations will expect FIPS 140-3 validated modules.
Are TLS certificates really dropping to 47 days?
Yes, on a staged schedule set by CA/Browser Forum Ballot SC-081v3: 200 days as of March 15, 2026, 100 days from March 15, 2027, and 47 days from March 15, 2029, with domain validation reuse falling to 10 days.
When do RSA and ECC actually stop being allowed?
NIST IR 8547 deprecates 112-bit RSA and elliptic-curve algorithms after 2030 and disallows RSA, ECDSA, ECDH, and Diffie-Hellman after 2035. Systems holding data with long confidentiality lifetimes should migrate well ahead of those dates.
Can we handle 47-day certificates without automation?
Realistically, no. A 400-certificate estate moves from roughly 400 renewal events per year to roughly 3,200, plus domain revalidation every ten days. Automated certificate lifecycle management is the only model that scales.
Should we wait for post-quantum standards to settle before starting?
No. The three primary standards — FIPS 203, 204, and 205 — were finalized in August 2024. Inventory and automation work is valuable regardless of which algorithms you eventually deploy, and it is the long pole in every migration we have run.
The Bottom Line
Certificate lifecycle management stopped being a maintenance task the moment the renewal cadence outgrew the people doing it. Between the FIPS 140-2 sunset this month, TLS validity shrinking toward 47 days, and NIST’s deprecation of RSA and ECC, the enterprises that automate now will absorb every one of these changes as a configuration update. The ones that wait will absorb them as outages, failed audits, and emergency projects priced at three times the cost.
The work is knowable and the deadlines are published. What separates the two outcomes is whether you start before or after something breaks.
| Talk to ibm/SEIMless Today
Our engineers will run a cryptographic discovery across your environment, map every certificate and module against the September 2026 FIPS transition and the SC-081v3 validity schedule, and deliver a prioritized certificate lifecycle management roadmap built on Exodus QRN. No obligation, no pressure from salespeople selling far less capable systems.
Call 646-546-5245 Email in**@**********ss.com
Headquarters One Liberty Plaza, New York, NY 10006
Start here Get Started · Contact Us · Services · FAQs · About Us |
by hannahadmin | Aug 21, 2026 | blog, cybersecurity, QRN, Seimless, telecom, wide area networking
Agentic AI security has moved from a research topic to a boardroom line item in under twelve months. At the same time, the countdown to Q-Day keeps ticking. Most enterprises still treat these as two separate projects, run by two separate teams, on two separate budgets. That separation is the mistake. Autonomous attackers and quantum-vulnerable encryption are not parallel risks. They are the same risk, arriving from two directions, and they will meet inside your network.
At ibm/SEIMless, we have spent more than two decades helping firms build networks that survive the next threat rather than the last one. This guide explains what changed, why it matters now, and what a defensible roadmap looks like for 2026 and beyond.
What Agentic AI Security Actually Means in 2026
Traditional AI security focused on the model. Teams worried about prompt injection, hallucination, and data leakage inside a chat window. Agentic AI security is a different discipline entirely, because agents do not just answer. They act.
An agentic system plans, calls tools, writes and runs code, authenticates to APIs, and chains dozens of steps together without a human in the loop. So every credential the agent holds becomes an attack path. Every tool it can reach becomes a lateral movement option.
The OWASP GenAI Security Project published its Top 10 for Agentic Applications on 9 December 2025. The list reads less like an AI document and far more like a network security document. Agent identity spoofing, tool misuse, privilege compromise, and cascading multi-agent failures all appear. In other words, agentic AI security is network security wearing a new label.
That framing matters for one practical reason. If the risk lives in identity, credentials, and traffic, then the controls belong in your network architecture — not only in your AI governance policy. Our NxT-Gen Network Security Solutions practice was built on exactly that principle.
The First Documented AI-Orchestrated Campaign Changed the Conversation
For years, autonomous attack scenarios lived in threat modeling slide decks. Then they left the slide deck.
