In August 2024, the U.S. National Institute of Standards and Technology (NIST) published its first three post-quantum cryptography standards: ML-KEM, ML-DSA, and SLH-DSA, formerly CRYSTALS-Kyber, CRYSTALS-Dilithium, and SPHINCS+. A few weeks later, the Commerce Department’s Bureau of Industry and Security added quantum computing items to the Export Administration Regulations, in a rule written to align with controls in allied countries. Neither act was dramatic and both were expected. Together they describe what quantum sovereignty means for an organization with no plans to build a quantum computer. The algorithms you deploy and the hardware your suppliers ship are now shaped by policy as much as by engineering.
What follows is the short version, written for the people who sign procurement contracts and approve architectures rather than the people who write national strategies.
What sovereignty actually asks
We use a narrow definition in our teaching, because the broad one turns into a slogan within a paragraph. Quantum sovereignty asks whether a country or an organization can build, operate, and trust the quantum capabilities it depends on under geopolitical stress, without being cut off from something it can’t replace. Domestic manufacture is one answer to that question. It’s rarely the cheapest, and across most of the stack it isn’t available at any price.
Nobody is fully sovereign and nobody is fully dependent. The United States and China come closest to full-stack capability, and both still import. Everyone else, including every enterprise, holds a portfolio of dependencies and decides which ones are tolerable.
The six levers
Governments use six instruments to draw the boundary, and the first four already affect commercial buyers who have nothing to do with national policy.
- Export controls. These now cover deemed exports, meaning the release of controlled technical data to a foreign national inside your own borders, treated in law as an export to that person’s country of nationality. For a lab, that turns hiring and conference talks into licensing questions. The precedent is semiconductors, where an October 2022 U.S. rule moved a class of commercial equipment into controlled status in a single publication. Quantum items followed two years later.
- Supply chain chokepoints. A chokepoint is a supply node with few enough qualified suppliers that one government decision can stop the flow. Quantum hardware has several, including dilution refrigerators, isotopically enriched materials, precision lasers, photonic foundry capacity, and cryogenic cabling. Helium-3, used in dilution refrigeration, comes from tritium decay held in a small number of national stockpiles, so no amount of industrial policy creates a domestic source.
- Capital. Investment screening now names quantum explicitly. The United Kingdom’s National Security and Investment Act 2021 lists quantum technologies among the sensitive areas requiring mandatory notification of qualifying acquisitions, the United States reviews transactions through the Committee on Foreign Investment in the United States, or CFIUS, and the European Union coordinates member state reviews under its foreign direct investment screening regulation. Ownership, board composition, and licensing terms are all reviewable.
- People. Trained physicists and engineers are scarcer than any material input. Visa policy, research security programs, and deemed-export rules applied to lab staff now decide where the work happens and who is allowed to do it.
- Intelligence. Quantum intellectual property is an active collection target, and the organizations holding it are often startups and university groups with no security function at all. Research security guidance exists in most allied countries and adoption is uneven.
- Alliances. The trilateral security partnership between Australia, the United Kingdom, and the United States (AUKUS) names quantum technologies among its advanced capability areas, and bilateral agreements do similar work elsewhere. Pooling converts partial national capability into collective capability, and it creates a dependency on the partner that behaves like any other dependency.
Three architecture decisions this changes
Which algorithms you support
The NIST standards are not the only ones being deployed. Germany’s Federal Office for Information Security (BSI) recommends FrodoKEM and Classic McEliece in its technical guidelines, France’s National Cybersecurity Agency (ANSSI) has pushed hybrid deployment of classical and post-quantum algorithms through the transition period, and other regulators are setting national parameters on top of international standards. A product sold into more than one bloc may need to support more than one suite, and the certification story differs by jurisdiction. Crypto-agility – the ability to change algorithm, key size, or protocol without redesigning the system – stops being an architectural preference at that point and becomes a market-access requirement.
Where your quantum compute runs
Almost all enterprise access to quantum hardware runs through a cloud service, and that access is a policy variable as much as a commercial one. Several governments are funding national or regional quantum computing facilities for exactly this reason. For a buyer the practical questions are narrow. Which jurisdiction governs the service, what happens to queued and stored workloads if access is restricted, and how long would a move to another provider take?
Timing and sensing dependencies
Quantum sensing will reach operational use before quantum computing does. Atomic clocks, gravimeters, magnetometers, and inertial units support navigation where GPS is jammed or spoofed, and precise timing underpins financial settlement and telecom synchronization. An organization that depends on a single foreign source for timing hardware has a supply exposure with the same shape as any other, and most have never assessed it.
Optionality over autarky
The realistic goal is the same for a state and for an enterprise, and it has nothing to do with self-sufficiency. What counts is the ability to swap a dependency faster than that dependency can do damage. Four moves make that possible.
Inventory before strategy. You can’t renegotiate a dependency you haven’t recorded. A cryptographic bill of materials, or CBOM, lists the algorithms, key sizes, certificates, and libraries in use and identifies where each one runs. The same discipline applies to hardware suppliers and cloud services, and in most organizations neither list exists yet.
Design for substitution. Open interfaces, negotiated algorithms, and key management that rotates keys without a redesign all lower the cost of a future swap. Every proprietary interface raises it.
Second-source what can be second-sourced. Some chokepoints have real alternatives and mapping them takes about a week. Others have none, and helium-3 is one of them. Naming the irreducible dependencies honestly is more useful than a plan to eliminate all of them.
Contract for change of law. Export-control and sanctions clauses, notice periods, design escrow where it makes sense, and continuity terms that still apply after a supplier changes ownership.
Then run the test. Three scenarios cover most of the exposure. A hardware supplier falls under a new control regime, an algorithm in your stack is withdrawn or weakened, and a cloud provider restricts access for reasons that have nothing to do with you. For each one the answer is a number. How long to recover, and what does it cost?
Most sovereignty strategy documents stop at ambition. The decisions that determine sovereignty are made in procurement contracts, interface specifications, and key management design, usually by engineers who were never shown the strategy. Architects and buyers are the ones who close that gap.
Where to start
For most security teams, sovereignty reduces to three ordinary questions. Can we change our algorithms without running a project? Do we know who owns our suppliers? What breaks if a service we use becomes unavailable for policy reasons? A team that can answer those three has more sovereignty than one with a national strategy and no inventory.
The full series, running to sixteen parts, is on PostQuantum.com. The migration methodology behind the crypto-agility work is at pqcframework.org. And if your team needs the structured version, with the export-control, procurement, and crypto-agility material in one program, that’s what we teach at Quantum Academy.