> ## Content Index
> Fetch the complete content index at: https://www.controlplaneinsider.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Enterprise Quantum Security: The 2026 State of the Union
- URL: https://www.controlplaneinsider.com/enterprise-quantum-security-the-2026-state-of-the-union/
- Published: 2026-07-20T18:41:52.000Z
- Updated: 2026-07-20T18:41:52.000Z
- Author: Lionel Cave

*Quantum security has moved from research horizon to enterprise operating model. The 2026-to-2027 challenge is not guessing the exact arrival date of a cryptographically relevant quantum computer; it is building the crypto inventory, governance, migration factory, vendor discipline, and agent-assisted evidence loop needed to become post-quantum ready.*

## Why quantum security matters now

Enterprise quantum security is no longer a theoretical discussion about what quantum computers may do someday. It is a practical security, governance, and operating-model problem today.

The reason is simple: modern enterprises are saturated with public-key cryptography. It protects TLS sessions, APIs, VPNs, software updates, code signing, identity systems, certificates, cloud connections, payment flows, device trust, machine-to-machine authentication, and long-lived records. If a future cryptographically relevant quantum computer can break widely deployed public-key algorithms, the exposure is not limited to a single protocol. It touches the way the enterprise establishes trust.

The timing remains uncertain. Responsible security leaders should avoid confident claims about the exact year a quantum computer will break current public-key cryptography at operational scale. But uncertainty is not the same thing as inaction. The risk calculus changes because of **harvest now, decrypt later**: adversaries can capture encrypted data today and hold it until future decryption becomes possible. The [CISA/NSA/NIST quantum-readiness guidance](https://media.defense.gov/2023/Aug/21/2003284212/-1/-1/0/CSI-QUANTUM-READINESS.PDF?ref=controlplaneinsider.com) explicitly warns that threat actors could target data now if it has a long secrecy lifetime.

That is why post-quantum readiness is not just an algorithm decision. It is a migration program. It requires knowing where vulnerable cryptography exists, which data needs protection for how long, which vendors control embedded crypto, which systems can be upgraded, which protocols require hybrid transition, which certificates and keys will change, and which business processes need governance.

Quantum security has become a crypto-migration, inventory, governance, vendor, and operating-model problem.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--01_30_25-PM.png)

## 2026 state of the union heading into 2027

The enterprise landscape changed materially in 2024, 2025, and 2026.

First, the standards foundation is now real. In August 2024, NIST released the first three finalized post-quantum cryptography standards: [FIPS 203 for ML-KEM](https://csrc.nist.gov/pubs/fips/203/final?ref=controlplaneinsider.com), [FIPS 204 for ML-DSA](https://csrc.nist.gov/pubs/fips/204/final?ref=controlplaneinsider.com), and [FIPS 205 for SLH-DSA](https://csrc.nist.gov/pubs/fips/205/final?ref=controlplaneinsider.com). NIST described FIPS 203 as the primary standard for general encryption/key establishment, FIPS 204 as the primary standard for digital signatures, and FIPS 205 as a stateless hash-based signature standard intended as a backup approach. NIST's announcement was direct: system administrators should begin transitioning to the new standards because full integration will take time ([NIST, August 2024](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards?ref=controlplaneinsider.com); [CSRC approval notice](https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved?ref=controlplaneinsider.com)).

Second, the standards process is still evolving, which reinforces the need for crypto-agility. In March 2025, NIST selected [HQC as a backup key-encapsulation mechanism](https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption?ref=controlplaneinsider.com) for ML-KEM, with a draft standard expected roughly a year later and a final standard expected in 2027\. In September 2025, NIST finalized [SP 800-227, Recommendations for Key-Encapsulation Mechanisms](https://csrc.nist.gov/pubs/sp/800/227/final?ref=controlplaneinsider.com). In June 2026, NIST published an updated final white paper on [crypto agility strategies and practices](https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final?ref=controlplaneinsider.com), defining crypto agility as the capability to replace and adapt cryptographic algorithms across protocols, applications, software, hardware, firmware, and infrastructure while preserving security and operations.

