The US National Security Agency (NSA) has launched a post-quantum cryptography resource hub to help national security organisations and defence suppliers prepare for a fundamental change in how digital information and trusted systems are protected.
Announced on 1 October 2026, the initiative brings together educational material and implementation resources intended to support the transition to cryptographic algorithms designed to withstand attacks from sufficiently powerful quantum computers. TheNSA’s resource hubis aimed primarily at National Security Systems and the defence industrial base, with explainers, technical guidance and white papers addressing the transition.
Its significance extends beyond its immediate audience. Read alongside guidance from the US National Institute of Standards and Technology and the UK’s National Cyber Security Centre, the initiative highlights a challenge that will reach across government, financial services, healthcare, telecommunications and other sectors: replacing vulnerable cryptography without disrupting the services that depend on it.
National Security Timelines Bring Procurement Into Focus
In itslaunch announcement, the NSA says that, under Committee on National Security Systems Policy 15, new commercial National Security Systems must be capable of supporting quantum-resistant algorithms from 2027. It also says legacy systems unable to support quantum-resilient algorithms are to be phased out by 2030.
Those statements concern the national security environment described by the agency. They should not be read as a blanket deadline requiring every private business to replace every cryptographic system by 2030.
Nevertheless, the procurement implication for affected organisations is immediate. Whether equipment can support the required algorithms becomes a question for purchasing and lifecycle planning, rather than something to revisit only when quantum attacks become practical.
The NSA also identifies authentication as a concern alongside confidentiality, warning that future quantum capabilities could threaten the mechanisms used to establish trust in users and systems. That expands the transition beyond the familiar task of protecting information from interception.
Why Quantum Computing Changes the Security Equation
The central issue is the mathematical foundation of widely used public-key cryptography. Systems such as RSA and elliptic-curve cryptography underpin secure communications and authentication because the relevant mathematical problems are prohibitively difficult for conventional computers to solve at appropriate security parameters.
A sufficiently capable quantum computer would change that calculation. TheNSA’s accompanying primerexplains the threat to systems built on integer factorisation and discrete logarithms, and introduces alternative approaches based on lattices and hash functions.
Post-quantum cryptography changes the algorithms used for these security functions. It does not require organisations to buy quantum computers. AsNIST explains, the objective is to develop defences against attacks from both conventional computers and future quantum machines.
The distinction is important: this is preparation for a particular cryptographic capability, not evidence that every quantum computer can already defeat operational encryption. The security question is whether organisations can complete a complex migration before the relevant capability becomes available to an adversary.
Sensitive Information Can Be Exposed Before It Is Decrypted
One reason governments are urging early action is that an attacker does not necessarily need to decrypt information at the time it is stolen.
In itsexplanation of the quantum threat, the NSA describes a strategy in which adversaries collect encrypted information, retain it and attempt to decrypt it when more powerful capabilities become available. This is commonly called “harvest now, decrypt later”.
The risk is particularly relevant to information that must remain confidential for many years. A stolen encrypted record may retain <a href="https://bitcomme.com/promising-artificial-intelligence-stocks-to-add-to-your-watchlist/” title=”Promising Artificial Intelligence Stocks To Add to Your Watchlist”>intelligence or commercial value long after the system that originally transmitted it has been replaced.
The practical implication is that future migration cannot retroactively protect copies already captured under vulnerable cryptographic arrangements. Security planning therefore needs to consider how long information must remain secret, alongside how long migration will take.
This creates a different prioritisation problem from ordinary patch management. The most urgent assets may include information with a long confidentiality requirement, even when the systems handling it are functioning normally and show no signs of an immediate breach.
Digital Trust Faces a Separate Transition
Confidentiality is only part of the problem. Digital signatures help systems decide whether software, identities and other digital objects should be trusted.
NIST’spost-quantum migration projectexplicitly includes identity certificates for devices and users, code signatures, identity verification and quantum-resistant key exchanges. These functions serve different purposes and cannot be treated as one interchangeable encryption feature.
An organisation could therefore make progress protecting a communications channel while still depending on vulnerable signature mechanisms elsewhere. A successful pilot in one service is evidence of progress, but it does not establish that the wider organisation has completed migration.
For executives, this means a readiness report needs to explain which security functions have changed and which dependencies remain. A simple claim that a platform “supports post-quantum cryptography” offers too little information to assess the organisation’s actual exposure.
NIST Standards Provide a Basis for Implementation
The transition already has an established technical foundation. In August 2024,NIST finalised its first three post-quantum cryptography standards, following years of international evaluation.