On 13 November 2025, Anthropic published its account of disrupting the first reported AI-orchestrated cyber espionage campaign. The operators, tracked as GTG-1002, manipulated an AI coding agent into running reconnaissance, vulnerability discovery, exploitation, and data exfiltration across roughly thirty target companies. Technology companies, financial institutions, chemical manufacturers, and government agencies all appeared on the target list.
The headline figure is the one that should reset your planning assumptions. The AI performed an estimated 80 to 90 percent of the campaign. Human operators intervened at only four to six critical decision points.
Congress noticed. The Congressional Research Service now maintains a standing brief titled “Agentic Artificial Intelligence and Cyberattacks,” most recently updated on 6 July 2026. Regulators, insurers, and auditors now read the same material your board reads.
Meanwhile, the pattern keeps repeating at smaller scale. Our coverage of the agentic AI security vulnerability exposed in ServiceNow, the malicious npm package that stole files from a Claude AI user directory, and the GlassWorm malware takedown all describe the same underlying shift. Attackers now automate the boring parts of intrusion, and the boring parts were the parts that used to give defenders time.
Why Speed Is the Real Weapon in Agentic AI Security
Autonomous tooling does not invent new exploits. Instead, it removes the human bottleneck. A campaign that once took a skilled team three weeks now takes an agent three hours.
Detection windows shrink accordingly. If your mean time to detect is measured in days, an agentic adversary has already finished. As a result, controls that depend on human triage speed are quietly obsolete, which is why we pair Exodus ARIA ADR with endpoint detection and response rather than relying on either alone.
Q-Day, Harvest Now Decrypt Later, and the Cryptographic Clock
Now consider the second front.
Q-Day describes the moment a cryptographically relevant quantum computer can break the RSA and elliptic-curve cryptography that protects almost every enterprise session today. The Cloud Security Alliance’s Q-Day Clock research places that moment as plausibly feasible around 2030.
However, the deadline that matters is not 2030. It is today. Adversaries already capture encrypted traffic and store it, waiting for the decryption capability to arrive. Security teams call this Harvest Now, Decrypt Later, and we covered the business impact in depth in Harvest Now, Decrypt Later.
Ask a simple question about your own data. How long does it need to stay secret? Patient records, financial contracts, engineering drawings, legal discovery, and government correspondence all carry secrecy lifetimes measured in decades. Therefore, anything you transmit today with classical encryption is already exposed to a decryption event ten years out.
The standards exist. NIST finalized FIPS 203, FIPS 204, and FIPS 205 on 13 August 2024, then selected HQC as a backup key encapsulation mechanism on 11 March 2025. You can read the current status directly on the NIST Post-Quantum Cryptography project page. For a plain-English explanation of the underlying mathematics, see our post on how quantum computers break encryption.
Adoption, by contrast, lags badly. The same Cloud Security Alliance research found that only about 5 percent of firms had deployed quantum-safe encryption as of May 2025.
Where Agentic AI Security and Quantum Risk Converge
Here is the thesis. These two threats do not simply coexist. They multiply.
Harvesting Becomes Cheap and Continuous
Harvest Now, Decrypt Later used to demand patient, well-resourced adversaries. Someone had to find valuable flows, set up collection, and hold access for years. Agentic tooling collapses that cost. An AI agent can map a network, spot long-lived sensitive flows, and stage theft around the clock.
In short, the pool of actors able to run a decade-long harvest just grew sharply. Our guidance on protecting data in motion and data at rest addresses both halves of that exposure.
Machine Identity Explodes the Key Estate
Every agent needs credentials. Those credentials depend on keys. Each key then becomes another item in a cryptographic inventory that most organizations cannot even enumerate today.
Most teams already struggle to track human identities. Now add thousands of non-human identities that spin up, authenticate, and disappear within minutes. So agentic AI security and post-quantum migration share one need: knowing where your keys are. That is precisely the problem Exodus Key Management exists to solve.
Crypto-Agility Stops Being Optional
Crypto-agility means you can swap algorithms without rebuilding applications. In the past, teams put it off, because algorithm changes came once a decade.
