The Shrinking Quantum Threshold: Why Intelligence Leaders Must Prepare Now

From IC Insider Tychon
Lower quantum attack-resource estimates strengthen the case for cryptographic discovery and migration planning.
By Garland W. Garris, TYCHON SVP, Research and Technology Strategy
For the Intelligence Community, quantum readiness begins with information that must remain confidential for years or decades. Adversaries can collect encrypted communications today and retain them for future decryption. Replacing the vulnerable cryptography protecting that information—and the systems supporting it—will require sustained planning and investment.
Recent research strengthens the case for beginning now. Several studies have substantially reduced the estimated quantum resources needed to attack RSA and elliptic-curve cryptography. These findings do not establish when a cryptographically relevant quantum computer (CRQC) will arrive but provide insight into how quickly quantum science is developing, enabling agencies to plan and mitigate risk.
The estimated requirements are falling for when a CRQC will be developed
A 2019 study estimated that factoring RSA-2048 would require approximately 20 million physical qubits. The 2026 Pinnacle architecture estimates fewer than 100,000 under different architectural assumptions. These are resource estimates for proposed systems, not demonstrated attacks.
Elliptic-curve research shows similar progress—and important tradeoffs. IonQ estimates approximately 19,400 physical qubits and nearly 26 days per attempt to attack the secp256k1 curve. Google’s superconducting design estimates fewer than 500,000 physical qubits with a runtime measured in minutes.
Three developments are driving these changes:
- More efficient algorithms reduce the computational resources an attack requires.
- Improved error correction reduces the physical hardware needed to support reliable operations.
- Hardware-specific designs trade qubit count against runtime, connectivity, and other requirements.
Qubit count alone therefore cannot measure proximity to a working attack. Hardware experiments are demonstrating important ingredients, but integrating them into a system capable of sustained, fault-tolerant computation remains a major unresolved challenge. Vendor roadmaps describe targets rather than proven capabilities.
Migration deadlines require planning now
Federal policy creates a planning obligation independent of the uncertain threat timeline.
Executive Order 14412 directs migration of federal high-value assets and high-impact systems, excluding National Security Systems from that provision, to post-quantum key establishment by December 31, 2030, and digital signatures by December 31, 2031. It also directs a proposed acquisition rule addressing covered contractors. National Security Systems require separate attention to applicable NSA and CNSS requirements, including CNSA 2.0.
These dates are migration milestones, not predictions of when quantum attacks will become possible.
Preparation itself takes time. The UK’s National Cyber Security Centre estimates two to three years for discovery and planning in large organizations, followed by another two to three years for early migration activities.
What intelligence and security leaders should do now
- Establish ownership and inventory. Assign a migration lead and identify vulnerable cryptography across applications, protocols, certificates, signing systems, hardware, and supplier services.
- Prioritize mission risk. Assess confidentiality lifetimes, adversary interest, exposure, and replacement lead times. Address both future decryption risks and the integrity of software, devices, and trusted identities.
- Test approved migration paths. Pilot implementations consistent with applicable requirements. Validate performance, interoperability, and operational effects before broader deployment.
- Engage suppliers early. Request algorithm support, validation status, delivery dates, and hardware replacement requirements. Include long-lived roots of trust and signing infrastructure.
- Build cryptographic agility. Reduce future replacement effort through managed interfaces, configurable implementations, and tested upgrade paths. Track research alongside hardware progress.
Security leaders do not need a reliable prediction of Q-Day to justify action. They need to understand where vulnerable cryptography supports their missions, how long information must remain protected, and how long replacement will take. Starting discovery and planning now gives organizations time to resolve those dependencies before they become urgent.
About Tychon
TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.
Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.
About IC Insiders
IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.







