The board’s PQC clock just moved up: why post-quantum migration is a 2026 governance item

Board-ready intelligence on AI law · Quantum governance · Post-quantum transition
NIST finalized the first PQC standards in 2024. For boards, the migration clock is already running.

Quantum governance · Quentir Intelligence

NIST finalized the first PQC standards in 2024. For boards, the migration clock is already running.

Published by Quentir Systems LLC · June 2026 · 7 min read

Post-quantum cryptography stopped being a future concern in 2024. When NIST finalized its first PQC standards — FIPS 203, 204, and 205 — the transition from research to regulatory expectation was complete. For boards, the question shifted permanently: not whether to address quantum-era cryptography, but by when, on what assets, and through whom.

Board takeaway. The 2026 governance task is not to predict the exact date of a cryptographically relevant quantum computer. It is to make sure management can show where quantum-vulnerable cryptography sits, which data would still matter after 2030, and which migration dependencies sit outside the organization’s direct control.

This is published intelligence, built to inform your own decisions. Claims are tied to named instruments, with sources and dates below.

What changed in 2024

The National Institute of Standards and Technology published the first finalized post-quantum cryptographic standards in August 2024: FIPS 203 (ML-KEM, based on CRYSTALS-Kyber), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, based on SPHINCS+). These are not draft guidance — they are operative standards against which U.S. federal requirements will be assessed and against which international regulators are already aligning.

The U.S. National Security Agency's CNSA 2.0 suite, published in 2022 and updated through 2024, sets migration calendars for national security systems: most systems adopting PQC algorithms by 2030, full completion by 2035. These dates are now active reference points in procurement, audit, and regulatory dialogue across public and private sectors alike.

Snapshot (NIST): FIPS 203/204/205 finalized August 2024. These are operative standards, not drafts. Source: nist.gov/pqcrypto. Published: June 14, 2026.

The threat that reframes the timeline

The reason PQC migration matters now — before large-scale quantum computers exist — is the harvest-now-decrypt-later (HNDL) threat. An adversary with the capability and motive can capture encrypted network traffic or stored data today, at low cost, and hold it against the day when a cryptographically relevant quantum computer can decrypt it.

That reframes the risk from a future engineering event to a present data-handling decision. Data with a long confidentiality life — financial records, legal communications, medical information, trade secrets, state-level sensitive data — is already at risk under HNDL if it is protected only by quantum-vulnerable algorithms such as RSA or elliptic-curve cryptography. The exposure is not hypothetical; it is a function of what is being captured now and how long it must stay confidential.

This is why migration sequencing matters: not all data deserves the same urgency. A cryptographic inventory, ranked by data shelf-life and sensitivity, is the starting point for rational board oversight — not a general mandate to upgrade everything simultaneously.

The regulatory overlay

Several instruments now create obligations with dates boards can be held to:

CNSA 2.0 (NSA, United States): Adoption timelines for national security systems; private-sector organizations operating in the defense industrial base, financial infrastructure, or critical sectors are expected to align. The 2030 and 2035 milestones are the most-cited reference points in board-level discussion.

NIS2 Directive (EU, operative October 2024): Mandates appropriate technical and organizational security measures for covered entities across critical infrastructure, digital services, and supply chains. Because "appropriate" is read against the current state of the art, cryptographic-migration readiness is increasingly part of how that standard is discussed for entities handling sensitive data or operating long-lived systems.

DORA (EU, applicable from January 2025): Requires financial entities to manage ICT risk, including cryptographic risk, with documented policies. Cryptographic-agility and PQC readiness are increasingly raised within ICT-risk management and audit discussions for significant financial institutions.

EU coordinated PQC roadmap (ENISA/NIS Cooperation Group): The EU's coordinated approach aligns with NIST finalization and sets expectations for member-state critical infrastructure operators. Sector-specific guidance is being developed through 2025–2026.

What a board should be able to answer

Board oversight of PQC migration does not require deep cryptographic expertise. It requires asking the right questions of management — and receiving substantive, documented answers.

