The Imperative & The Important — PQC Edition
Why read this
While most organizations are still watching the calendar for a cryptographically relevant quantum computer, the migration stopped waiting. This month it showed up in three places nobody’s spreadsheet covers: the badge reader at the front door, a network setting a vendor flipped on your behalf, and a piece of hardware your procurement team can now be required to buy. If your quantum-readiness plan is a list of your own certificates, this edition is about everything the list is missing.
Every edition of The Imperative & The Important uses two lenses. The Imperative is what happened this month that demands a reaction. The Important is what will still be true after the headlines fade.
First, the acronyms. Post-quantum cryptography (PQC) is the family of encryption algorithms designed to resist attack by quantum computers, standardized by the U.S. National Institute of Standards and Technology (NIST). A hardware security module (HSM) is the tamper-resistant device that guards an organization’s most sensitive encryption keys. Transport Layer Security (TLS) is the protocol that encrypts nearly all web traffic. Keep all three in mind — this story is about how far beyond them the migration now reaches.
The Imperative
1. Washington opened two new fronts in one announcement. The General Services Administration (GSA) and the U.S. Department of the Treasury launched parallel PQC initiatives grounded in Office of Management and Budget (OMB) Memorandum M-26-15 and Executive Order 14412. GSA is modernizing the Federal Identity, Credential, and Access Management (FICAM) framework and expanding its FIPS 201 lab to test quantum-resistant building access controls, visitor passes, and employee badges — qualified hardware goes on the government’s mandatory Approved Products List. Its first interagency working group convened August 12 with 40 participants from 17 agencies. Treasury established a public-private Quantum-Readiness Task Force, led by Secretary Scott Bessent, with workstreams covering the phased migration of banks, payment processors, asset managers, and insurers — plus vendor supply-chain readiness and digital-asset quantum risk (Quantum Computing Report). Business impact: if you sell to the government or move money through the U.S. financial system, your cryptographic readiness is about to become a line item on someone else’s checklist — including the readiness of your vendors.
2. A major slice of the internet went quantum-safe by default — without asking you. As of August 12, end-to-end post-quantum encryption is generally available across Akamai’s Enhanced TLS network. Two of the three transport legs — browser-to-Akamai and Akamai-to-Akamai — are now on by default. Akamai observed more than 450 million post-quantum connections in the first two minutes, and one financial-technology customer immediately reached 99.4 percent quantum resistance. The third leg — Akamai to your own origin servers — remains opt-in (Akamai). Business impact: part of your traffic just got quantum-safe with zero effort from you. That is the good news and the trap. The leg you own still requires your action, and a default you didn’t configure is a control you haven’t verified.
3. The “no validated hardware” excuse expired. Canada’s Crypto4A received FIPS 140-3 Level 3 validation for QASM, the cryptographic module inside its quantum-safe HSM — by the company’s account, the first module at that level to support every NIST-approved post-quantum algorithm. Level 3 requires physical tamper resistance, identity-based authentication, and secure key management (Crypto4A). Business impact: procurement teams that have been waiting for independently validated quantum-safe hardware can now write it into requirements — and regulators and auditors know it.
The Important: The Cryptographic Inventory Just Left the Server Room
Last week’s Zero Trust edition applied the discovery–agility–governance trio to identities. This week the trio comes home to cryptography itself — and the territory grew.
For two years, “build a cryptographic inventory” meant cataloging your own algorithms, keys, and certificates. This month’s evidence says that inventory now has three new wings. The badge reader on the loading dock is a cryptographic asset — GSA is already testing its replacement. The encrypted connection your customers ride is partly owned by a vendor who upgrades it on their own schedule — Akamai just proved it. And the hardware module anchoring your keys is now something a task force can ask your suppliers about — Treasury just built the task force.
The industry has a name for the mature version of this: a Cryptographic Bill of Materials (CBOM) — like a software bill of materials, but for every place cryptography lives, including the places other people run for you.
The discipline is the same trio, with a wider lens:
Discovery — inventory beyond your certificates: physical access systems, every leg of every encrypted path (including the legs a vendor terminates), hardware modules, and the cryptography buried in supplier products. The connection you don’t terminate is still your risk.
Agility — Akamai’s default flip is what agility looks like when someone else does the work. The question is whether your own systems could accept an algorithm swap that gracefully. If upgrading one leg of one connection requires a re-architecture, you have a physics problem before you have a quantum one.
Governance — Treasury put a Cabinet secretary’s name on financial-sector quantum readiness. Match the energy: name an owner for your migration, and put the vendor-readiness question into procurement before a regulator puts it there for you.
The Imperative changes weekly. The Important is your homework either way.
Three Questions for Your Board
Do we have a cryptographic bill of materials — and does it include building access systems, vendor-terminated connections, and hardware modules, or just our own certificates? If the list ends at the server room door, so does the protection.
Which legs of our encrypted traffic did a provider already upgrade by default — and which legs are still ours to fix? Verified, not assumed. A default you haven’t checked is not a control.
Who owns our quantum readiness by name — and do our vendor contracts ask the question Treasury is about to ask for us? Name the person, hand them the inventory, and put a date on the first report.
The Imperative & The Important is the briefing from Carl’s Corner — timely developments and the durable ideas underneath them, across post-quantum cryptography, IoT and OT security, cybersecurity, and enterprise AI.
Sources
Quantum Computing Report — GSA and Treasury Launch Dual-Agency Post-Quantum Cryptography Initiatives for U.S. Federal Financial Infrastructure: https://quantumcomputingreport.com/gsa-and-treasury-launch-dual-agency-post-quantum-cryptography-initiatives-for-u-s-federal-financial-infrastructure/
Akamai — Future-Proofing the Internet: Akamai Achieves End-to-End PQC: https://www.akamai.com/blog/security/future-proofing-internet-akamai-achieves-end-to-end-pqc
Crypto4A — Crypto4A achieves FIPS 140-3 Level 3 validation for QASM: https://crypto4a.com/resources/newsroom/2026-08-19-fips-certification-announcement
#PostQuantumCryptography #PQC #QuantumReadiness #Cybersecurity #CBOM #TheImperativeAndTheImportant