That assumption no longer holds. Between the NIST standards, NSA CNSA 2.0 requirements, and vendor timelines, most firms will change cryptographic primitives more than once before 2032. Moreover, AI-assisted code breaking may shorten those cycles further. A design that hard-codes one cipher has a shelf life.
Your Overlay Is Only as Strong as Its Handshake
Software-defined networking encrypts site-to-site traffic, and most teams consider that box ticked. Look closer, though. Many overlays still negotiate keys with classical Diffie-Hellman.
An attacker capturing that traffic today can decrypt it after Q-Day, no matter how modern the overlay looks. We examined this gap in Today’s Software-Defined Networks Are Not Future-Ready and in SD-WAN Not Ready for Next Generation Attacks. If you run SD-WAN or are evaluating MPLS replacement solutions, the handshake deserves an audit before the roadmap does.
Agentic AI Security Cuts Both Ways for Defenders
The picture is not one-sided. Autonomy cuts both ways, and defenders can automate correlation, triage, and containment just as effectively.
Modern networks already use machine learning to spot anomalies that no analyst would catch at three in the morning. We explored that shift in AI-Native Networks: The Future of Telecommunications and in How LLMs Will Improve Network Security. Furthermore, our piece on AI leading the next generation of defense covers the operational side of that argument.
The difference comes down to preparation. Attackers use autonomy when it suits them. Defenders must use it on purpose, with governance, logging, and clear escalation paths. Organizations that build that discipline into agentic AI security now will absorb the next wave far better than those retrofitting later.
What Executive Order 14412 Changes for Private Enterprises
On 22 June 2026, the White House signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”. The order appeared in the Federal Register on 25 June 2026. A companion order, “Ushering in the Next Frontier of Quantum Innovation,” targets deployable quantum capability by 2028.
The federal timeline is now concrete:
- 30 days: every agency names a post-quantum cryptography migration lead.
- 90 days: OMB issues guidance covering High Value Asset inventories and transition plans.
- 180 days: NIST launches a migration pilot, and CISA publishes guidance on minimum cryptographic bill of materials elements.
- 270 days: the FAR Council proposes amended contractor disclosure rules.
- 31 December 2030: High Value Assets use post-quantum cryptography for key establishment.
- 31 December 2031: the same systems use post-quantum cryptography for digital signatures.
Three Ways the Order Reaches Private Networks
Private enterprises are not directly bound. Nevertheless, three mechanisms will pull you in anyway.
First, procurement. Federal contract language flows down to subcontractors and suppliers, and the FAR rulemaking makes that explicit. Second, the cryptographic bill of materials concept will become a standard due-diligence question, much as software bills of materials did. Third, insurers and auditors follow federal benchmarks when they define reasonable care.
CISA’s Post-Quantum Cryptography Initiative and the NSA’s CNSA 2.0 FAQ remain the clearest public statements of expectation. Notably, CNSA 2.0 pushes new national security system acquisitions toward quantum-resistant algorithms from January 2027. Our earlier reporting on U.S. lawmakers urging action on the quantum threat traced how this policy momentum built.
Industry is moving on its own schedule too. Cloudflare reports that more than two-thirds of browser traffic to its network already uses post-quantum encryption. The Quantum Insider’s August 2026 timeline survey shows Google and Cloudflare targeting 2029, Microsoft targeting 2033, and SWIFT planning a post-quantum SwiftNet release for 2027.
What the Convergence Means Sector by Sector
Risk is never evenly distributed. Your exposure depends on how long your data stays valuable and how quickly your operations must respond.
Healthcare. Patient records carry a legal and practical secrecy lifetime of decades. So healthcare providers sit at the very top of the Harvest Now, Decrypt Later risk list. Meanwhile, connected clinical devices give autonomous attackers an unusually soft internal surface.
Financial services. Transaction records, credit files, and contract archives all outlive current encryption. SWIFT plans a post-quantum SwiftNet release for 2027, so the migration pressure is already contractual rather than theoretical. Our analysis of why big cybersecurity budgets still fail explains why spending alone will not close this gap.
Manufacturing and supply chain. Engineering drawings and process data retain competitive value for twenty years or more. In addition, third-party exposure keeps growing, as the Ericsson service provider breach showed.