Third, governments have turned PQC migration into a governance program, not a research topic. The [Quantum Computing Cybersecurity Preparedness Act](https://www.govinfo.gov/app/details/PLAW-117publ260?ref=controlplaneinsider.com), signed as Public Law 117-260 in December 2022, encourages the migration of federal information technology systems to quantum-resistant cryptography. OMB's [M-23-02 memorandum](https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf?ref=controlplaneinsider.com) directed federal agencies to build prioritized inventories of cryptographic systems, initially focused on high-value and high-impact assets, and to account for algorithms, key lengths, vendors, hosting model, and data lifecycle characteristics.

Fourth, discovery and inventory are moving toward automation. CISA's [Post-Quantum Cryptography Initiative](https://www.cisa.gov/topics/risk-management/quantum?ref=controlplaneinsider.com) and its [strategy for automated PQC discovery and inventory tools](https://www.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools?ref=controlplaneinsider.com) put the operational emphasis where enterprises should put it: automated cryptography discovery, inventory maintenance, and migration measurement. NIST's NCCoE draft practice guide on [quantum readiness and cryptographic discovery](https://www.nccoe.nist.gov/sites/default/files/2023-12/pqc-migration-nist-sp-1800-38b-preliminary-draft.pdf?ref=controlplaneinsider.com) similarly treats discovery tools and inventories as practical foundations for migration.

Fifth, vendor readiness is becoming a procurement issue. CISA's 2026 [product-category guidance for technologies using PQC standards](https://www.cisa.gov/resources-tools/resources/product-categories-technologies-use-post-quantum-cryptography-standards?ref=controlplaneinsider.com) is an important market signal: buyers should not wait until every internal system is remediated before asking cloud, endpoint, browser, network, identity, and application vendors for PQC roadmaps, attestations, configuration options, and transition commitments.

The state of the union heading into 2027 is therefore clear: the standards exist, additional guidance is arriving, federal governance has created a reference model, discovery must become continuous, and enterprises need a migration factory rather than a one-time project.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--01_34_15-PM.png)

## What post-quantum readiness actually looks like

Post-quantum readiness is not a certificate that says "PQC enabled." It is a set of operating capabilities.

### 1\. Cryptographic inventory

Readiness starts with an inventory of cryptography in use. That inventory should include:

- Algorithms and key lengths.
- Protocols and services using public-key cryptography.
- Certificate authorities, certificate stores, key management systems, HSMs, and signing services.
- Applications, libraries, firmware, embedded devices, OT systems, and CI/CD pipelines.
- Data protected by each cryptographic mechanism and the required protection lifetime.
- Asset criticality, business owner, system owner, vendor, deployment model, and migration constraints.

OMB M-23-02 is useful even outside government because it shows the level of specificity a serious inventory requires: not just "uses RSA," but what service the crypto provides, where it is deployed, who supplies it, how it is hosted, and how long the protected data must remain secure.

### 2\. Risk-tiered migration

Not every system moves first. The migration sequence should be based on risk:

- Long-secrecy data exposed to external collection.
- High-impact or high-value systems.
- Identity, access, certificate, and signing infrastructure.
- Internet-facing protocols and remote access.
- Software-update, firmware-update, and code-signing paths.
- OT and embedded systems with long replacement cycles.
- Vendor-controlled systems where lead times may be long.

The CISA/NSA/NIST guidance recommends quantum-readiness roadmaps, inventories, risk assessments, and vendor engagement; it also calls out high-impact systems, industrial control systems, and systems with long-term confidentiality needs as priorities.

