up:: Doing the Work MOC
Why Is Quantum Readiness a Governance Problem?
I’ve watched teams hold a technically perfect post-quantum roadmap and go nowhere with it for a year. The algorithm choices were right, the sequencing was sound, and the engineers who wrote it understood the cryptography better than anyone else in the building. It sat still anyway. When I ask what’s holding it there, the answer is organizational every time. No one’s name is on the program, the board has never been asked to fund it, and nobody in the room has the standing to make five other teams move at once.
At a quantum security summit in Washington this summer, I was the only person on the stage who talked about the org chart. Everyone else talked about qubits, lattices, and timelines, and every word of it was correct. The line that formed afterward wanted to tell me the same thing in different words, that the part which actually decides whether their migration happens is organizational, and I was the only one naming it. The claim this essay makes is plain: quantum readiness is a governance problem long before it’s a technology problem, and the org chart, rather than the algorithm, is where it’s won or lost.
Where a migration actually stalls
The cryptography is the solved half of this problem. NIST has published the replacement standards, a capable engineer can deploy them, and the reference architectures for doing it safely are well understood. The transition runs on three dimensions at once, technical, organizational, and human, and the two that stall it are the last two. That’s the thing the field keeps underweighting, and it’s the reason a flawless roadmap can produce motion of zero. This is the whole argument of Why Post-Quantum Migrations Stall, and it lands on governance.
Governance is the layer where a technical finding turns into a funded program with an owner, a cadence, and a queue that keeps moving. A migration described only in the language of key sizes and handshake groups tends to stop at the boundary between the security team and the people who control the budget. The real work of readiness is carrying it across that boundary, and that work is organizational.
The empty owner’s seat
Ask five people in most organizations who owns the post-quantum migration, and you’ll get five different answers or five shrugs. Cryptography has run quietly in the background for decades, so no one was ever put in charge of the whole of it, and it now sits in the seams between engineering, infrastructure, identity, procurement, and governance while each function assumes another one holds it. Responsibility spread that thin looks covered on paper and is owned by no one in practice.
A program with no accountable owner drifts, because there’s no one with the standing to commission an inventory, resolve a cross-team dispute, or move budget. Naming a single accountable executive is the true first act of a migration, ahead of discovery and ahead of any code. How that ownership gets structured lives in Cryptographic Ownership. The point here is that it’s a governance decision, and it’s the one every downstream step quietly depends on.
Quantum risk already has a home in the framework you run
A team doesn’t need a separate quantum framework to govern this. Quantum risk is a fresh instance of an ordinary category of cyber risk, and the NIST Cybersecurity Framework already has rooms for it. The 2024 revision added Govern as the anchoring function, the place where cybersecurity strategy, roles, policy, oversight, and supply-chain risk management live.1
That’s exactly where the quantum decisions belong. Treating quantum-vulnerable cryptography as an enterprise risk, assigning it an owner, setting policy, and pressing vendors for post-quantum roadmaps all sit under Govern. Finding where cryptography actually hides across the estate is asset management, which sits under Identify, and it’s the job a cryptographic inventory does for the crypto layer. Deploying the new algorithms falls under Protect. The framework stays deliberately silent on how to migrate, and it gives the program a structure a board and an auditor already recognize, which is most of the distance between a technical finding and a funded decision.
Does writing a cryptography policy count as governance?
It’s tempting to answer the quantum question by writing a cryptography policy, filing it, and calling the estate governed. A standalone cryptography policy can genuinely help: it gives crypto-agility and ownership a single home, and it reads coherently to a regulator who wants to see cryptographic governance in one artifact. Whether it earns its place depends on the size and volatility of the cryptographic surface, and NIST itself models both a dedicated policy and rules folded into broader ones.2
The trap is treating the document as the achievement. A policy names the approved algorithms and the accountable owner, and naming rules is the easy part. Compliance and resilience are different things, and a policy that restates controls the estate doesn’t actually have manufactures comfort while the systems stay quantum-vulnerable. Real governance is the policy backed by an inventory, an owner, and working capability, so the paper is worth exactly as much as the program standing behind it.
