28 July 2026
The clock is ticking on one of the most profound technological disruptions in history. Quantum computing, once the domain of theoretical physicists and science fiction, is approaching a threshold that will reshape the foundations of digital security. When a sufficiently powerful quantum computer runs Shor's algorithm, it will factor large prime numbers in minutes instead of millennia. That single capability will break RSA encryption, elliptic curve cryptography, and virtually every public-key system that protects online banking, secure communications, and digital signatures today.
The question is not whether this will happen, but when. And the more pressing question for governments, industries, and individuals is what we should do about it right now. Regulating quantum computing before it breaks encryption is not a luxury. It is a necessity that most policymakers have barely begun to address.

The specific threat to encryption comes from two algorithms. Shor's algorithm, developed by Peter Shor in 1994, can factor large integers and compute discrete logarithms in polynomial time. This directly attacks RSA, Diffie-Hellman, and elliptic curve cryptography. Grover's algorithm, while less dramatic, provides a quadratic speedup for brute-force searches, effectively halving the security of symmetric encryption like AES.
Most people assume this is a distant problem. They think quantum computers are still too small, too error-prone, and too expensive. That assumption is dangerous. The progress in quantum computing over the last five years has been staggering. Companies like IBM, Google, and IonQ have demonstrated quantum processors with over 100 qubits. While error correction remains a major hurdle, the trajectory is clear. A fault-tolerant quantum computer capable of breaking 2048-bit RSA could exist within a decade, possibly sooner.
None of these efforts address the core regulatory question: How do we prevent or mitigate the damage when quantum computers break encryption? The answer is not to ban quantum computing, which would be both impossible and counterproductive. Quantum computers have enormous potential for drug discovery, materials science, optimization, and climate modeling. The goal is to manage the transition so that encryption breaks do not cause catastrophic failures in critical infrastructure.
If you send an encrypted email today, an adversary could capture it and store it for ten years. When quantum computers mature, that email becomes readable. This is not a theoretical concern. Intelligence agencies have been doing this for decades with classical computing improvements. Quantum computing makes the threat absolute because the data will eventually be decryptable regardless of key length.
Regulation must address this by mandating timelines for migrating to quantum-resistant cryptography. Organizations that handle long-lived secrets, such as government agencies, healthcare providers, and financial institutions, need to begin transitioning now. Waiting until the quantum computer exists is too late.

The National Institute of Standards and Technology (NIST) has been running a multi-year process to select and standardize PQC algorithms. In 2024, NIST finalized standards for three primary algorithms: CRYSTALS-Kyber for key encapsulation, and CRYSTALS-Dilithium, FALCON, and SPHINCS+ for digital signatures. These algorithms are based on lattice-based cryptography, hash-based cryptography, and code-based cryptography.
CRYSTALS-Kyber offers relatively small key sizes and good performance, making it suitable for general use. However, its security relies on the hardness of the Learning With Errors problem, which is still being studied. If new attacks emerge, the algorithm could become weaker than expected.
SPHINCS+ is a stateless hash-based signature scheme that relies only on the security of hash functions, which are well understood. But its signatures are large, sometimes exceeding 40 kilobytes. That is fine for firmware updates but problematic for constrained devices or high-volume transactions.
FALCON provides small signatures and fast verification but has complex implementation requirements. It is harder to deploy securely without side-channel vulnerabilities.
Regulators cannot simply mandate "use PQC." They must specify which algorithms for which use cases, and they must allow for algorithm agility so that systems can switch if a chosen algorithm is broken.
Regulators should require that all new systems, especially those handling long-lived data, support multiple cryptographic algorithms simultaneously. This allows a gradual migration. For example, a system might use both RSA and CRYSTALS-Kyber for key exchange, with the quantum-resistant algorithm taking precedence once it is proven.
Regulators should establish phased deadlines. For example, all new systems deployed after 2025 should include PQC support. Existing systems handling data with a lifespan beyond 2035 should begin migration by 2028. Systems handling national security information should have even tighter timelines.