### 3\. Crypto-agility

Crypto-agility is the ability to change cryptography without breaking the business. That means algorithm choices should be decoupled from application logic wherever possible. Enterprises need abstraction layers, central policy, modular libraries, replaceable certificates and keys, testable protocol configurations, and documented rollback paths.

The 2026 NIST crypto-agility white paper matters because PQC migration will not be the last cryptographic transition. Algorithms, standards, hardware support, protocol behavior, and vendor implementations will continue to evolve. A brittle migration only solves the first wave.

### 4\. Vendor attestations and procurement controls

Enterprises cannot migrate what they do not control or cannot see. Vendor due diligence should ask:

- Which vulnerable algorithms are embedded in the product or service?
- Which NIST PQC standards are supported today?
- Is support production-ready, preview, roadmap, or dependent on another vendor?
- Does the product support hybrid modes where relevant?
- How are certificates, keys, trust stores, firmware signing, and software-update signing handled?
- What evidence can the vendor provide: documentation, test results, security certifications, release notes, SBOM/CBOM-style artifacts, or contractual commitments?
- What is the vendor's target migration timeline and customer configuration path?

The CISA/NSA/NIST factsheet explicitly recommends engaging vendors and planning for contract changes so new products can be delivered with PQC built in and older products can be upgraded against transition timelines.

### 5\. Hybrid/PQC pilots

Readiness includes controlled pilots, not blanket production flips. Hybrid approaches may combine classical and post-quantum mechanisms during transition where standards, protocols, and products support them. Pilots should test interoperability, performance, handshake sizes, certificate behavior, logging, monitoring, key management, rollback, and operational support.

The point is not to prove that PQC works in a lab. It is to learn how PQC behaves inside the enterprise's real dependency graph.

### 6\. Certificate and key lifecycle planning

PQC migration touches certificate authorities, issuance automation, renewal cadence, trust stores, HSMs, key-generation procedures, key escrow policies, code-signing systems, mutual TLS, device identity, and break-glass procedures. It also affects incident response: when an algorithm, library, or certificate profile changes, the enterprise needs a repeatable way to find exposure and rotate safely.

### 7\. Continuous compliance

A cryptographic inventory is not a spreadsheet. It is a control system. Readiness means continuous discovery, evidence collection, policy monitoring, exception handling, and audit-ready reporting. That is where agentic AI can help — provided it is bounded by security approvals.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--01_38_12-PM.png)

## Enterprise reference architecture / operating model

A practical enterprise operating model for quantum security has seven layers.

### 1\. Governance layer

The board and executive team need a named quantum-readiness owner, usually connected to the CISO, CTO, CIO, enterprise architecture, and procurement. The program should define risk appetite, migration principles, policy exceptions, vendor requirements, and approval gates.

### 2\. Inventory layer

The inventory layer collects evidence from network scanning, endpoint telemetry, source-code scanning, package metadata, certificate transparency/CA systems, HSM/KMS logs, cloud configuration, CI/CD systems, asset management, CMDB, SBOMs, and vendor attestations. The target artifact is a living cryptographic inventory, not a periodic static report.

### 3\. Risk model layer

Every inventory item should be mapped to data sensitivity, data lifetime, external exposure, business criticality, regulatory obligation, technical feasibility, dependency constraints, and vendor readiness. This creates the migration priority queue.

### 4\. Migration factory layer

The migration factory converts priorities into execution: design patterns, reference configurations, test plans, change windows, exception processes, rollback plans, evidence requirements, and release governance. This is where pilots become repeatable playbooks.

### 5\. Vendor and supply-chain layer

Procurement, third-party risk, architecture, and security need a common questionnaire and evidence model for PQC readiness. Vendor claims should be tied to product version, configuration, supported protocol, algorithm, certificate/key lifecycle, and implementation maturity.

### 6\. Observability and compliance layer

Teams need dashboards for inventory completeness, vulnerable crypto exposure, long-secrecy data coverage, vendor readiness, migration status, exceptions, compensating controls, and audit evidence. Compliance should be continuous, not a quarter-end scramble.

