up:: 00 Field Guide Map
Analysis
Analysis is the part of this Guide where I argue rather than explain. A reference note teaches a concept that a competent reader could not reasonably dispute, and an analysis note defends a claim that a competent reader genuinely could. Both are held to the same citation standard; only the thing being asserted is different.
Most of what I argue here converges on a single observation: the post-quantum transition is not failing on mathematics, and the mathematics is the part that has gone well. It is failing on ownership, on attention, on procurement, and on the fact that the threat produces no visible event to react to.
Map of content
A short overview of the arguments running through this Guide, and the index that routes you to each one. Skim it to see the through-line, then follow the links to the full case.
The short version:
- The hard problem was solved and the field moved on to the hard problems. The algorithms exist, they came out of an open international process, and everything still unresolved sits above them.
- The transition stalls organizationally. Ownership is unassigned, cryptography is invisible in most estates, and no engineer is rewarded for replacing something that currently works.
- The threat is built to produce no warning. Harvesting is silent, a break can stay classified for years, and there is no incident to point at when asking for budget.
- The strongest skeptic arguments are worth answering properly. No quantum computer can break RSA today, the timelines have slipped before, and a case that cannot survive those facts is not worth making.
- The unresolved layer is political rather than technical. Divergent national requirements, an unverifiable capability, and a norms vocabulary that has no word for silent collection.
What separates analysis from reference here?
One test, applied to the note’s central sentence. If a knowledgeable reader could not reasonably disagree with it, the note is reference. If they could, and the note earns the claim anyway, it’s analysis.
| Reference note | Analysis note | |
|---|---|---|
| Anchored on | An entity: a term, algorithm, standard, or component | A claim someone could dispute |
| Answers | ”What is it, and how does it work?" | "Why is this happening, and what follows?” |
| Success looks like | Complete, correct, and nobody argues | The strongest objection is stated and answered |
| Citation standard | Every load-bearing claim to a primary source | Identical, and the interpretation is labeled as interpretation |
| Example | FIPS 203 (ML-KEM) | Why Post-Quantum Migrations Stall |
The citation row is the one that matters most. Argument does not lower the evidentiary bar, it raises it, because a disputable claim built on unsourced facts is just an opinion with footnote-shaped decoration. What differs is that an analysis note has to make clear which sentences are documented and which are my read of the documents.
Why does the transition keep stalling?
Because the difficulty moved. Choosing replacement algorithms was a coordination problem with a technical answer, and an open international standardization process produced one. What remains has no equivalent mechanism.
- Nobody owns cryptography. It’s embedded in systems owned by teams who did not choose it and cannot see it, so a migration has no natural home in an org chart. Why Post-Quantum Migrations Stall · Cryptographic Ownership
- Governance precedes engineering. A technically perfect roadmap produces no motion without a decision structure behind it. Why Is Quantum Readiness a Governance Problem
- The threat resists attention. Slow, invisible, and lacking a triggering event, which is the exact profile human risk perception handles worst. Why Is the Quantum Threat So Easy to Ignore
- Strong cryptography fails at human seams anyway. The historical record of cryptographic failure is mostly governance, key handling, and trust decisions rather than broken mathematics. Why Does Strong Cryptography Still Fail
- Deploying is not the same as being protected. Resistance arrives when the vulnerable algorithm is removed, and adding a new one alongside it changes nothing on its own. Deprecation, Not Deployment
Why can’t you wait for the announcement?
Because the design of the threat removes the announcement. A cryptographic break is an intelligence asset, and the incentive of whoever achieves it first is to say nothing and read quietly. Meanwhile the collection that makes the break valuable is already happening and leaves no trace at either endpoint.
- The No-Warning Problem argues the case that no announcement is coming.
- The Quantum Capability Asymmetry argues that recording has become cheap and widely available while reading will stay expensive and rare, and that nobody can verify who crosses the line.
- Did We Know the Quantum Threat Was Coming places it in the 40-year record of trusted ciphers being retired on schedule rather than in surprise.
- Do Cryptographic Algorithms Last Forever argues cryptography was always a replaceable subsystem, which reframes this transition as maintenance rather than as an emergency.
What do the skeptics get right?
More than the marketing around this subject admits, which is why the skeptic case gets its own notes rather than a dismissal.
No cryptographically relevant quantum computer exists. Published timelines have moved before. Plenty of vendors have an interest in urgency. Any argument for acting now has to survive all three of those facts, and an argument that only works by ignoring them convinces nobody worth convincing.
- Is the Quantum Threat Overhyped takes the skeptic case seriously and marks which parts hold.
