Federal agencies do not need a standalone budget to fund post-quantum cryptography (PQC) migration. Dr. Garfield Jones argues in an opinion piece for MBT Magazine that PQC migration should be funded through existing Zero Trust and modernization programs rather than new budget lines.
The two efforts are complementary. Zero Trust, per NIST 800-207 or the CISA model, governs who and what can communicate. PQC ensures those communications resist future decryption. The prerequisites overlap: cryptographic inventory, certificate and key management, and centralized policy are ZT modernization tasks that also seed PQC readiness.
Executive Order 14412, signed June 22, 2026, sets binding deadlines for agencies and contractors to migrate high-value systems to post-quantum key establishment by December 31, 2030, and to post-quantum digital signatures by December 31, 2031. Those targets compress the prior NSM-10 government-wide goal of 2035 by four to five years. EO 14412 directs deployment of the NIST standards finalized in August 2024: FIPS 203, 204, and 205.
For security leaders, the practical payoff is sequencing. Treating crypto-agility as a Zero Trust workstream produces near-term deliverables, an enterprise cryptographic inventory, centralized crypto policy, and crypto-agile infrastructure, that map onto already-funded programs and show measurable progress before 2030.
One caveat: this is a bylined advocacy piece. Jones cites a “new industry consensus” placing a cryptographically relevant quantum computer at 2029, a figure single-sourced to the article. Treat it as his characterization, not a verified position.



Leave a Reply