The Department of Warโs Post-Quantum Cryptography Strategy landed just a day or so ago, but it deserves far more attention than itโs getting.
- Brian Couzens
- Jun 25
- 1 min read
The DoW just gave us a document worth promoting - my favourite line is
๐๐ฎ๐๐ง๐ญ๐ฎ๐ฆ ๐ซ๐๐ฌ๐ข๐ฌ๐ญ๐๐ง๐๐ ๐ข๐ฌ ๐ง๐จ๐ญ ๐๐๐ก๐ข๐๐ฏ๐๐ ๐ฐ๐ก๐๐ง ๐๐๐ ๐ข๐ฌ ๐ซ๐จ๐ฅ๐ฅ๐๐ ๐จ๐ฎ๐ญ, ๐๐ฎ๐ญ ๐ฐ๐ก๐๐ง ๐ช๐ฎ๐๐ง๐ญ๐ฎ๐ฆ-๐ฏ๐ฎ๐ฅ๐ง๐๐ซ๐๐๐ฅ๐ ๐ฌ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง๐ฌ ๐๐ซ๐ ๐๐๐ฉ๐ซ๐๐๐๐ญ๐๐.
The Department of Warโs Post-Quantum Cryptography Strategy landed just a day or so ago, but it deserves far more attention than itโs getting.
In my view, it is much more relevant and operationally important than EO 14409 because it turns quantum risk into a concrete migration mandate.
This is not a vision statement. It is a deadline-driven requirement:
Support PQC by 2030 or phase systems out.
Use PQC across the department by 2031.
No shortcuts, no โquantum-safeโ theatre, no proxy fixes.
Whatโs off the table is just as important:
QKD and quantum networking as security solutions.
Non-local quantum randomness generation.
PSK-based schemes for quantum resistance.
Longer keys on vulnerable algorithms.
PQC proxy workarounds instead of real upgrades.
The clearest way to clear the bar is straightforward:
In-place migration.
Re-platforming.
Retiring the service.
That framing matters because it forces leaders to make a real decision for every system: can it be upgraded, rebuilt, or should it be sunset? Success here is not measured by deployment alone, but by the removal of quantum-vulnerable cryptography across the full lifecycle.
For cybersecurity, infrastructure, and national security teams, the message is simple: identify vulnerable cryptography now, map mission impact, and build a realistic migration roadmap immediately.
The 5 LOEs into something leaders can actually act on.
#PQC #PostQuantumCryptography #Cybersecurity #QuantumComputing #NationalSecurity #Cryptography #DoW #DefenseTech


Comments