Skip to main content

Quantum Readiness May Paradoxically Raise Contractor Risk

Written by: Jesse W. Lemon, Esq., CIPP/US, CIPP/E

On June 22, President Donald Trump issued two quantum technology executive orders that should be read as one strategy.

Executive Order No. 14413 on quantum innovation seeks to accelerate the deployment and commercialization of quantum computing, sensing and networking, while building the workforce, supply chains, institutions and partnerships needed for a domestic quantum ecosystem. Executive Order No. 14412 addresses the potential security consequences of that ambition by accelerating migration away from cryptographic systems that future quantum capabilities may compromise.

Together, the orders create an advance-and-defend strategy. The innovation order pushes quantum capability toward deployment, commercialization, and national-security application. The migration order pushes post-quantum cryptography into inventories, validation, procurement, disclosure control and demonstrable readiness.

Organizations must document cryptographic dependencies, migration barriers and readiness gaps to comply with the migration order. The resulting inventories, assessments, cryptographic bills of materials and migration plans may become the most complete description of an organization’s cryptographic weaknesses and dependencies. That is the quantum road map paradox.

The order sets governance deadlines and migration targets. Agencies have 30 days to designate post-quantum cryptography migration leads. The Office of Management and Budget is directed to issue guidance within 90 days.

The National Institute of Standards and Technology is directed to initiate a post-quantum cryptography migration pilot within 180 days and complete it by Dec. 31, 2027. The order also sets migration deadlines of 2030 for key establishment and 2031 for digital signatures.

The order also directs the Federal Acquisition Regulatory Council to propose rules requiring covered contractors to comply with post-quantum Federal Information Processing Standards by Dec. 31, 2030. In addition, it expands contractor disclosure obligations to include cryptographic weaknesses.

Together, these requirements place post-quantum readiness inside procurement, validation and market access rather than technical planning alone.

From Planning to Enforcement

The June 22 orders use different tools but serve a common strategy. The quantum innovation order updates the national quantum strategy, promotes deployment and commercialization, expands work on quantum sensing and networking, strengthens supply chains, develops the quantum workforce and increases protection of quantum technology against adversarial threats. The migration order addresses the other side of the equation by turning the cryptographic consequences of quantum capability into deadlines, inventories, validation requirements, procurement obligations and evidence of readiness.

Former President Joe Biden’s May 12 Executive Order No. 14028 launched the federal government’s push toward cybersecurity modernization and software supply chain security. NSM-10, issued in May 2022, identified quantum computing as a national security challenge and directed agencies to begin planning for migration. OMB Memorandum M-23-02, issued in November 2022, required agencies to inventory cryptographic assets and dependencies.

Executive Order Nos. 14144 and 14306, issued in January and June 2025, expanded the framework through additional software security, identity, artificial intelligence and post-quantum measures.

Trump’s migration order is the next step in that progression. It attaches deadlines, validation requirements, procurement obligations and measurable evidence to work that earlier directives largely required organizations only to identify, assess and plan.

The order converts prior planning into concrete market signals through deadlines, validation, procurement and evidence. As with Trump’s June 2 executive order on artificial intelligence, Executive Order No. 14409, the administration is relying on standards, procurement and market access rather than comprehensive licensing.

For contractors, that translates into operational obligations: They must know which products, systems, modules, vendors, certificates and algorithms they depend on; support their claims about post-quantum readiness; ensure their disclosure processes cover cryptographic weaknesses; and flow these requirements down to subcontractors.

Post-quantum cryptography refers to methods designed to resist attack by quantum computers. The concern is over the development of a cryptographically relevant quantum computer capable of breaking widely used public-key systems.

No one can fix the arrival date of such a machine, but the window has tightened. Several developments add urgency, including Microsoft’s progress developing its Majorana 2 quantum chip, IBM’s road map for realizing a fault-tolerant quantum computer by 2029, Google’s accelerated migration timeline, and new research reducing cryptographic resource estimates.

They do not establish a date certain for the arrival of Q-day, but explain why 2030 and 2031 are now planning dates, rather than distant aspirations.

The Road Map Problem

Walls fail at their thinnest point, gates at their weakest hinge and supply lines at their most exposed stretch. The innovation order may accelerate the quantum capabilities that will test existing defenses. The migration order requires agencies and contractors to identify and map the cryptographic dependencies that must be replaced before those defenses fail.

