Quantum computing in government and the public sector

For public agencies, quantum computing is mainly a cryptography migration with published deadlines, and a policy question about national quantum programs.

PQC · policy

For a public agency, quantum computing in government has a calendar that most private companies don’t have yet. The United States, the European Union and several allied governments have published dates for moving off RSA and elliptic-curve cryptography, and those dates are close enough that projects starting in 2027 will already be late. Everything else a government might do with quantum computers is research and industrial policy.

Which post-quantum deadlines already bind US and European agencies?

US civilian agencies must mitigate as much quantum risk as feasible by December 31, 2030, under OMB memo M-26-15, and finish remaining systems by 2035. National security systems follow the NSA’s CNSA 2.0 dates. EU member states agreed to start by the end of 2026 and move critical infrastructure no later than the end of 2030.

The US timeline has been built in layers since 2022:

Date Document What it asks for
May 4, 2022 National Security Memorandum 10 Mitigate as much quantum risk as feasible by 2035
November 18, 2022 OMB memo M-23-02 A prioritized inventory of systems with quantum-vulnerable cryptography by May 4, 2023, then every year
2022 Quantum Computing Cybersecurity Preparedness Act OMB migration guidance and agency migration plans
August 13, 2024 NIST FIPS 203, 204 and 205 The first post-quantum standards
November 2024 Draft NIST IR 8547 Deprecate RSA and elliptic-curve algorithms in 2030, disallow them in 2035
June 22, 2026 Executive order “Securing the Nation Against Advanced Cryptographic Attacks” Accelerated federal migration
June 24, 2026 OMB memo M-26-15 Mitigate as much risk as feasible by December 31, 2030, and submit a migration plan within 120 days, which puts the deadline in late October 2026

CNSA 2.0 is more granular than the civilian memo. According to The Quantum Insider’s summary of the NSA timeline, networking equipment should use CNSA 2.0 algorithms exclusively by 2030, and operating systems, custom applications and cloud services by 2033, with full quantum resistance across national security systems by 2035.

M-26-15 lays out five phases, from strategy and discovery in 2026 and 2027 through full migration by 2035, and requires plans to align with NIST IR 8547. It doesn’t apply to national security systems. Those follow the NSA’s CNSA 2.0 suite, which expects new acquisitions to comply from January 1, 2027.

In Europe, member states adopted a coordinated implementation roadmap in June 2025. It asks all of them to start the transition by the end of 2026, to move critical infrastructure no later than the end of 2030, and to finish as far as feasible by 2035.

Why does quantum computing in government start with cryptography?

Quantum computing in government starts with cryptography because governments hold data that must stay secret for decades and run some of the oldest systems in any economy. Encrypted traffic recorded today can be decrypted once a large quantum computer exists, and finding every vulnerable system across a ministry takes years.

Governments hold data with the longest confidentiality windows of any sector: intelligence, diplomatic cables, tax and health records, census microdata, identity documents. An adversary who records encrypted government traffic today can wait. This is the harvest now, decrypt later problem, and it is why the security agencies set their dates long before anyone has built a quantum computer large enough to break RSA.

Governments also run the oldest systems. A ministry can have mainframes, PKI for national ID cards, embedded devices in traffic control and radio networks that all use different cryptographic libraries. Finding them is the slow part, which is why M-26-15 leans so heavily on automated inventory.

What are Latin American governments doing about quantum risk?

Latin American governments are working on quantum strategy, research funding and sector coordination, not on binding migration deadlines. Chile published a national quantum technologies strategy in December 2025, Colombia formed a post-quantum working group in June 2026, and Mexico set up a Quantum Safe advisory council in September 2026.

We haven’t found a Latin American government that has published a binding post-quantum migration deadline for its agencies. Chile’s National Quantum Technologies Strategy for 2025 to 2035 names energy, mining, telecommunications and logistics among the sectors where it expects quantum solutions to be tested. In Colombia, a first sector working group on post-quantum cryptography brought together government, academia, finance and critical infrastructure in June 2026, and the science ministry’s ColombIA Inteligente 2026 call funds quantum projects, including secure communications. Brazil’s science ministry has said the country will invest R$5 billion in quantum technology through 2034. In Mexico, the Mexican Internet Association created the Consejo Consultivo Quantum Safe México on September 22, 2026, to issue recommendations to regulators and sectors.