- Is Q-Day Another Y2K examines the most common analogy and finds the disanalogy that matters: Y2K was a date everyone could see, and this is a threshold crossed in private.
- Can AI Build Your Cryptographic Inventory pushes back on the current enthusiasm, arguing AI narrows the search and cannot produce a traceable inventory.
What is still unresolved at the political layer?
The technical layer has answers. The layer above it does not, and these are the arguments about that.
| Open question | The argument | Where it’s made |
|---|---|---|
| Do allied systems still interoperate after migration? | Nations are migrating to different parameters on different timelines, and NATO’s own strategy lists a quantum-safe alliance as an undated objective | The Coalition Interoperability Gap |
| Is harvesting already an act of cyber conflict? | The doctrine made exactly this move for pre-positioning in 2024 and has never applied it to cryptographic collection | Is Harvesting Encrypted Data an Act of Cyber Conflict |
| Who will actually be able to decrypt? | Collection has democratized while decryption concentrates, and possession leaves nothing to verify | The Quantum Capability Asymmetry |
| Should post-quantum run alongside classical or replace it? | Four national authorities disagree, and each is hedging a different failure mode | ANSSI vs BSI vs NCSC vs NSA on Hybrid |
| Which sector has the hardest version of this? | Telecom, because its most exposed surface runs on a card in the subscriber’s pocket and its second depends on bilateral operator agreements | Why Mobile Networks Are the Hardest Migration |
Common misconceptions
- “Analysis means it’s less rigorous.” The citation standard is identical. What differs is that the claim is disputable, so the note has to state the counterargument rather than skip it.
- “These are predictions.” No note here puts a date on a quantum computer. Dated forecasts age into liabilities, and the arguments are built on published evidence rather than on projections.
- “The skeptic notes undercut the rest of the Guide.” They test it. A case for urgency that cannot survive “no such machine exists yet” was never a case worth making.
- “Analysis is where the advice lives.” It isn’t. These notes argue about the world, and they stop before telling any particular organization what to do, which is the same line every note in this Guide holds.
Questions people ask
What makes a note analysis rather than reference? Whether a knowledgeable reader could reasonably disagree with its central sentence. Reference notes teach things that are settled, analysis notes defend claims that are not, and both cite every load-bearing fact to a primary source.
Are these opinion pieces? They’re arguments built on cited evidence, which is a narrower thing. The facts are documented and the interpretation is mine, and each note tries to make clear which sentences are which.
Why do analysis notes still appear in the topical sections? Because their up:: deliberately stays topical, so a reader working through The Threat still meets the arguments about the threat. This hub indexes them without removing them from the journey.
Do you argue against your own field’s consensus? Where the evidence supports it. The skeptic notes exist because parts of the standard urgency case do not hold up, and saying so is more useful than repeating a pitch.
How is this different from the newsletter? These are the durable versions, maintained and re-verified with a date on each one. Newsletter writing tracks the news cycle and this layer is meant to still be correct in 3 years.
Do the arguments get updated when the evidence changes? Yes, and the verified date on each note records the last time it was checked against its sources. A corpus-wide check also fails any note quoting a superseded figure without the current one beside it.
Which one should I read first if I only read one? Why Post-Quantum Migrations Stall, because almost every other argument here is a consequence of it.
Go deeper
The stall, and why it’s organizational: Why Post-Quantum Migrations Stall · Why Is Quantum Readiness a Governance Problem · Why Is the Quantum Threat So Easy to Ignore · Why Does Strong Cryptography Still Fail · Deprecation, Not Deployment
The threat, and why it stays invisible: Is Harvesting Encrypted Data an Act of Cyber Conflict · The No-Warning Problem · The Quantum Capability Asymmetry · Did We Know the Quantum Threat Was Coming · Do Cryptographic Algorithms Last Forever
The skeptic case, taken seriously: Is the Quantum Threat Overhyped · Is Q-Day Another Y2K · Can AI Build Your Cryptographic Inventory
The political layer: Why Mobile Networks Are the Hardest Migration · The Coalition Interoperability Gap · ANSSI vs BSI vs NCSC vs NSA on Hybrid (a comparison note rather than analysis, and it carries an argument worth reading alongside these)
The reference material these arguments rest on starts at the map, the deadlines driving them are in the mandates, and the human and organizational ground most of them stand on is in the human side.
Everything here is the map, given freely. When one of these arguments has to become a defensible position for a specific organization, in front of a specific regulator or board, that’s the work I do at LaMarr Labs.
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.