The common phrase for quantum risk is “harvest now, decrypt later.” Adversaries can collect encrypted data today and hold it until decryption becomes feasible, creating a long-tail risk for health data, financial records, trade secrets, diplomatic communications, defense technology, intelligence sources and authentication data.

Cryptography also underwrites identity, authentication, code signing, certificates, device validation, software updates and system integrity. If quantum computing degrades the signature and authentication security layer, the risk is not just exposure of old secrets but the erosion of trust itself and the ability to impersonate it.

Inventories are no longer optional: Agencies cannot migrate what they cannot find; contractors cannot make credible commitments without knowing their dependencies; boards cannot oversee risk without visibility.

The migration order’s cryptographic bill of materials, or CBOM, requirement sits at the center of that effort. A CBOM identifies cryptographic assets — including algorithms, protocols, libraries, modules, certificates, key management dependencies, validation status, vendor exposure, legacy systems, and migration barriers — and exposes where the walls are thin.

A software bill of materials shows components and supply-chain dependencies. A CBOM shows how identity, authentication, code signing, certificates and system integrity are protected. In the wrong hands, a CBOM is not just an inventory but a targeting map.

Controlled Transparency

The map is a necessity, but it cannot be handled like an ordinary compliance record.

Contractors should treat CBOMs, inventories, gap assessments, vendor responses and migration plans as sensitive security records, with access limits, contractual protections, privilege discipline and attention to whether materials qualify as controlled unclassified information, trade secrets, confidential business information or security-sensitive procurement information.

Routine compliance records are generally discoverable; copying counsel does not change that. The role of counsel is to structure governance, define the purpose of assessments, manage representations and limit unnecessary technical detail while preserving evidence of diligence.

Contractors will need to demonstrate their readiness to agencies, primes, insurers and customers without creating a consolidated index of weaknesses for adversaries or litigants. How the map is handled matters as much as what it shows.

A full CBOM may be the longer-term target, but companies should not wait for perfect tooling. A practical interim step is creating a quantum-exposure inventory.

Companies should identify the systems that matter most: long-lived sensitive data stores, identity infrastructure, certificate management, code signing, product security, operational technology, critical communications, federal-adjacent systems and vendor-managed cryptographic dependencies.

The National Security Systems Split

The migration order excludes national security systems from civilian review of high-value assets and high-impact systems, placing them on a separate track under the director of the National Security Agency, acting as national manager for national security systems through the Committee on National Security Systems.

Systems in the intelligence community, the military, and cryptologic programs, command-and-control environments, weapons systems and classified networks, operate under different authorities, threat models and mission tolerances, with distinct disclosure risks, acquisition pathways and architectures.

Civilian agencies and contractors on a second track will move through the OMB, the Cybersecurity and Infrastructure Security Agency, NIST, sector-risk management agencies, public guidance and the Federal Acquisition Regulation.

National security systems will move through the National Security Agency, the Committee on National Security Systems, and channels suited to classified and mission-sensitive environments.

Contractors supporting both tracks should expect different disclosure models, evidence burdens and limits on what can be shared, but not a lower standard of care.

National security systems are the more likely targets for capable adversaries, including those pursuing quantum advantage. The separation of civilian and national security systems therefore increases, rather than reduces, the need for post-quantum readiness.

Contractors cannot treat the national security system track as an area where visibility, discipline or migration can lag.

Cryptographic visibility is necessary in both tracks. The difference will not be whether the map exists, but how tightly it is controlled.

Two Migrations

The migration order separates key establishment from digital signatures. Key establishment protects the exchange of secrets and addresses the harvest-now, decrypt-later problem. Hybrid post-quantum key exchange is already appearing in parts of the internet stack.

Digital signatures are harder. They protect authenticity and integrity. They help prove that software, firmware, certificates, documents, devices or messages came from a trusted source and were not altered. If the signature layer fails, the risk may include forged software, false certificates, compromised updates and impersonated trust.

The signature track reaches certificate infrastructure, code-signing practices, device identity, firmware validation, software update pipelines, hardware security modules, legacy applications and vendor chains. It may involve longer dependencies and more brittle migration paths than encryption alone.

Contractors that sell software, devices, cloud services, security products or managed services to the government should not treat post-quantum readiness as a narrow encryption project.

Crypto-agility means the ability to replace algorithms, certificates, libraries, modules and vendor implementations without rebuilding systems. Contractors should build crypto-agility into their systems, contracts and vendor expectations now, because standards, threat estimates, product support and validation status will continue to change.

