For years, post-quantum cryptography was a topic for researchers and standards committees, something an executive could reasonably file under “important, not urgent.” That filing is about to expire. Sometime soon, in a board meeting, a regulatory review, a customer security questionnaire, or a private-equity diligence session, someone is going to ask a direct question: are we quantum ready? And they will expect a direct answer.
The reason the question is arriving now has almost nothing to do with a breakthrough in quantum computing. A machine capable of breaking today’s encryption does not yet exist. What changed is that governments stopped waiting for one. Rather than time their deadlines to an unpredictable “Q-Day,” regulators published the dates anyway. The United States, the European Union, Canada, and others have all set calendars for retiring the encryption that protects most of the world’s data, and those calendars are now measured in a handful of years, not decades.
For most organizations, the uncomfortable part is not the deadline itself. It is that they cannot yet answer the question. A confident “yes, we are on track” requires knowing exactly where and how cryptography lives inside every system you run, including the older, custom applications that no one fully remembers. That knowledge is precisely what most enterprises lack. This post begins a series about closing that gap, starting with why the question has become unavoidable.
The Post-Quantum Deadlines Arrived Before the Threat
The strange feature of the post-quantum transition is that its deadline is firmer than its threat. No one can tell you the year a cryptographically relevant quantum computer will arrive. The compliance dates, by contrast, are already printed. In the United States, NIST guidance deprecates the RSA and elliptic-curve algorithms that secure most systems today after 2030 and disallows them after 2035. For national security systems, the NSA’s CNSA 2.0 schedule moves faster, phasing in category by category well before then. And in June 2026, a set of executive and budget-office actions converted what had been a relaxed 2035 posture into a phased schedule with near-term obligations for federal agencies and the contractors that serve them.
There is a second reason the threat is more present than it looks. Adversaries do not need a quantum computer today to benefit from one tomorrow. They can collect encrypted data now and decrypt it later, once the capability exists. Security professionals call this “harvest now, decrypt later,” and it means that any information with a long confidentiality horizon, whether medical records, financial data, defense material, or intellectual property, is effectively at risk the moment it crosses the wire. For that data, the clock did not start at some future Q-Day. It started already.
The Challenge of Quantum Readiness
Here is the good news that makes the rest harder. The cryptography itself is close to a solved problem. NIST finalized its post-quantum standards in 2024, and the replacement algorithms, ML-KEM for key exchange and ML-DSA for digital signatures, are published, tested, and ready to deploy. If the only task were swapping one algorithm for another inside a well-documented modern system, this would be a manageable engineering project.
The difficulty is not the new locks. It is finding every door. Cryptography is woven through an enterprise in thousands of places: in applications, libraries, protocols, stored data, hardware, and the connections between systems. In modern, well-maintained software, much of that is declared and visible. In the older custom systems that quietly run payroll, orders, claims, and reporting, it is not. The encryption is buried in code that was written years ago, copied rather than imported, and understood by people who have since left. You cannot migrate what you cannot see, and most organizations cannot yet see the whole picture. That, not the algorithms, is why the readiness question is so difficult to answer honestly.
Quantum Readiness Is a Legacy Modernization Problem
Once the problem is framed that way, something useful becomes clear. Post-quantum readiness is not really a cryptography project. It is a visibility project, and visibility is the first thing any serious modernization effort requires. The work of finding where encryption lives is the same work of understanding what your legacy systems actually contain, how they are built, and where their real risk sits.
This is the thread that runs through everything Aspen does. Our modernization practice is grounded in deep analysis of the code as it exists, not as anyone remembers it, and that analysis is independently validated through our partnership with Silverthread and its CodeMRI® platform. The same understanding that lets a team modernize a system safely, or responsibly layer AI on top of it, is what lets that team produce an honest account of its cryptographic exposure. You cannot secure, modernize, or extend a system you cannot see. Seeing it clearly is where readiness begins.
What This Post-Quantum Series Will Cover
Over the coming posts, this series walks from the question to a defensible answer. It moves through three stages: first why the risk is real now, then what the calendar requires, and finally how the work gets done.
We begin with why the clock is already running:
- Harvest Now, Decrypt Later. Why Your Encrypted Data Is Already at Risk. Why information with a long confidentiality horizon is exposed today, well before any quantum computer exists.
- The Deadlines That Were Always Coming: NIST and CNSA 2.0. The standing regulatory framework, and why its dates are fixed points rather than predictions.
- When Guidance Became Obligation: What 2026 Changed. How this year’s executive and budget-office actions compressed a relaxed posture into near-term requirements.
- The Deadline Is Not Just for Federal Agencies. How the requirements reach contractors, the defense supply base, and regulated industries.
- You Can’t Migrate What You Can’t See. The Cryptographic Inventory Problem. Why discovery, not deployment, is the true starting line.
- Why Legacy Code Is the Hardest Part of the Quantum Transition. Where migrations stall, and why older custom systems hide their cryptography so well.
- From Inventory to Roadmap. Building a Migration Plan That Survives the Timeline. Turning a clear component picture into a prioritized, multi-year plan.
- Modernize Before You Migrate. Getting Your Foundation Ready for Post-Quantum. Why quantum readiness and modernization are the same work, and how to do them once instead of twice.
The through-line is simple. Organizations that treat quantum readiness as a standalone scramble will pay for it twice. The ones that treat it as part of modernizing their foundation will come out ahead on both.
Book a Call with Aspen
If your board, your customers, or your regulators have started asking whether you are quantum ready, and you are not yet certain how you would answer, let’s talk. Aspen can help you see what is inside your legacy systems, map where your cryptographic risk sits, and give your modernization roadmap a foundation it can stand on.
Schedule a discovery chat: https://calendly.com/aspen-ess/aspen-ess-discovery-chat