For a public agency, quantum computing in government has a calendar that most private companies don’t have yet. The United States, the European Union and several allied governments have published dates for moving off RSA and elliptic-curve cryptography, and those dates are close enough that projects starting in 2027 will already be late. Everything else a government might do with quantum computers is research and industrial policy.
Which post-quantum deadlines already bind US and European agencies?
US civilian agencies must mitigate as much quantum risk as feasible by December 31, 2030, under OMB memo M-26-15, and finish remaining systems by 2035. National security systems follow the NSA’s CNSA 2.0 dates. EU member states agreed to start by the end of 2026 and move critical infrastructure no later than the end of 2030.
The US timeline has been built in layers since 2022:
| Date | Document | What it asks for |
|---|---|---|
| May 4, 2022 | National Security Memorandum 10 | Mitigate as much quantum risk as feasible by 2035 |
| November 18, 2022 | OMB memo M-23-02 | A prioritized inventory of systems with quantum-vulnerable cryptography by May 4, 2023, then every year |
| 2022 | Quantum Computing Cybersecurity Preparedness Act | OMB migration guidance and agency migration plans |
| August 13, 2024 | NIST FIPS 203, 204 and 205 | The first post-quantum standards |
| November 2024 | Draft NIST IR 8547 | Deprecate RSA and elliptic-curve algorithms in 2030, disallow them in 2035 |
| June 22, 2026 | Executive order “Securing the Nation Against Advanced Cryptographic Attacks” | Accelerated federal migration |
| June 24, 2026 | OMB memo M-26-15 | Mitigate as much risk as feasible by December 31, 2030, and submit a migration plan within 120 days, which puts the deadline in late October 2026 |
CNSA 2.0 is more granular than the civilian memo. According to The Quantum Insider’s summary of the NSA timeline, networking equipment should use CNSA 2.0 algorithms exclusively by 2030, and operating systems, custom applications and cloud services by 2033, with full quantum resistance across national security systems by 2035.
M-26-15 lays out five phases, from strategy and discovery in 2026 and 2027 through full migration by 2035, and requires plans to align with NIST IR 8547. It doesn’t apply to national security systems. Those follow the NSA’s CNSA 2.0 suite, which expects new acquisitions to comply from January 1, 2027.
In Europe, member states adopted a coordinated implementation roadmap in June 2025. It asks all of them to start the transition by the end of 2026, to move critical infrastructure no later than the end of 2030, and to finish as far as feasible by 2035.
Why does quantum computing in government start with cryptography?
Quantum computing in government starts with cryptography because governments hold data that must stay secret for decades and run some of the oldest systems in any economy. Encrypted traffic recorded today can be decrypted once a large quantum computer exists, and finding every vulnerable system across a ministry takes years.
Governments hold data with the longest confidentiality windows of any sector: intelligence, diplomatic cables, tax and health records, census microdata, identity documents. An adversary who records encrypted government traffic today can wait. This is the harvest now, decrypt later problem, and it is why the security agencies set their dates long before anyone has built a quantum computer large enough to break RSA.
Governments also run the oldest systems. A ministry can have mainframes, PKI for national ID cards, embedded devices in traffic control and radio networks that all use different cryptographic libraries. Finding them is the slow part, which is why M-26-15 leans so heavily on automated inventory.
What are Latin American governments doing about quantum risk?
Latin American governments are working on quantum strategy, research funding and sector coordination, not on binding migration deadlines. Chile published a national quantum technologies strategy in December 2025, Colombia formed a post-quantum working group in June 2026, and Mexico set up a Quantum Safe advisory council in September 2026.
We haven’t found a Latin American government that has published a binding post-quantum migration deadline for its agencies. Chile’s National Quantum Technologies Strategy for 2025 to 2035 names energy, mining, telecommunications and logistics among the sectors where it expects quantum solutions to be tested. In Colombia, a first sector working group on post-quantum cryptography brought together government, academia, finance and critical infrastructure in June 2026, and the science ministry’s ColombIA Inteligente 2026 call funds quantum projects, including secure communications. Brazil’s science ministry has said the country will invest R$5 billion in quantum technology through 2034. In Mexico, the Mexican Internet Association created the Consejo Consultivo Quantum Safe México on September 22, 2026, to issue recommendations to regulators and sectors.
Latin American agencies will feel the US and EU dates anyway. Cloud providers, browsers, HSM vendors and certificate authorities are moving to post-quantum defaults for their global customer base, and agencies that exchange data with US or European counterparts will be asked about their plans.
Beyond cryptography
Governments are also large buyers of the problems quantum computers may eventually help with: transport and energy network planning, scheduling of public services, and simulation for health and materials research. None of these is a reason to buy quantum hardware today. The useful public role right now is funding research, training people, and making sure procurement teams can tell a real quantum claim from a marketing one.
What should an agency do first about post-quantum migration?
An agency should first name an accountable official, build a cryptographic inventory that starts with high-value assets, and write post-quantum requirements into every new purchase. Vendor roadmaps and training come next. OMB’s M-26-15 describes this as the strategy, planning and discovery phase, running through 2026 and 2027.
- Name an accountable official for post-quantum migration. M-26-15 is explicit that this is a responsibility of the whole leadership team, not only the CIO and CISO.
- Build or update the cryptographic inventory, starting with high-value assets and systems that protect data with long confidentiality needs.
- Add post-quantum and crypto-agility requirements to every new procurement, including cloud and identity services.
- Ask your top ten vendors for dated post-quantum roadmaps.
- Train the people who will run the migration and the people who will approve its budget.
How AndesQubit can help
We work with public institutions and their contractors in Spanish and English. A quantum readiness assessment produces the inventory and prioritization that migration plans ask for, and our post-quantum cryptography migration work takes it from plan to rollout. For ministries shaping national programs, the quantum strategy and roadmap service covers policy options and skills. We are opening engagements in stages; contact us to join the early-access list.
Sources
- OMB, Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, June 24, 2026
- OMB, Memorandum M-23-02, Migrating to Post-Quantum Cryptography, November 18, 2022
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
- The Quantum Insider, Quantum security deadlines are here (CNSA 2.0 timeline), May 8, 2026
- European Commission, EU reinforces its cybersecurity with post-quantum cryptography, June 23, 2025
- Expansión, México crea consejo para anticipar riesgos del cómputo cuántico, September 22, 2026