Where is quantum-vulnerable cryptography in our stack? RSA and ECC are the primary algorithms at risk. They appear in TLS, PKI, code signing, VPN, email encryption, authentication, and data-at-rest protection. A meaningful answer names the systems, not just the algorithm families.

Which of our data has a shelf-life that outlasts the migration window? This is the prioritization question. Long-lived sensitive data — patient records, legal files, trade secrets, financial instruments with multi-decade enforcement lives — is at higher risk under HNDL than short-lived operational data.

What is our phased, time-stamped roadmap to 2030 and 2035, and who is accountable? A credible answer includes a named owner, at least three phases (inventory → hybrid transition → full PQC), and explicit milestone dates tied to the regulatory calendar.

Board oversight does not require cryptographic expertise. It requires the three questions above to have substantive, documented answers — and a named owner accountable for each milestone.

A 2026 board agenda.

  1. Q3 2026: assign an accountable owner for cryptographic inventory and define the first estate to be mapped.
  2. Q4 2026: identify long-lived sensitive data, critical certificates, identity systems, vendor-controlled platforms, and systems with unusual replacement cycles.
  3. 2027: pilot migration paths on bounded systems, including hybrid or PQC-ready options where vendor support permits.
  4. 2028–2030: move priority systems in a sequence that reflects data shelf-life, operational dependency, and regulatory exposure.
  5. 2030–2035: complete residual migration, retire exceptions, and keep the board record current as standards and vendor support mature.

This sequence is deliberately inventory-first. It gives directors something auditable to oversee without pretending that every system should move on the same day.

What not to do. Do not wait for a perfect quantum-computer forecast. Do not treat a vendor’s general “quantum safe” statement as a migration plan. Do not ignore archives, backups, firmware, certificates, identity infrastructure, or third-party transfer paths. And do not start with a universal upgrade mandate if the organization has not yet ranked data by confidentiality shelf-life. The board record should show prioritization, not panic.

The first 90 days

The practical first 90 days should be disciplined: appoint an accountable owner, inventory RSA and ECC usage, classify long-lived sensitive data, map vendor-controlled migration points, set a PQC roadmap and open an exception register. That sequence gives the board a way to oversee migration without pretending that every system can be changed at once.

How Quentir reads it

Quentir's PQC Migration Roadmap for Boards, 2026 maps the threat-and-standards landscape, the inventory-and-prioritization method, and a four-phase dated roadmap aligned to the regulatory calendar — every claim tied to a named instrument with a dated source record. It is published intelligence, identical for every reader, built to inform your own decisions.

Quentir resource. This is the gap The PQC Migration Roadmap for Boards, 2026 is built for: not a general explanation of quantum computing, but an inventory-first board sequence with dated milestones, source-backed obligations, and the questions management should be able to answer.

Sources: NIST Post-Quantum Cryptography project; NIST FIPS 203, FIPS 204, and FIPS 205 (Aug 2024); NSA CNSA 2.0 (2022, updated 2024); OMB M-23-02; EU NIS2 Directive; EU DORA; ENISA/NIS CG coordinated PQC roadmap. Published: June 14, 2026.

Board-ready PQC migration roadmap

Use the roadmap to turn inventory, long-lived data, vendor dependencies, and the 2030/2035 calendar into an overseen sequence.

What the paid edition adds. The PQC Migration Roadmap for Boards — a Quentir Signature Report — goes where a post cannot: four time-bound migration phases through 2035, ten oversight questions for the board pack, the full standards and regulatory calendar, and named refresh triggers, in a citable document with a dated evidence spine under a single-organization internal-use license. Every Signature Brief and Signature Report, plus the full archive, is also included in the All-access membership.

This analysis is published intelligence produced by Quentir Systems LLC. It does not constitute legal advice and creates no advisory or client relationship. Consult qualified legal counsel for advice specific to your organization’s situation and jurisdiction.

© 2026 Quentir Systems LLC
Previous
Previous

Long-lived data, quantum risk: harvest-now-decrypt-later in biomedical research