Cloudflare's 2029 Target, HPE's 24 to 48 Months, Dell's 1.2 Million Old Servers and QuSecure's Vendor-Reported TRL 7: Four Post-Quantum Clocks Against EO 14412's 2030 and 2031 Deadlines
Four companies put dates and numbers on the post-quantum migration in the first week of September 2026, and none of them is a government. Cloudflare's roadmap, restated in the German trade press on 4 September, targets completion in 2029; HPE told enterprises on 4 September to plan on 24 to 48 months; Dell told investors on 1 September that 1.2 million of its installed servers are old enough that customers are refreshing them, with security requirements among the reasons; and QuSecure reported on 2 September that its platform ran under soldier operation at a US Army exercise and, by the company's reading, reached Technology Readiness Level 7. Read against Executive Order 14412's 2030 and 2031 federal deadlines, the four give a program office something the policy documents do not: the pace at which suppliers say they can move, and the size of the installed base that has to be carried along.
The four announcements measure different things. Cloudflare's is a post-quantum roadmap with dated milestones, the first of which it has announced support for. HPE's is a lead-time estimate for a large enterprise. Dell's is a count of hardware that customers are replacing whatever the cryptography does. QuSecure's is a readiness level reported by the company from a field exercise. This Monitor reads each one for what it can support, then sets all four beside the federal calendar and beside what the founder of this site wrote about lead times in War on the Rocks in July.
ASD's LATICE Guidance of 20 July 2026 and the NCSC's Workshop Report of 22 July 2026 Both Start With the Cryptographic Inventory, and the EU's End-2030 Date Leaves Little Time to Build One
Three post-quantum migration documents surfaced together on 4 September 2026: the Australian Signals Directorate's LATICE guidance of 20 July, the UK NCSC's report of 22 July on its first industry migration workshop, and an Italian reading of the EU roadmap that sets the end of 2030 for critical infrastructure. ASD and the NCSC both begin with a cryptographic inventory, which ASD says should be started in partial form and maintained over time. The NCSC gives large organizations two to three years for that discovery phase against its 2028, 2031 and 2035 dates, and its workshop found that supplier readiness decides whether a plan can be kept. This Monitor reads what the documents let a program office refuse, and what an inventory cannot answer.