### 7\. Agentic AI operations layer

Agentic AI can sit across the model as an orchestration and evidence layer. It can watch for changes, reconcile sources, maintain tickets, summarize gaps, collect attestations, generate readiness reports, and route exceptions. But it should not unilaterally approve cryptographic changes, change production policy, rotate keys, accept vendor claims, or override security controls.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--01_42_28-PM.png)

A simple reference model looks like this:

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--02_06_15-PM.png)

## Where agentic AI helps defend against quantum threats

Agentic AI's role is not quantum magic. It does not make cryptography quantum-safe by itself. Its value is operational: keeping the crypto-readiness program alive, current, evidence-backed, and governed.

### Continuous discovery

Agents can monitor evidence sources for new cryptographic usage: code dependencies, TLS endpoints, certificates, container images, CI/CD pipelines, cloud resources, firmware packages, network services, and vendor documentation. They can flag likely RSA, ECDH, ECDSA, or other CRQC-vulnerable public-key dependencies for review.

### Inventory maintenance

A one-time scan goes stale quickly. Agents can reconcile findings from multiple systems, deduplicate records, attach owners, update status, and identify missing metadata. They can preserve provenance: where the finding came from, when it was observed, which tool produced it, and what evidence supports it.

### Policy enforcement

Agents can compare findings against enterprise policy: unsupported algorithm, key length, certificate profile, vendor status, data lifetime, or system criticality. The right control pattern is recommendation and routing, not silent enforcement. For high-impact systems, agents should create evidence-backed tickets and route them through security change approval.

### Migration orchestration

Agents can help sequence migrations by dependency, risk tier, owner, maintenance window, and vendor availability. They can generate migration runbooks, pre-change checklists, test cases, rollback criteria, and evidence templates. They can also track whether pilots covered performance, interoperability, monitoring, and failure modes.

### Evidence collection

PQC readiness will be audited. Agents can collect release notes, screenshots, config exports, scan outputs, vendor letters, test reports, policy approvals, and exception records into a readiness evidence pack.

### Vendor tracking

Agents can monitor vendor roadmaps, product advisories, release notes, procurement attestations, and contract obligations. They can compare a vendor's claims against internal inventory: which products are deployed, which versions are in scope, and which systems still depend on the vendor's roadmap.

### Exception management

Some systems will not migrate quickly. Agents can maintain exception registers with expiry dates, compensating controls, business owner acceptance, residual risk, and re-review schedules.

### Audit and readiness reporting

Agents can produce executive dashboards and board-ready summaries: inventory coverage, top risk concentrations, migration velocity, vendor gaps, exceptions, and next-quarter priorities. The key is traceability. Every summary should link back to evidence, not model-generated assertion.

The boundary is important: agents can accelerate governance, but they should not replace governance.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--02_14_10-PM.png)

## Risks, misconceptions, and governance boundaries

### Misconception 1: "Quantum security can wait until a quantum computer exists."

The exact timeline remains uncertain, but long-secrecy data changes the decision. The CISA/NSA/NIST guidance explicitly frames harvest now, decrypt later as a present concern. If the data must remain confidential into the 2030s or beyond, the migration clock has already started.

### Misconception 2: "PQC migration is just a library swap."

Some changes will be simple. Many will not. Cryptography is embedded in protocols, certificates, devices, firmware, applications, identity systems, and vendor products. Migration touches testing, interoperability, procurement, monitoring, performance, and rollback.

### Misconception 3: "Once we support ML-KEM, we are done."

ML-KEM is central, but readiness also includes digital signatures, certificate lifecycles, code signing, key management, hybrid transition, embedded systems, vendor controls, and crypto-agility. NIST's selection of HQC as a backup KEM is a reminder that standards portfolios evolve.