Latin American agencies will feel the US and EU dates anyway. Cloud providers, browsers, HSM vendors and certificate authorities are moving to post-quantum defaults for their global customer base, and agencies that exchange data with US or European counterparts will be asked about their plans.

Beyond cryptography

Governments are also large buyers of the problems quantum computers may eventually help with: transport and energy network planning, scheduling of public services, and simulation for health and materials research. None of these is a reason to buy quantum hardware today. The useful public role right now is funding research, training people, and making sure procurement teams can tell a real quantum claim from a marketing one.

What should an agency do first about post-quantum migration?

An agency should first name an accountable official, build a cryptographic inventory that starts with high-value assets, and write post-quantum requirements into every new purchase. Vendor roadmaps and training come next. OMB’s M-26-15 describes this as the strategy, planning and discovery phase, running through 2026 and 2027.

  1. Name an accountable official for post-quantum migration. M-26-15 is explicit that this is a responsibility of the whole leadership team, not only the CIO and CISO.
  2. Build or update the cryptographic inventory, starting with high-value assets and systems that protect data with long confidentiality needs.
  3. Add post-quantum and crypto-agility requirements to every new procurement, including cloud and identity services.
  4. Ask your top ten vendors for dated post-quantum roadmaps.
  5. Train the people who will run the migration and the people who will approve its budget.

How AndesQubit can help

We work with public institutions and their contractors in Spanish and English. A quantum readiness assessment produces the inventory and prioritization that migration plans ask for, and our post-quantum cryptography migration work takes it from plan to rollout. For ministries shaping national programs, the quantum strategy and roadmap service covers policy options and skills. We are opening engagements in stages; contact us to join the early-access list.

Sources

  1. OMB, Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, June 24, 2026
  2. OMB, Memorandum M-23-02, Migrating to Post-Quantum Cryptography, November 18, 2022
  3. NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
  4. The Quantum Insider, Quantum security deadlines are here (CNSA 2.0 timeline), May 8, 2026
  5. European Commission, EU reinforces its cybersecurity with post-quantum cryptography, June 23, 2025
  6. Expansión, México crea consejo para anticipar riesgos del cómputo cuántico, September 22, 2026

Questions we get about this

What is the US deadline for federal agencies to move to post-quantum cryptography?

National Security Memorandum 10 (May 2022) set the goal of mitigating as much quantum risk as feasible by 2035. OMB memo M-26-15, issued June 24, 2026, tightened this for civilian agencies. It asks them to mitigate as much risk as feasible by December 31, 2030, to submit migration plans within 120 days, and to finish remaining systems by 2035.

What is CNSA 2.0?

It is the NSA's Commercial National Security Algorithm Suite 2.0, the set of quantum-resistant algorithms required for US national security systems. New national security system acquisitions must support it from January 1, 2027, with most categories moving to exclusive use between 2030 and 2033 and the whole transition done by 2035.

What does the EU post-quantum roadmap require?

The coordinated implementation roadmap adopted by EU member states in June 2025 asks every member state to start transitioning by the end of 2026, to move critical infrastructure no later than the end of 2030, and to complete the migration as far as feasible by 2035.

Do Latin American governments have post-quantum deadlines?

Not with fixed dates yet. Chile published a national quantum technologies strategy for 2025 to 2035, Colombia formed a first sector working group on post-quantum cryptography in June 2026, and Mexico's internet association set up a Quantum Safe advisory council in September 2026. Agencies in the region will also feel the US and EU dates through their vendors.

Can quantum computers help governments with anything besides security?

Possibly, in time. Public agencies run large optimization problems in transport, energy grids and scheduling, and fund research that depends on simulation. Today classical methods still do this work better, so the practical role for most agencies is funding research and building skills.

Get in before the queue forms

We are taking a short list of companies for our first readiness assessments and post-quantum migrations. Tell us what you are working on and we will get back to you within two business days.

Write to us