Government and public sector. Executive Order 14412 applies directly, and the flow-down reaches every supplier. Our reporting on the Pentagon’s supply-chain risk designation for an AI vendor shows how quickly AI procurement scrutiny is tightening.
Critical communications. Outages and intrusions compound each other. Recent incidents such as the AT&T 911 outage show how thin the safety margin has become for vital services.
A Seven-Step Roadmap for Agentic AI Security and Quantum Readiness
You do not need two programs. You need one program with two outputs. Here is the sequence we use with clients.
- Build a combined inventory. Catalog cryptographic assets and non-human identities in the same exercise. Both questions share one answer set. Where are the keys, who holds them, and what do they protect?
- Classify by secrecy lifetime. Rank data by how long it must stay confidential. Anything above ten years moves to the front of the queue immediately.
- Audit your handshakes. Check what your VPNs, overlays, and management planes actually negotiate. Marketing material and packet captures often disagree.
- Govern agents like privileged users. Give every agent a scoped identity, a short-lived key, and a full audit trail. Above all, remove standing access. Our work on zero trust content security applies directly here.
- Protect the two data states separately. Data in motion and data at rest fail differently, so plan them as distinct workstreams. Exodus Transparent Encryption and our EXODUS QRN data-at-rest guidance cover the second.
- Shorten detection to machine speed. Automated attacks require automated response. Human triage remains essential for judgement, yet it cannot be the first line.
- Rewrite procurement language now. Ask every vendor for post-quantum support, key inventories, and agent governance. This costs nothing today and saves enormous rework later.
For a deeper build sequence, see our companion pieces on post-quantum cryptography migration and enterprise IT infrastructure services.
How ibm/SEIMless Approaches Agentic AI Security and Quantum-Resistant Networking
We are vendor-agnostic by design. Since 2001, we have selected technology on fit rather than on partnership incentives, which matters more than ever now that every vendor claims quantum readiness.
Our Exodus Quantum-Resistant Networking portfolio addresses the cryptographic layer through key management, data in motion, data at rest, and edge enforcement through QR-Edge and Exodus PIET. On the detection side, Exodus NxtGen Firewall, Exodus ARIA ADR, and EDR close the response-time gap that agentic attackers exploit.
Underneath sits the transport itself. Whether you run Ethernet, MPLS, wavelength services, dark fiber, private line, or wireless, the encryption question follows the circuit. Our cloud services, Microsoft SaaS and DaaS, telecom services, and document management practices extend the same standard across the rest of the estate.
Frequently Asked Questions
Is agentic AI security different from traditional AI security?
Yes. Traditional AI security protects a model and its outputs. Agentic AI security protects an autonomous system that holds credentials, calls tools, and takes actions across your network, so the controls resemble identity and network security far more than content moderation.
Do we need to fix quantum risk before agentic AI risk?
Neither one waits for the other. Start both with the same inventory exercise, because the underlying question — where your keys and identities live — is identical for both programs.
Does Executive Order 14412 apply to private companies?
Not directly. However, its requirements reach private firms through federal procurement flow-downs, contractual due diligence, and the benchmarks that auditors and insurers adopt.
What is a realistic first ninety days?
Complete a cryptographic and non-human identity inventory, classify data by secrecy lifetime, audit your overlay handshakes, and update procurement language. Those four steps cost little and unlock everything that follows.
How does quantum-resistant networking differ from post-quantum cryptography?
Post-quantum cryptography describes the algorithms. Quantum-resistant networking describes the architecture that deploys, rotates, and governs those algorithms across live enterprise traffic.
The Bottom Line
Two clocks are running. One counts down to autonomous attackers operating faster than your response process. The other counts down to the day today’s captured traffic becomes readable. They are converging, and the organizations that treat them as one program will finish years ahead of those that do not.
Agentic AI security and quantum-resistant networking share the same foundation: know your keys, govern your identities, and build architecture you can change. Everything else is implementation detail.