Export controls on quantum computers are already in place in some countries, but they are inconsistent. A more effective approach would be to control access to the algorithms and software libraries that implement Shor's algorithm at scale. However, this is difficult because the algorithm is publicly known and can be implemented on any sufficiently powerful quantum computer.
A better regulatory focus is on the cryptographic infrastructure itself. Requiring that all encryption products sold or deployed in a jurisdiction include PQC support creates a market incentive for adoption. It also ensures that even if a quantum computer is built elsewhere, the data it can access is limited.
Hash functions like SHA-256 are also relatively resistant. Grover's algorithm can find preimages faster, but the security margin remains high for practical purposes.
The primary threat is to public-key cryptography used for key exchange and digital signatures. Regulators should prioritize these systems without panicking about all encryption.
QKD requires dedicated fiber optic links or satellite connections. It does not work over the existing internet infrastructure without significant modification. It also does not provide authentication, so it must be combined with classical cryptography to prevent man-in-the-middle attacks. And it is expensive.
For most applications, PQC is a more practical solution. QKD may be useful for specific high-security links, but it is not a general replacement for public-key cryptography.
Smart regulation creates certainty. It gives companies clear targets and timelines. It encourages investment in PQC products because there is a guaranteed market. It also protects consumers and national security by preventing catastrophic failures.
The migration to PQC will be far more complex because it affects not just hash functions but the entire public-key infrastructure. Every TLS certificate, every code signing key, every email signature, every VPN connection will need to change.
A better example is the transition from DES to AES in the late 1990s and early 2000s. That transition took over a decade and required coordination between governments, standards bodies, and industry. Even then, some systems still use Triple DES decades after AES was standardized.
NIST's PQC standardization process is a good model. It was open, transparent, and rigorous. It considered security, performance, and implementation difficulty. The result is a set of algorithms that can be referenced in regulations.
However, standards bodies are slow. They move at the pace of consensus, which is often too slow for technological change. Regulators should not wait for final standards before acting. They can reference draft standards or require algorithm agility that allows for future updates.
This inventory will reveal dependencies that are not obvious. For example, many cloud services use elliptic curve cryptography for TLS. If those services do not support PQC, you need to plan for migration.
This creates a race. The United States, China, the European Union, and others are investing heavily in quantum research. But the regulatory response is uneven. China has centralized control and can mandate cryptographic migration across its entire infrastructure. Democratic countries must balance regulation with privacy and market freedom.
International coordination is essential but difficult. The cryptography used in one country affects the security of global communications. If the United States mandates PQC but China does not, the weakest link determines overall security. Adversaries will target the jurisdictions with the weakest protections.
Regulators should prioritize interoperability. They can do this by referencing common standards, allowing multiple algorithms, and requiring backward compatibility during transition periods.
First, establish a national cryptographic transition office with authority to coordinate migration across government agencies. This office should publish timelines, provide technical guidance, and fund research into implementation challenges.
Second, require all government procurement of cryptographic products to include PQC support. This creates a market demand that drives industry adoption. It also ensures that government systems are protected.
Third, mandate that critical infrastructure sectors, including energy, finance, healthcare, and transportation, submit cryptographic transition plans. These plans should include inventories, timelines, and risk assessments.
Fourth, fund education and training for cybersecurity professionals. Quantum-safe cryptography requires new skills. The current workforce is largely unfamiliar with lattice-based cryptography and its implementation challenges.
Fifth, engage in international diplomacy to establish common standards and timelines. The alternative is a fragmented internet with incompatible cryptographic systems.
Waiting for a crisis is not a strategy. Regulating quantum computing before it breaks encryption is about managing risk, not eliminating it. No regulation can guarantee that quantum computers will not break encryption. But smart regulation can ensure that the damage is limited, that systems are resilient, and that the transition is orderly.
The alternative is a world where encrypted communications become transparent overnight, where digital signatures cannot be trusted, and where every piece of data collected today is readable tomorrow. That world is avoidable, but only if we act now.
all images in this post were generated using AI tools
Category:
Tech PolicyAuthor:
Kira Sanders