### Misconception 4: "Quantum key distribution solves the problem."

NSA's post-quantum resources warn against over-reliance on quantum key distribution for National Security Systems unless significant limitations are overcome. NSA emphasizes that quantum-resistant algorithms can be implemented on existing platforms and generally offer a more maintainable path than specialized QKD infrastructure for most enterprise-style needs ([NSA PQC resources](https://www.nsa.gov/Cybersecurity/Post-Quantum-Cybersecurity-Resources/?ref=controlplaneinsider.com)).

### Misconception 5: "The vendor says it is PQC-ready, so the risk is closed."

Vendor claims need scope. Which product? Which version? Which algorithms? Which protocols? Which configuration? Which certificate/key flows? Which deployment model? Which evidence? Which remaining gaps?

### Misconception 6: "Agentic AI can run the migration by itself."

Agentic AI can help discover, reconcile, plan, document, and report. It should not approve cryptographic standards, bypass change control, rotate production keys without authorization, accept residual risk, or make unilateral security decisions. Cryptographic migration is a high-impact security change and must remain under accountable human governance.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--02_16_55-PM.png)

## 12-month enterprise action plan

### Months 0-1: establish ownership and scope

- Name the executive owner and program lead.
- Form a cross-functional quantum-readiness team: security, architecture, infrastructure, cloud, application engineering, identity, PKI, procurement, legal/compliance, audit, and business owners.
- Define scope: crown jewels, high-impact systems, regulated data, identity systems, software-update paths, external-facing services, cloud services, and critical vendors.
- Establish governance: approval paths, exception process, evidence requirements, and reporting cadence.

### Months 1-3: build the first cryptographic inventory

- Start with high-value and high-impact systems.
- Combine automated discovery with targeted manual review for critical systems.
- Capture algorithm, key length, protocol, certificate/key flow, owner, vendor, data lifetime, and business criticality.
- Correlate findings with CMDB, asset inventory, cloud inventory, IAM/PKI, EDR, and CI/CD.
- Identify visibility gaps: embedded crypto, vendor-controlled systems, OT, firmware, legacy appliances, and SaaS dependencies.

### Months 3-4: create the risk-tiered migration roadmap

- Rank systems by data lifetime, exposure, criticality, feasibility, vendor dependency, and replacement cycle.
- Identify quick wins, difficult migrations, and vendor blockers.
- Define pilot candidates for hybrid or PQC-capable configurations.
- Establish migration patterns for TLS, VPN, API gateways, code signing, certificate services, software updates, and key management.

### Months 4-6: launch vendor and procurement controls

- Send PQC questionnaires to critical vendors.
- Require product-level roadmap, supported standards, version commitments, configuration guidance, and evidence.
- Update procurement requirements for products in categories where PQC-capable offerings are available or emerging.
- Add PQC readiness clauses to renewals and new contracts where appropriate.

### Months 6-9: run pilots and build the migration factory

- Pilot PQC or hybrid configurations in controlled environments.
- Test performance, interoperability, certificate behavior, monitoring, rollback, and failure handling.
- Build reusable runbooks, change templates, validation scripts, and evidence packs.
- Define crypto-agility patterns: abstraction, configuration, central policy, testing, rollback, and version control.

### Months 9-12: operationalize continuous readiness

- Move inventory from project artifact to continuous control.
- Add dashboards for coverage, residual risk, vendor gaps, exceptions, and migration status.
- Deploy agentic AI workflows for discovery triage, evidence collection, vendor tracking, exception reminders, and audit reporting.
- Conduct tabletop exercises for urgent cryptographic change: algorithm weakness, vendor delay, certificate profile change, or protocol deprecation.
- Present board-level readiness: where risk is concentrated, what has migrated, what is blocked, and what funding or executive action is needed.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--02_21_04-PM.png)

## Executive takeaway

The enterprise quantum-security agenda for 2026 heading into 2027 is not about predicting the exact day quantum computing becomes cryptographically disruptive. It is about preparing the enterprise so that uncertainty does not become paralysis.

The standards foundation is now in place. The governance direction is clear. The hard work is operational: discover cryptography, understand risk, build crypto-agility, engage vendors, pilot post-quantum patterns, plan certificate and key lifecycles, and maintain evidence continuously.

Agentic AI can help — not by making quantum threats disappear, but by making the readiness program measurable, current, and auditable. The right role for agents is continuous discovery, inventory maintenance, policy comparison, migration orchestration, evidence gathering, vendor tracking, exception management, and reporting. The right boundary is equally important: cryptographic decisions, security approvals, production changes, and residual-risk acceptance must remain accountable human decisions.

Quantum security has crossed from theory into operating model. Enterprises that treat it as a governed migration program will be better positioned than those waiting for a perfect forecast.

![](https://storage.ghost.io/c/37/e7/37e7618e-757e-4769-a8f1-6d27d2caccf8/content/images/2026/07/ChatGPT-Image-Jul-20--2026--02_25_29-PM.png)

## Sources / references

- [NIST: NIST Releases First 3 Finalized Post-Quantum Encryption Standards](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards?ref=controlplaneinsider.com)
- [NIST CSRC: Announcing Approval of Three FIPS for Post-Quantum Cryptography](https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved?ref=controlplaneinsider.com)
- [FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard](https://csrc.nist.gov/pubs/fips/203/final?ref=controlplaneinsider.com)
- [FIPS 204: Module-Lattice-Based Digital Signature Standard](https://csrc.nist.gov/pubs/fips/204/final?ref=controlplaneinsider.com)
- [FIPS 205: Stateless Hash-Based Digital Signature Standard](https://csrc.nist.gov/pubs/fips/205/final?ref=controlplaneinsider.com)
- [NIST: NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption](https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption?ref=controlplaneinsider.com)
- [NIST PQC Project Publications](https://csrc.nist.gov/Projects/post-quantum-cryptography/publications?ref=controlplaneinsider.com)
- [NIST SP 800-227: Recommendations for Key-Encapsulation Mechanisms](https://csrc.nist.gov/pubs/sp/800/227/final?ref=controlplaneinsider.com)
- [NIST CSWP 39upd1: Considerations for Achieving Crypto Agility: Strategies and Practices](https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final?ref=controlplaneinsider.com)
- [CISA: Post-Quantum Cryptography Initiative](https://www.cisa.gov/topics/risk-management/quantum?ref=controlplaneinsider.com)
- [CISA: Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools](https://www.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools?ref=controlplaneinsider.com)
- [CISA: Product Categories for Technologies That Use Post-Quantum Cryptography Standards](https://www.cisa.gov/resources-tools/resources/product-categories-technologies-use-post-quantum-cryptography-standards?ref=controlplaneinsider.com)
- [CISA/NSA/NIST: Quantum-Readiness: Migration to Post-Quantum Cryptography](https://media.defense.gov/2023/Aug/21/2003284212/-1/-1/0/CSI-QUANTUM-READINESS.PDF?ref=controlplaneinsider.com)
- [NSA: Post-Quantum Cybersecurity Resources](https://www.nsa.gov/Cybersecurity/Post-Quantum-Cybersecurity-Resources/?ref=controlplaneinsider.com)
- [OMB M-23-02: Migrating to Post-Quantum Cryptography](https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf?ref=controlplaneinsider.com)
- [Public Law 117-260: Quantum Computing Cybersecurity Preparedness Act](https://www.govinfo.gov/app/details/PLAW-117publ260?ref=controlplaneinsider.com)
- [NIST NCCoE: Migration to Post-Quantum Cryptography — Quantum Readiness: Cryptographic Discovery](https://www.nccoe.nist.gov/sites/default/files/2023-12/pqc-migration-nist-sp-1800-38b-preliminary-draft.pdf?ref=controlplaneinsider.com)