Which US Federal Post-Quantum Deadline Binds You
Federal post-quantum policy now sets dates, not intentions. Five June 2026 documents assign different deadlines to different system classes. Here is how to find…
Archive
Federal post-quantum policy now sets dates, not intentions. Five June 2026 documents assign different deadlines to different system classes. Here is how to find…
Regulators require an inventory of cryptography your suppliers are not obliged to disclose. Four governance artifacts that close the gap and keep third-party PQC…
Reporting lines say little about what a CISO controls. Who leads post-quantum migration depends on where the cryptographic estate sits and on decision rights…
CNSA 2.0 is the one post-quantum directive written like a control rather than a goal: named algorithms, fixed parameter levels, dated procurement gates. A…
A technical question deserves a technical answer. When a quantum security vendor substitutes something else, the substitution is your finding. A field guide to…
NIST IR 8547 is usually reduced to 2035. It sets two dates, and the earlier one is already shaping procurement and risk acceptance decisions.
European post-quantum regulation rarely says "deploy PQC by date X." It says produce the file. Here is what that file contains, and what your…
Statutes, executive orders, OMB memoranda, federal standards, acquisition rules and standard of care all bind differently. A field guide to sorting them, with three…
Most organisations will rent quantum access, not own it. Six control points decide how much sovereignty survives the contract, and each one is negotiable.
Since September 2024, a screen share with a foreign colleague can require a US export license. What deemed export rules mean for quantum teams,…