Every TLS handshake happening right now — a bank login, a WhatsApp message, a git push — is protected by math that a sufficiently capable quantum computer could eventually break. Nobody can break it today. But an adversary recording that traffic today doesn't need to break it today; they can just wait. Security researchers call this harvest now, decrypt later (HNDL): hoover up encrypted traffic now, sit on it in cold storage, and decrypt it retroactively once a cryptographically relevant quantum computer (CRQC) exists. For anything with a shelf life longer than a few years — state secrets, medical records, source code, the identity of an intelligence asset — that isn't a hypothetical. It's a countdown clock nobody can see the display of.
For most of the last four years that clock has been background hum: a NIST standard here, an NSA memo there, engineers quietly retrofitting protocols that nobody outside cryptography conferences pays attention to. That changed on June 22, 2026, when the deadline stopped being a recommendation and became an executive order. Here's what I could verify about that order, what NIST has actually finalized versus what's still in draft, how much of the real internet has already moved, and — because getting a fact wrong once already cost this site an AdSense rejection — where I'm drawing an explicit line between a documented figure and an inflated headline.
Executive Order 14412: the deadline nobody was fully expecting
On June 22, 2026, President Trump signed Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks." I went and read it on whitehouse.gov myself before writing a word of this, precisely because "the White House signed an order about quantum computers" is the kind of headline that's easy to embellish and hard to walk back. It's real, it's primary-sourced, and its deadlines are specific: federal high-value and high-impact systems must complete migration to post-quantum key-establishment by December 31, 2030, and to post-quantum digital signatures by December 31, 2031. The order also requires agencies to run a PQC migration pilot within 180 days of signing and to issue guidance on cryptographic bills of materials (CBOM) — essentially an inventory of where and how cryptography is used across a system — within 270 days.
A companion order, EO 14413, "Ushering in the Next Frontier of Quantum Innovation," was signed the same day, aimed at the research and industrial side of quantum technology rather than the defensive migration side. The two orders read as a matched pair: one pushes the country to adopt quantum-resistant cryptography before the threat matures, the other pushes it to keep building quantum computers anyway. That's not a contradiction so much as an acknowledgment that the same underlying technology is both the eventual attacker and, in different applications, a strategic asset worth racing for — a tension that shows up across a lot of the broader tech policy landscape this year, not just cryptography.
The math NIST already settled
Executive orders don't invent cryptography; they enforce adoption of it. The algorithms EO 14412 is telling agencies to migrate to were finalized by NIST nearly two years earlier. On August 13, 2024 (effective the next day, per the Federal Register), NIST published three finalized standards: FIPS 203 (ML-KEM, a lattice-based key-encapsulation mechanism, derived from CRYSTALS-Kyber), FIPS 204 (ML-DSA, a lattice-based signature scheme, derived from CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, a hash-based signature scheme, derived from SPHINCS+). Those three standards are the foundation everything downstream — Cloudflare's rollout, Apple's defaults, CNSA 2.0's mandates, EO 14412's deadlines — builds on top of.
NIST didn't stop there. On March 11, 2025, it selected HQC, a code-based key-encapsulation mechanism, as a fifth algorithm — a structurally different backup in case a future cryptanalytic advance weakens the lattice-based approach underlying ML-KEM. A final HQC standard is expected around 2027. The one piece that isn't finished yet is FIPS 206, the standard for FN-DSA (Falcon), a second lattice-based signature scheme intended for applications where signature size matters more than speed. As of mid-2026 it's still in draft, not finalized — worth flagging plainly, because it's easy to round "NIST picked five algorithms" up to "NIST has five finished standards," and that's not accurate yet.
How much of the internet already migrated
The genuinely underreported part of this story is that a meaningful chunk of the internet moved before anyone was legally required to. Cloudflare's 2025 Radar Year in Review tracks the share of human web traffic on its network that's protected by post-quantum key agreement, and the curve is steep: roughly 29% in January 2025, climbing to about 52% by early December 2025 — in other words, more than half of the human traffic flowing through one of the internet's largest networks was already using post-quantum key establishment before EO 14412 existed.
That climb has identifiable drivers, not one single cause. Apple shipped PQ3 in iMessage on February 21, 2024 (iOS 17.4). Signal shipped its PQXDH key-agreement protocol in September 2023. Chrome turned on post-quantum key agreement by default on desktop in March 2024. Apple then extended post-quantum defaults further with iOS 26 and macOS Sequoia in mid-September 2025. Each of those shipped independently, for different reasons, on different timelines — but stacked together they explain most of that 29-to-52 climb. It's a useful reminder for anyone tracking how crawlers and infrastructure quietly reshape the web: the biggest protocol-level shifts on the internet often happen with no announcement most users ever see.
Cloudflare itself has now folded EO 14412 into its own roadmap: in April 2026 the company announced it was moving its target for full PQC coverage across its network up to 2029, explicitly citing the federal order as a reason to accelerate. That's a data point worth sitting with — a private infrastructure company adjusting its own migration timeline in direct response to a government deadline aimed, on paper, at federal systems.
PQC-Protected Web Traffic, 2025
Cloudflare Radar, 2025 Year in Review
Interpolated monthly shape between Cloudflare's published Jan (~29%) and early-Dec (~52%) anchors — Cloudflare Radar, 2025 Year in Review
Q-Day: what the experts actually think
None of this matters unless a CRQC is a real prospect, so it's worth asking plainly how close anyone thinks we actually are. The most concrete recent signal came from Google: on December 9, 2024, Google announced Willow, a 105-qubit chip demonstrating "below threshold" quantum error correction — meaning that, for the first time on this hardware, adding more qubits reduced the error rate rather than compounding it, a long-sought milestone published in Nature. Willow generated a follow-up result on October 22, 2025, called "Quantum Echoes," described as a verifiable quantum-advantage computation. Both are real engineering milestones. Neither is a CRQC capable of breaking RSA-2048, and Google has not claimed otherwise. I go into the hardware roadmap in more depth in an earlier look at where quantum computing actually stands in 2026, if you want the fuller picture.
For the actual probability estimate, the most careful public source I could find is the Global Risk Institute's 2024 Quantum Threat Timeline Report (Mosca and Piani, published December 2024), which surveyed 32 quantum-computing experts. It's worth quoting the range rather than collapsing it to one number, because the range is the finding: the probability of a CRQC capable of breaking RSA-2048 within 24 hours existing within 10 years runs from about 19% (pessimistic estimate) to about 34% (optimistic estimate) among respondents. Within 5 years, the optimistic figure drops to around 14%. Extend the horizon and the pessimistic estimate climbs — about 39% within 15 years, about 60% within 20 years — and by the 30-year mark, 28 of the 32 experts surveyed assign at least a 70% likelihood. Cryptographers sometimes frame the underlying logic as an inequality: if the number of years your data must stay secret, plus the number of years your migration will take, exceeds the number of years until a CRQC arrives, you've already lost the race before you noticed you were running it. That's the actual argument for moving now on a threat that most experts still put at well under even odds within a decade — the migration timeline, not the quantum-computing timeline, is the variable actually inside anyone's control.
Q-Day Probability by Horizon
Global Risk Institute, 2024 Quantum Threat Timeline Report (32 experts)
Probability a cryptographically relevant quantum computer exists within each horizon, per 32 expert respondents — Global Risk Institute, 2024 Quantum Threat Timeline Report
The federal scaffolding underneath the order
EO 14412 didn't appear out of nowhere; it's the newest layer on a stack of federal cryptography policy that's been under construction since 2022. National Security Memorandum 10 (NSM-10), signed May 4, 2022, set the original direction, instructing agencies to begin planning for post-quantum migration. The NSA followed in September 2022 with CNSA 2.0 (Commercial National Security Algorithm Suite 2.0), which mandates specific algorithm parameters — ML-KEM-1024 and ML-DSA-87, the higher-security parameter sets — for national security systems, on its own staggered schedule: new NSS acquisitions are required to be CNSA-2.0-compliant by January 1, 2027, with most other systems expected to transition by 2033. In between, OMB Memorandum M-23-02 (November 2022) required federal agencies to complete inventories of their vulnerable cryptographic systems, laying the groundwork for exactly the kind of CBOM reporting EO 14412 now formalizes with a deadline attached.
One thing that stack does not include, at least in anything I could verify: a public dollar figure for what this migration actually costs. NSM-10 requires OMB to deliver a cost estimate to Congress, so that reporting obligation exists — but I haven't found a published number I'd trust to repeat, and I'd rather leave that gap visible than fill it with a plausible-sounding estimate. Federal IT modernization at this scale is the kind of project that tends to touch the same legacy-systems problem showing up across cloud and agentic infrastructure spending more broadly — a lot of money moving, without a clean public accounting of where.
The Policy and Standards Timeline
NIST CSRC; whitehouse.gov; NSA CNSA 2.0 advisory
- May 2022NSM-10 signedsets the original PQC migration direction
- Sep 2022CNSA 2.0 publishedNSA mandate for national security systems
- Aug 2024FIPS 203/204/205 finalizedML-KEM, ML-DSA, SLH-DSA standards locked
- Mar 2025HQC selectedfifth, code-based backup KEM; final ~2027
- Jun 2026EO 14412 signedenforceable federal deadlines
- Dec 2030Key-establishment deadlinefederal high-value/high-impact systems
- Dec 2031Signature deadlinefederal high-value/high-impact systems
The view from Kathmandu
The quantum threat feels genuinely abstract from a rooftop in Kathmandu. Nobody here is worried about a CRQC breaking RSA-2048 on any timescale you could put a date on. But the TLS handshake protecting a bank login in Kathmandu runs the same protocol stack as the one protecting a bank login in Washington or Singapore, and that stack is being rebuilt, piece by piece, on the same global schedule — mostly invisible, mostly automatic, mostly something end users will never notice happened. The Cloudflare number that struck me hardest in reporting this wasn't 52%; it was that most of the climb to 52% happened because a handful of companies (Apple, Signal, Google) flipped defaults, not because anyone individually opted in. That's probably the honest shape of this migration everywhere it succeeds: not a decision anyone in Kathmandu or anywhere else makes deliberately, but a default that arrives quietly in a software update, years ahead of the deadline that made it mandatory.
Sources
- The White House — Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks," signed June 22, 2026 (whitehouse.gov)
- The White House — Executive Order 14413, "Ushering in the Next Frontier of Quantum Innovation," signed June 22, 2026 (whitehouse.gov)
- NIST Computer Security Resource Center — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA), finalized August 13, 2024
- NIST — HQC selection as fifth PQC algorithm, announced March 11, 2025
- NIST — FIPS 206 (FN-DSA/Falcon) draft status, as of mid-2026
- Cloudflare Radar — 2025 Year in Review, post-quantum traffic share (~29% to ~52%, Jan–Dec 2025); Cloudflare Blog, full-PQC 2029 target announcement, April 2026
- Apple Security Blog — iMessage PQ3 (Feb 2024); iOS 26/macOS Sequoia PQ defaults (Sept 2025); Signal Technical Blog — PQXDH (Sept 2023)
- Google Blog; Nature — Willow chip and below-threshold error correction, Dec 9, 2024; "Quantum Echoes" result, Oct 22, 2025
- Global Risk Institute — 2024 Quantum Threat Timeline Report, Mosca and Piani, December 2024 (32 expert respondents)
- National Security Memorandum 10, signed May 4, 2022; NSA CNSA 2.0 advisory, September 2022; OMB Memorandum M-23-02, November 2022
Written by Abhishek Kushwaha, founder and writer at Global Tech Search, based in Kathmandu, Nepal.
