The 2026 federal post-quantum mandate: what boards should ask now
Quantum governance Henry Quentir Quantum governance Henry Quentir

The 2026 federal post-quantum mandate: what boards should ask now

The 2026 federal post-quantum mandate gives boards a concrete governance question: can the organization identify where quantum-vulnerable cryptography sits, which data must remain confidential for years, who owns migration, and which vendors control the systems that will need rotation? The mandate does not make every private company a federal agency, but it changes the reference point for procurement, audit and supplier-risk conversations.

This foundational Quentir brief explains why boards should treat post-quantum cryptography as a management system rather than a research watch item. It connects the federal policy signal to NIST FIPS 203, FIPS 204 and FIPS 205, long-lived confidential data, cryptographic inventory, vendor dependency, migration ownership and exception tracking. The article is the baseline for the broader Quentir PQC cluster: separate briefs address contractor evidence, biomedical harvest-now-decrypt-later exposure and board-clock sequencing. The practical board packet should be dated, source-bound and modest: inventory what depends on RSA and ECC, classify long-lived data, map supplier-controlled systems, name the accountable owner, test a rotation path and record what cannot yet be migrated.

Read More
Long-lived data, quantum risk: harvest-now-decrypt-later in biomedical research
Quantum governance Henry Quentir Quantum governance Henry Quentir

Long-lived data, quantum risk: harvest-now-decrypt-later in biomedical research

Harvest-now-decrypt-later risk is especially serious in biomedical research because the harm is not limited to one patient record. Genomic data, clinical trial archives, tissue-linked datasets and family-line identifiers can remain sensitive for decades, and disclosure may affect relatives, communities and future research trust long after the original security decision was made.

This Quentir brief reads post-quantum migration through a biomedical ethics lens. It explains why long-lived biomedical data should be prioritized by confidentiality lifespan, identifiability, consent expectations, vendor dependency and re-identification risk. The practical question is not whether cryptographically relevant quantum computers exist today. It is whether today’s encrypted archives will still matter when they do, and whether the institution can show that it identified the datasets whose confidentiality obligations outlast the current cryptographic stack. The article points boards, research leaders, data protection officers, ethics committees and security teams toward a dataset-level evidence packet: shelf-life register, consent compatibility review, vendor encryption map, PQC migration owner, exception log and review cadence. That is the bridge between quantum governance, biomedical trust and practical information security.

Read More
The board’s PQC clock just moved up: why post-quantum migration is a 2026 governance item
Quantum governance Henry Quentir Quantum governance Henry Quentir

The board’s PQC clock just moved up: why post-quantum migration is a 2026 governance item

The board’s PQC clock is now a governance timeline, not a distant technical curiosity. NIST has finalized the first post-quantum standards, public-sector migration expectations are becoming more concrete, and organizations with long-lived confidential data need to understand where RSA and elliptic-curve cryptography still sit before procurement, audit and renewal cycles force rushed decisions.

This Quentir brief is the general board primer for post-quantum migration. It explains why cryptographic inventory is the first management task, why harvest-now-decrypt-later risk matters for data with long confidentiality value, and why vendor-controlled systems can slow migration even when internal security teams are ready. The article connects NIST standards, national-security timelines, European cyber-resilience expectations and practical board governance into a first 90-day sequence: appoint an accountable owner, inventory RSA/ECC usage, classify long-lived sensitive data, map supplier dependencies, set a roadmap and maintain an exception register. Related Quentir posts go deeper on contractor evidence and sector-specific biomedical risk; this piece gives directors and executive teams the starting point for asking the right questions now.

Read More