Readiness is measured by what’s gone
Governance also decides what the scoreboard counts, and most migration scoreboards measure the flattering thing. They count where a post-quantum algorithm has been switched on, which feels like progress, when the number that reflects real security is how many systems can still fall back to RSA or classical Diffie-Hellman. A migration that has deployed everywhere and deprecated nothing has closed no exposure, because every classical primitive a quantum computer breaks is still reachable on the wire.
The mandates define the finish line as removal with a date attached. NIST’s transition schedule deprecates the vulnerable public-key algorithms after 2030 and disallows them after 2035, and the U.S. Department of War’s 2026 strategy sets a full-transition gate at 2031.3 The governance discipline is to hold the program to deprecation over deployment, and to report the metric an auditor and a quantum computer both actually test, which is what’s been removed rather than what’s been added. Choosing which number the board sees is itself a governance act, and it’s the one that keeps a program honest.
Has an org chart decided a security outcome before?
It has, and the cleanest example I know sits inside the NSA’s own history. For years the agency’s defensive arm, the Information Assurance Directorate, was housed away from the main Fort Meade campus at the airport annex, while the offensive mission sat at headquarters. When the agency came under pressure to elevate defense, it raised the directorate’s budget and left its address alone, as Fred Kaplan documents in Dark Territory.4 The money went up and the placement stayed put.
The placement was telling a truth the budget line obscured. Where a function sits, how many layers it stands from the decision-maker, and whether it’s in the strategy conversation or summoned after it are expensive and political to fake, so they carry honest information about priority. Post-quantum migration is defensive, patch-type, success-is-invisible work, precisely the kind an organization exiles to its own annex. If cryptography is already three rooms from power when the transition arrives, no budget line rescues it, because the problem was organizational all along.
Where readiness is actually won
So the truest thing I can tell you about quantum readiness is that its decisive work is governance work. It’s naming the accountable owner, locating quantum risk inside the framework you already run, deciding whether a dedicated policy earns its place and backing it with real capability, and measuring the program by the vulnerable algorithms you’ve actually removed. Each of those is a decision the org chart makes, and the cryptography is the part that was ready first.
The engineers can hand you a roadmap that’s right in every particular. Whether it moves is settled somewhere else entirely, in who’s accountable, what the board has agreed to fund, and how the organization keeps a multi-year program alive through reorganizations and competing quarters. Handle that layer with the same seriousness you’d give the algorithm choice, and the roadmap you already have finally starts to move, because the math was ready long before the organization was.
Go deeper
- The Five-Name Test: asks five people who owns the migration, and reads the answer for a vacuum.
Everything here is the map, given freely. When your team needs the governance layer of the transition designed and run as deliberately as the cryptography, so a finished roadmap turns into real motion, that’s a working session with your team.
Last verified 2026-07-26 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.
Footnotes
-
NIST, “The NIST Cybersecurity Framework (CSF) 2.0,” NIST CSWP 29, February 26, 2024, §2 (the Govern function). nvlpubs.nist.gov ↩
-
NIST models both placements. It treats policy as a Govern-function outcome in the CSF (category GV.PO) and embeds cryptographic controls in the System and Communications Protection family in SP 800-53 Rev. 5, while separately defining a dedicated Key-Management Policy in SP 800-57 Part 1 Rev. 5. NIST CSWP 29, nvlpubs.nist.gov; NIST SP 800-57 Part 1 Rev. 5, doi.org/10.6028/NIST.SP.800-57pt1r5. ↩
-
NIST IR 8547 (Initial Public Draft), “Transition to Post-Quantum Cryptography Standards,” November 2024, §4 (112-bit RSA, ECDSA, and ECDH deprecated after 2030; classical RSA, ECC, and Diffie-Hellman disallowed after 2035). csrc.nist.gov. U.S. Department of War, “Post-Quantum Cryptography (PQC) Strategy,” 2026 (every system uses PQC by December 31, 2031). dodcio.defense.gov ↩
-
Fred Kaplan, Dark Territory: The Secret History of Cyber War (Simon & Schuster, 2016). The account of the Information Assurance Directorate housed at the airport annex away from Fort Meade headquarters, and of the agency raising its budget while leaving its placement unchanged, is drawn from Kaplan’s history. ↩