Ready to start? Get started with ibm/SEIMless or contact our team for a cryptographic and agent-governance readiness assessment. You can also review our reports, browse our partners, read the FAQs, or explore distributor opportunities.
Complete ibm/SEIMless Resource Index
Quantum-Resistant Networking
NxT-Gen Network Security Solutions
Wide Area Networking and Connectivity
Cloud Services
Contact Us | Our Blog | Our Services | See Previous Post
by hannahadmin | Aug 17, 2026 | blog, QRN, Seimless
Ask most executives when quantum computing becomes a security problem, and they’ll say “in ten years.” That answer is already wrong. The most dangerous quantum attack doesn’t require a working quantum computer today — it requires only patience. Adversaries are copying your encrypted traffic right now, warehousing it, and waiting for the day a cryptographically relevant quantum machine can unlock it. Security researchers call it “harvest now, decrypt later,” and it has quietly turned 2026 into the most important migration year in the history of enterprise cryptography.
| In 2024, the U.S. government finalized the first post-quantum encryption standards. In 2025 and 2026, federal agencies, defense contractors, and regulated industries began operating under hard migration timelines. If your network still relies exclusively on RSA and elliptic-curve cryptography, every long-lived secret you transmit has a shelf life measured against Q-Day. Quantum-resistant networking is no longer a research topic. It’s a procurement decision. |
The Clock Already Started: What “Harvest Now, Decrypt Later” Really Means
Public-key cryptography — the math behind HTTPS, VPNs, digital signatures, and virtually every secure connection your business makes — rests on problems that are hard for classical computers but trivial for a sufficiently large quantum computer. A future quantum machine running Shor’s algorithm could unravel RSA and elliptic-curve keys in hours instead of the billions of years it would take today’s supercomputers.
The uncomfortable part is the timeline mismatch. You don’t need a quantum computer to steal the data — you only need it to decrypt the data later. That means a health system’s records, a bank’s transaction history, or a defense supplier’s design files that must stay confidential for 15, 25, or 50 years are already exposed the moment they cross a network protected only by classical encryption. That’s why the U.S. Cybersecurity and Infrastructure Security Agency urges organizations to begin inventorying and migrating today (CISA Post-Quantum Cryptography Initiative).
What Changed in 2024–2026: The New Standards Are Now the Baseline
For years, “quantum-safe” was aspirational because there was no official standard to build toward. That ended in August 2024, when the National Institute of Standards and Technology published the first finalized post-quantum cryptographic standards after nearly a decade of global evaluation (NIST Post-Quantum Cryptography Project). Three of them now anchor every serious migration plan:
- FIPS 203 (ML-KEM) — a module-lattice key-encapsulation mechanism that protects the key exchange establishing secure sessions; the workhorse for network traffic (read FIPS 203).
- FIPS 204 (ML-DSA) — a lattice-based digital signature standard for authentication and code signing (read FIPS 204).
- FIPS 205 (SLH-DSA) — a stateless hash-based signature scheme that provides an algorithmically diverse backup, so the ecosystem doesn’t rest on lattice math alone.
NIST’s guidance is blunt: apply these standards now. Because rip-and-replace is never realistic at enterprise scale, migration is being deployed in a hybrid model — classical and post-quantum algorithms running together. The NIST National Cybersecurity Center of Excellence has published detailed crypto-agility guidance for exactly this transition (NCCoE Migration to PQC).
The 2026 Deadlines Bearing Down on U.S. Enterprises
A series of U.S. government mandates now sets the pace for the entire private sector, because vendors, contractors, and regulated industries inherit these requirements downstream:
- The White House Office of Management and Budget directed federal agencies to inventory cryptographic systems and build funded migration plans under memorandum M-23-02 (OMB Migration to PQC memo).
- The National Security Agency’s CNSA 2.0 suite sets aggressive adoption timelines for national security systems (NSA CNSA 2.0 requirements).
- The federal National Quantum Initiative continues to coordinate cross-agency security policy and workforce readiness (gov Technology Security).
If your organization sells to the government, operates in healthcare or financial services, or handles data with a long confidentiality horizon, these mandates are already your problem. Building this readiness into your enterprise IT infrastructure today is far cheaper than an emergency retrofit later.
