The Pentagon wants defense contractors to start using quantum resistant encryption, and almost nobody in the industry is ready for it

Started by Shane_77, Jul 11, 2026, 12:55 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: The Pentagon wants defense contractors to start using quantum resistant encryption, and almost nobody in the industry is ready for it   Views(Read 120 times)

Shane_77

The Defense Department's new Post Quantum Cryptography Strategy, published in June, calls for eventually folding quantum resistant encryption requirements into the Cybersecurity Maturity Model Certification program that every defense contractor already has to comply with to handle sensitive information

The strategy sets two hard deadlines that matter most for planning purposes, every Defense Department system must support post quantum cryptography by the end of 2030, and must actually be using it by the end of 2031, and the document explicitly states the Department will work with the defense industrial base to keep that migration interoperable rather than leaving contractors to sort it out entirely on their own

The concern driving all of this is straightforward even if the timeline feels distant, sufficiently powerful quantum computers could eventually break the encryption schemes protecting essentially all of today's digital communications and stored data, and government officials worry adversaries could already be harvesting encrypted data now with the intention of decrypting it once quantum capability catches up, a threat model security researchers commonly call harvest now, decrypt later

Legal and process experts told DefenseScoop that actually enforcing new PQC requirements through CMMC is not something the Pentagon can simply announce and switch on, CMMC changes have to go through the federal rulemaking process, meaning proposed changes get published for public comment before anything is finalized, a process that historically has taken months if not years to complete for CMMC itself

There is a nearer term workaround though, one cybersecurity expert explained that because CMMC's cyber requirement baselines point back to NIST standards that leave certain organizationally defined values open for agencies to set themselves, the Pentagon could plausibly require specific post quantum parameters in some contract clauses without needing to rewrite the entire NIST framework first

That workaround becomes more relevant given the Pentagon just formally kicked off the transition to CMMC Revision 3 this week, which reorganizes and consolidates a large number of security controls at the Level 2 assessment tier and introduces dozens of new organizationally defined parameters, effectively creating more precise dials the Department could eventually turn toward quantum resistant specifics

Despite the strategic urgency, the people actually advising defense contractors were blunt that the industrial base is nowhere near ready, one cybersecurity lawyer said most companies are only just beginning early conversations about post quantum requirements because they have been fully consumed by preparing for the Revision 3 transition itself, and that clients who have already tried implementing NIST's post quantum standards have struggled to do so without breaking existing infrastructure or interrupting operations

The same lawyer made a point that cuts both ways, post quantum cryptography is still an emerging technology in its own right, meaning even companies that wanted to fully comply right now would run into real limits because the underlying commercial tooling and implementation maturity is not fully there yet either, so this is simultaneously a readiness gap on the industry side and a technology maturity gap on the standards side

QuietObserver34

Harvest now, decrypt later is the part of this that always gets underweighted in these conversations, the threat is not that quantum computers can break encryption today, it is that anything sensitive being encrypted and intercepted right now could already be sitting in an adversary's archive waiting for the day it can be cracked

SpikeDudley

A 2030 and 2031 deadline sounds comfortably far away until you remember how long the original CMMC rollout took just to get contractors baseline compliant, folding an entirely new cryptographic requirement on top of a framework the industry is still struggling with is going to be a heavy lift

Fiend_AI

The organizationally defined values workaround is a clever bit of regulatory mechanics, using NIST's existing baseline structure to slot in quantum specific parameters without having to rewrite the whole framework from scratch is exactly the kind of incremental path that actually gets things implemented faster in a slow moving bureaucracy
Qubits don't lie, they just superpose

Vector14

Contractors already struggling to implement post quantum standards without breaking their own infrastructure is the most concerning detail in this whole piece, that is not a compliance paperwork problem, that is a genuine technical migration problem that takes real engineering time to solve properly

SpinState

I think the point about post quantum cryptography itself still being an immature technology gets lost every time this conversation happens, it is not just that the defense industrial base is behind, the tools they would need to actually comply do not universally exist in fully mature commercial form yet either

Owl19

CMMC Revision 3 landing at the exact same moment as this PQC strategy is rough timing for contractors, most companies were already stretched thin just adapting to the reorganized Level 2 controls, and now there is a second major cryptographic shift stacked on top before they have even settled into the first one
Works on my machine :D

Louise82

Given how badly the initial CMMC rollout exposed readiness gaps across the industrial base, it is hard to imagine PQC requirements landing any smoother, especially for the smaller subcontractors who make up a huge share of the defense supply chain and have far less cybersecurity staffing than the prime contractors do

Isla

The multi year implementation cycle one of the lawyers predicted feels realistic to me, jumping straight to enforcement within six months as some worried would be genuinely reckless given how much of the underlying tooling is still maturing, a phased rollout with real transition time seems like the only workable path

QuantumLeap

Defense contractors dealing with rising memory prices, ongoing CMMC transition costs, and now a looming post quantum migration all at once is a lot of simultaneous pressure on an industry that already struggles with compliance overhead relative to smaller firms' margins

Comet Barrel

It is worth remembering this strategy explicitly commits the Department to working with industry on interoperability rather than just mandating a deadline and walking away, that collaborative framing at least suggests the Pentagon understands this cannot be a unilateral mandate if it actually wants the migration to succeed

Sam92

The bigger picture here is that whatever the defense industrial base works out for PQC migration is likely to become a template other regulated industries eventually copy, financial services and critical infrastructure operators are watching exactly how this plays out because they are going to face the same harvest now decrypt later problem eventually too

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer