Denis Mandich is the Cofounder of Qrypt, a quantum cybersecurity firm, and founding member of the Quantum Economic Development Consortium.
Washington did two things during the summer of 2026 that appeared contradictory.
The first was on June 22, when the White House issued two quantum executive orders. One (EO 14413) accelerated quantum technology, and the other (EO 14412) directed federal agencies to move high-value and sensitive systems to post-quantum cryptography for key establishment by 2030 and digital signatures by 2031.
Three weeks later, the Cybersecurity Maturity Model Certification (CMMC) program launched a top-to-bottom review with the stated objective of removing costs and bureaucratic barriers driving smaller and nontraditional companies out of the defense industrial base.
One policy tightens the cryptographic deadline, while the other loosens a certification regime, but this isn’t a contradiction at all. It transfers the high burden from paperwork to engineering, which is much harder and more resource-intensive, even with AI assistance. The CMMC pause didn’t eliminate the obligation to protect federal data because the self-assessments and contractors’ safeguarding obligations remain. What changed is how compliance may be measured, not whether cybersecurity matters in the quantum era.
Meanwhile, EO 14412 put dates on the calendar and called for a cryptographic bill of materials capable of supporting automated assessment, creating an immediate problem for every agency. How do they and their contractors discover, prioritize and migrate decades of cryptography without breaking the systems they’re trying to protect?
The wrong answer is to unleash a hallucinogenic chatbot on a classified codebase and hope for the best. Cryptography demands deterministic outcomes. General-purpose LLMs are statistical systems that can be impressively useful and confidently wrong at the same time. In a marketing campaign, that’s embarrassing. In a weapons system, payment network or intelligence platform, it’s unacceptable and a potential national security nightmare.
Three outcomes now look increasingly likely.
1. Bounded AI will replace much of manual cryptographic discovery.
Every system built on today’s digital infrastructure is quantum-unsafe and riddled with vulnerable classical cryptography. Saying organizations must begin with an inventory is just trivial, an endlessly recycled truism that identifies the obvious without solving anything.
The real challenge is determining which cryptographic dependencies matter most, what can be replaced without breaking mission-critical systems and how to prevent the next algorithm migration from becoming another decades-long, manual reconstruction. NIST’s migration program already emphasizes cryptographic discovery and interoperability. Specialized automation and narrowly trained AI can extend this work through code analysis, binary inspection, configuration review, dependency mapping and migration testing, which doesn’t require frontier AI models (if AI at all).
The useful systems will be smaller, purpose-built and capable of operating locally inside controlled environments. They should produce evidence experts can verify, not written prose that’s grammatically perfect and that operators are expected to trust because it reads well. The White House’s June 2026 memorandum on AI in the national security enterprise sets the right standard: reliable, robust, steerable and controllable systems backed by testing and verification.
There won’t be one universal scanner for every balkanized agency network on the government’s vast global estate. Customization is unavoidable and security-critical, but manual discovery across millions of components isn’t a strategy, either. Although some security purists will inevitably argue it’s the most prudent way to be sure, that approach is just a scheduling failure in disguise. It can’t meet any of the federal deadlines that made the last generation of beltway bandits rich with overruns and delays while the government suffered breaches.
2. AI will become an engineering multiplier for quantum hardware.
EO 14413 established the Quantum Computer for Application Development and Discovery Science effort. The Department of Energy followed with its Quantum Genesis initiative targeting a scientifically relevant, fault-tolerant quantum capability by 2028 with full bipartisan support and billion-dollar budgets. AI will be an engineering multiplier across materials, fabrication, control electronics, calibration and even error correction.
A general-purpose model won’t suddenly invent a better quantum computer. That was never in its training data, and AI isn’t a thinking physicist. However, specialized AI will help engineers search design spaces and operate hardware beyond manual controls in real time, far beyond the current adaptive mechanisms.
The irony is actually very useful because AI will help accelerate quantum computing while also helping defend the infrastructure larger quantum systems threaten.
3. The market will move from algorithms to architecture.
PQC is necessary, and the NIST-standardized algorithms ML-KEM and ML-DSA establish the new baseline. Unfortunately, replacing one algorithm with another while preserving the same brittle key-distribution architecture from the 1970s isn’t real crypto-agility but a hopefully more secure lock on the same single door. There’s no proof that’s even true, but it’s still better than what we’re using today, so the transition is critical regardless.
Harvest now, decrypt later (HNDL) is a long-persistent collection strategy many decades old and doesn’t skip a beat after the PQC transition is done. Adversaries need storage, access and patience, not a cryptographically relevant quantum computer today. Long-lived data is already exposed to whatever capabilities or implementation failures arrive later.
The scalable and durable response is architectural: Separate key establishment from the data plane, reduce the movement of secret key material, derive symmetric keys independently at communicating endpoints where possible, combine PQC with distributed entropy, support hybrid modes, and abstract the cryptographic layer so algorithms can change without rewriting applications.
The companies best positioned won’t be those simply attaching a PQC sticker to a legacy product. They’ll already operate across advanced quantum-secure architecture leveraging quantum entropy, key establishment and orchestration while integrating with existing infrastructure. The goal is removing single points of failure without requiring a rip-and-replace event.
The CMMC suspension gave no agency permission to wait. The 2030 deadline sounds distant only to organizations that have never attempted a cryptographic migration. For everyone else, it has already arrived, and the high-priority systems are already on the practical path to finish early.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







