All posts

PQC Basics · Part 4 of 10

Post-Quantum Cryptography Deadlines: Why 2026 Changed the Timeline

August 20, 2026 ·  PQCClear  ·  6 minute read

Last post, a sample encryption entry carried a quiet flag: vulnerable to a sufficiently advanced quantum computer. Here's what that actually means, why it isn't happening today, and why organizations are being asked to act anyway.

Nobody's Encryption Is Broken Today

Nobody’s encryption is broken today. That’s the first thing to get straight, because the topic gets talked about in a way that makes it sound otherwise.

A lot of the encryption protecting things right now, including the login example from last post, relies on a specific kind of math problem. Multiplying two enormous numbers together is easy for a computer. Taking the result and working backward to find the two original numbers is, for a computer as we know it today, effectively impossible. Not “difficult.” Impossible in any practical sense, the kind of impossible where the calculation would still be running long after every computer on Earth wore out.

That one-way difficulty is the actual foundation a huge amount of encryption is built on. As long as working backward stays impossible, the encryption holds.

What a Quantum Computer Changes

So Why Act Before It's Real?

Two reasons, and they compound each other.

First: swapping out encryption across a real organization is slow, often measured in years rather than months. It touches software written by people who’ve long since moved on, systems nobody wants to risk breaking, and vendors who have to move on their own schedule too. Waiting until the risk is imminent means starting a multi-year project after the deadline has already effectively passed.

Second, and this is the one that actually creates urgency today: some encrypted data doesn’t need to be broken the moment it’s sent. It needs to be broken while it still matters. Financial records, health data, and long-retained files are valuable for years after they’re created. Data like that could be copied and stored now, unreadable today, and decrypted later once the right tool exists. We’ll spend a full post on exactly this next act, since it’s the single idea that turns this from “someday” into “now.”

What Actually Changed in 2026

The math risk itself isn’t new. What changed recently is that the response to it moved from recommended to required, and it happened fast.

  1. Aug 2024

    Official replacements finalized

    The U.S. standards body responsible for this kind of thing (NIST) finalized the new generation of encryption methods designed to resist this exact risk. Before this, organizations had nothing official to migrate toward. After it, they did.

  2. Jun 2026

    Deadlines attached, for the first time

    Within the same eight-day stretch, a presidential executive order and detailed federal guidance both set real, dated timelines for migrating away from the vulnerable methods. This is the moment “recommended” became “on the clock,” at least for federal systems.

  3. TodayYou are here

    The window before it reaches everyone else

    Federal deadlines don't automatically apply to banks, credit unions, or private companies. History says examination and audit expectations follow federal rule-making within a year or two. This is the window before that catches up.

None of that requires understanding the underlying math. It just requires understanding the shape of it: a real, well-documented risk, an official replacement that already exists, and a policy clock that started running in 2026 whether or not any individual organization has looked at it yet.

The math hasn’t changed. The deadline has.

The clock is running on your vendors too

PQCClear assesses the quantum readiness of every fintech vendor in your portfolio: a PQC Readiness Score, a full CBOM, and an examination-ready report for each one.

Request access
post-quantum deadlinesquantum computing riskPQC migration timelinecryptographic inventory

PQC Basics is an ongoing series from PQCClear explaining post-quantum cryptography readiness in plain language, one idea at a time. This post represents PQCClear’s own editorial explanation and should not be construed as technical, legal, or regulatory advice.

Key sources: NIST FIPS 203, 204, and 205 (csrc.nist.gov, August 2024); Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (June 22, 2026); OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography (June 24, 2026).