Validation and Procurement

Migration will turn on validated products that can be procured, deployed and certified at scale.

The migration order directs NIST to revise the Cryptographic Module Validation Program, a joint effort with the Canadian Center for Cybersecurity, to accelerate validation.

If agencies and contractors must rely on post-quantum modules validated under NIST’s Federal Information Processing Standards, migration will depend on validation capacity, product availability, vendor readiness and acquisition cycles. Standards move through products, contracts, budgets, testing, exceptions and replacement schedules.

A 2024 initial estimate from the OMB projected that migrating priority federal systems between 2025 and 2035 would cost roughly $7.1 billion. That number does resolve the operational questions: which systems will move first, which vendors can support the change, which products will be validated in time, which systems require replacement, and how agencies will fund work that crosses budget years.

Those constraints are the point. Even federal agencies operating under mandates, standards and central guidance face sequencing, dependency and funding limits. Contractors with legacy systems cannot wait for the market to settle. Planning, inventory, vendor diligence and claims discipline have become baseline requirements.

The New Reasonableness Baseline

The migration order is another marker on the timeline against which regulators, contracting authorities, insurers, courts and boards may eventually assess when a sophisticated organization should have begun preparing for post-quantum risk.

For large, sophisticated enterprises, that timeline will likely track the federal government’s benchmarks.

Major cloud providers, defense contractors, telecom carriers, hospital systems, banks, utilities, data brokers, software vendors and other critical infrastructure operators cannot treat quantum risk as remote.

Organizations holding long-lived sensitive data must account for harvest-now, decrypt-later risk. Those that sign code, manage identity, issue certificates, run operational technology, support federal agencies or sell security products cannot wait until 2030 to locate and assess their cryptography.

For federal contractors, post-quantum readiness will become a condition of market access through the FAR process. They will need to assess whether their products rely on non-FIPS algorithms, whether vendors can support migration, whether disclosure programs cover cryptographic weaknesses, whether subcontractors can answer the same questions and whether public quantum-ready claims can be substantiated.

Even where not formally bound, sophisticated organizations will be measured against the federal timeline. If agencies are appointing migration leads now, receiving OMB guidance within 90 days, building CBOM guidance within 270 days, piloting by 2027, and working toward 2030 and 2031 deadlines, large enterprises should be able to explain their own schedules.

They need not mirror each step, but they need a defensible analog: ownership, inventory, risk ranking, vendor engagement, budget planning, board visibility and a migration path for the systems that matter most.

What Companies Should Do Now

For contractors and federal-adjacent companies, the sequence begins with identifying who owns their quantum risk. Quantum risk spans legal, security, product, procurement, vendor management, engineering, compliance and the board. A company without a clear owner will not build a credible timeline.

The next step is visibility. Contractors should begin with high-value and long-lived data, identity systems, code-signing infrastructure, certificate management, operational technology, regulated systems, federal work, and products or services sold into sensitive sectors.

A quantum-exposure inventory is enough to start, provided it leads to more precise cryptographic mapping.

Vendor management should begin early. Many companies will not control their own migration and will depend on cloud providers, software vendors, managed service providers, certificate authorities, device manufacturers and security vendors.

Procurement teams should ask when vendors will support NIST-standardized post-quantum algorithms, whether products rely on validated modules, whether hybrid approaches are available, and how authentication and signature systems will be handled.

Companies should discipline their claims. “Quantum safe” and “post-quantum ready” are attractive phrases but create litigation and regulatory risk if they outrun the facts. Readiness should be defined by scope — which systems, algorithms, vendors, functions, dates — and supporting evidence.

Finally, companies should protect their road map. CBOMs, inventories, gap assessments, vendor responses and migration plans should carry access controls, contractual protections and document discipline before these become the subject of an incident, audit, diligence request or subpoena.

The migration order converts post-quantum risk into a governance expectation. Procurement will enforce much of that expectation before courts or Congress do. The organizations best positioned for the 2030 and 2031 deadlines will be those that can identify their cryptographic dependencies, demonstrate a migration path and protect the road map they created along the way.

Data Breach Lawyer, Data Security Law Firm, Privacy Law Firm, Cryptocurrency Law Firm & Data Due Diligence Law Firm in Buffalo, NY

Data Breach Lawyer in Buffalo, NY | Privacy Law Firm

Privacy Law FirmData Breach LawyerData Security Law FirmData Due Diligence Law FirmIncident Response Consultant ∴ Buffalo, NY

Buffalo, NY