Why Traditional SIEM and Network Security Aren’t Enough Anymore
Detection and encryption solve different halves of the problem. A traditional Security Information and Event Management platform is superb at spotting anomalies and flagging intrusions after an attacker is inside. But “harvest now, decrypt later” is a passive attack — the adversary may simply copy encrypted traffic at a peering point, generating no alert at all. You cannot detect your way out of a math problem.
The industry felt this shift acutely over the past year as the SIEM market consolidated and long-standing platforms reached end-of-support milestones. Even IBM’s own quantum-safe roadmap now treats cryptographic discovery and remediation as first-class disciplines alongside monitoring (IBM Quantum Safe). The lesson: next-generation network security has to protect data in transit at the cryptographic layer, not merely watch for break-ins after the fact.
What Quantum-Resistant Networking Actually Looks Like
1. Crypto-agility by design
Build infrastructure that can swap algorithms without ripping out hardware. Standards will keep evolving; your network should absorb those changes gracefully. This is the single most important design principle of a future-proof build.
2. Hybrid key exchange
Running a classical algorithm and a NIST post-quantum algorithm together keeps a connection secure even if one is later found weak. Major providers already deploy hybrids in production — Cloudflare, for example, moved post-quantum key agreement to general availability across dozens of products (Cloudflare: Post-Quantum Cryptography Goes GA).
3. A physically resilient backbone
Encryption protects the payload, but the transport layer matters too. Dedicated, privately controlled fiber shrinks the number of points where traffic can be quietly copied. That’s why dark fiber services and future-proof communications are core pillars of a quantum-resistant posture, not afterthoughts.
4. Quantum-safe cloud and hybrid environments
Workloads spread across public and private clouds multiply the number of key exchanges that need hardening. A private hybrid cloud architecture lets you apply consistent quantum-safe policy across environments instead of chasing gaps.
A Practical Five-Step Migration Roadmap for 2026
- Inventory your cryptography. Map every system, certificate, VPN, and application that uses public-key cryptography, and flag the data with the longest confidentiality lifespan first.
- Triage by risk and data longevity. Prioritize the long-lived, high-value secrets that “harvest now, decrypt later” targets.
- Deploy hybrid post-quantum cryptography. Start with your highest-risk links and roll out NIST-aligned hybrid key exchange, validating interoperability as you go.
- Harden the transport layer. Reduce exposure with dedicated fiber, segmented architecture, and monitored routes.
- Institutionalize crypto-agility. Ongoing managed IT services turn this from a one-time project into a durable capability.
Become Quantum-Ready with ibm/SEIMless
From cryptographic discovery to quantum-resistant fiber, cloud, and managed security, ibm/SEIMless designs enterprise networks built for the post-quantum era — with a single point of contact and a business-first, vendor-agnostic approach. Explore our security services. |
Frequently Asked Questions
Is the quantum threat real if quantum computers can’t break encryption yet?
Yes. The immediate risk is data theft, not decryption. Attackers harvest encrypted data now and decrypt it once quantum hardware matures, so any information that must remain secret for years is already at risk today.
What are FIPS 203, 204, and 205?
They are the first finalized U.S. post-quantum cryptography standards from NIST, covering quantum-safe key exchange (ML-KEM), digital signatures (ML-DSA), and a hash-based signature backup (SLH-DSA).
Does my business have to comply if we’re not a government agency?
Often, yes — indirectly. Federal mandates flow downstream to contractors, healthcare, financial services, and any vendor in a regulated supply chain.
How long does a post-quantum migration take?
For most enterprises it is a multi-year program, which is precisely why 2026 is the year to start.
The Bottom Line
Quantum-resistant networking has crossed the line from emerging trend to strategic necessity. The standards are finalized, the deadlines are real, and the “harvest now, decrypt later” threat is actively working against every organization still running purely classical encryption. To see how it fits your environment, learn more about ibm/SEIMless or start on our homepage.
Contact Us | Our Blog | See Previous Post | Our Services