FIPS 203 specifies ML-KEM, a key-encapsulation mechanism used to establish a shared secret that can support encrypted communications. FIPS 204 specifies ML-DSA for digital signatures. FIPS 205 specifies SLH-DSA, a digital-signature approach based on hash functions rather than the lattice-based approach used by ML-DSA.
These distinctions matter when evaluating products. Support for a key-establishment algorithm does not automatically provide post-quantum digital signatures, and the presence of an algorithm in a library does not establish that every service using that library has adopted it.
NIST’s message at the standards’ release was that organisations should begin integration because deployment takes time. The availability of standards moves the conversation towards implementation, compatibility and product assurance, while leaving organisations responsible for selecting the appropriate mechanisms for their systems.
Additional Algorithms Reinforce the Need for Flexibility
The standards effort also recognises that cryptographic confidence must be maintained over time.
In March 2025,NIST selected HQC for standardisationas an alternative based on a different mathematical approach from ML-KEM. HQC uses error-correcting codes, providing diversity in case weaknesses emerge in the approach underpinning the primary key-establishment standard.
NIST described HQC as a backup rather than a replacement for ML-KEM and urged organisations to continue migrating to the standards finalised in 2024.
The wider lesson is that migration should leave systems easier to update again. Treating one algorithm as a permanent solution risks recreating the inflexibility that makes the current transition difficult. Organisations need a way to change approved cryptographic mechanisms as standards, implementations and the understanding of threats develop.
Discovery and Supplier Engagement Come First
The operational challenge begins with understanding where cryptography is used.
Ajoint advisory from CISA, NIST and the NSAset out the preparation required in 2023: establish a roadmap, engage technology vendors, inventory cryptographic systems and prioritise sensitive and critical assets.
These steps turn a broad concern into an actionable programme. A useful inventory needs to connect cryptographic dependencies to the services they support and the information they protect. Without that connection, a list of algorithms offers little help in deciding what should change first.
Supplier discussions also need to move beyond general promises. Organisations can ask which product versions will support the required capabilities, whether hardware replacement is necessary, how compatibility will be tested and what support will remain available during migration. These are practical procurement questions arising from the agencies’ emphasis on vendor engagement and prioritisation.
NIST’s migration project reinforces the importance of testing: its work includes identifying compatibility problems in controlled environments before organisations encounter them in production. That approach connects algorithm adoption to the reliability of real services.
The UK Sets Out a Staged Path to 2035
TheUK NCSC’s migration guidanceoffers a broader organisational timetable, particularly for large organisations, critical infrastructure operators and businesses with bespoke technology.
These dates structure the work; they are not a prediction that a cryptographically relevant quantum computer will arrive in a particular year.
The NCSC also distinguishes organisations running complex infrastructure from smaller businesses relying mainly on commodity technology. Many smaller organisations will depend heavily on updates from their service and software suppliers, while bespoke systems require more direct planning.
For multinational organisations, the implication is to map requirements to the relevant systems and jurisdictions. A UK planning target and a US national security requirement have different scopes, even when they contribute to the same overall transition.
Post-Quantum Cryptography Is Different From Quantum Key Distribution
The NSA’s hub also draws attention to the distinction between post-quantum algorithms and technologies marketed around quantum communications.
In itspublished position on quantum key distribution, the agency identifies limitations including specialist equipment requirements, authentication dependencies, infrastructure costs and implementation challenges. It does not recommend QKD or quantum cryptography for protecting National Security Systems unless those limitations are overcome.
Post-quantum algorithms, by contrast, are intended for implementation on conventional computing platforms. Their purpose is to provide quantum-resistant security through different mathematical constructions.
For buyers, the distinction matters because a product described as “quantum” does not necessarily address the organisation’s migration requirements. Technology selection must be tied to the security function being protected, the relevant standards and the environment in which it will operate.
An Organisational Programme With Long-Term Consequences
Taken together, the NSA’s new resources and the wider guidance point towards a transition that reaches well beyond specialist cryptography teams. Procurement determines what can be upgraded. Service owners understand operational dependencies. Security teams assess exposure. Senior leadership controls funding and accountability.
The management implication is to measure progress through concrete outcomes: knowing which critical services depend on vulnerable cryptography, identifying their migration paths, securing supplier commitments and testing changes before deployment.
The hub gives national security stakeholders another starting point for that work. Its broader message is that the time required to discover, replace and validate cryptographic dependencies is itself a security consideration. Organisations that begin those preparations early have more opportunity to integrate the transition into planned upgrades and avoid concentrating difficult decisions into a last-minute response.