Picture a burglar who never breaks in. He stands on the sidewalk, photographs the key of every house on the block, and files the prints in a warehouse. The machine that can cut those keys is years from installation, but the photographs cost nothing and never expire. That is the operating logic of “harvest now, decrypt later,” the strategy that has moved post-quantum cryptography from an academic sidebar to a board line item. When the future cost of decryption falls, today’s encrypted data becomes tomorrow’s loss.

Five Signals, One Procurement Schedule

Over the past 90 days, five separate signals have converged into a single market fact: Executive Order 14412 fixing federal post-quantum deadlines, IBM’s $10 billion fault-tolerance commitment, a trio of cryptanalysis papers that cut the estimated qubit budget for breaking RSA-2048 by two orders of magnitude, logical-qubit demonstrations approaching one hundred from Quantinuum and QuEra, and Cloudflare’s disclosure that a majority of human web traffic now negotiates post-quantum key agreement. Read together, they mark the moment the quantum threat stopped being a research question and became a procurement schedule.

The arithmetic explains the urgency. Physical-qubit estimates for factoring RSA-2048 have collapsed from roughly 20 million in 2019 to under one million in Craig Gidney’s 2025 analysis, and below 100,000 in Iceberg Quantum’s February 2026 Pinnacle architecture.

“If you are a CISO, CTO, or policymaker still treating quantum risk as a future problem, that decision should give you pause.” — Craig Gidney, Google Quantum AI

Y2K’s Ghost and the Economics of the Non-Event

The nearest precedent is the Y2K remediation, and it cuts two ways. A disaster that is prepared for reads, in hindsight, as a hoax: the clocks rolled over, the jets flew, and a revisionist industry spent a decade arguing the bug was consultant fiction. Quantum security is already generating its own revisionism. The second lesson is harder. Y2K was a binary, date-bounded fix with a closed inventory; the post-quantum migration is re-keying every door in a city that keeps adding doors. Organizations that treated Y2K as a checklist found orphaned embedded systems a decade later. The post-quantum equivalent — an uninventoried hardware security module, a forgotten TLS terminator — is exactly the asset a harvest-now adversary photographs first.

What the Headlines Miss: Enterprise Security’s Silent Repricing

The first unseen shift is the repricing of long-horizon confidentiality. EO 14412’s contractor clause pushes cryptographic obligations down the supply chain the way Sarbanes-Oxley pushed audit obligations a generation ago: a machine shop holding a federal contract now inherits a 2030 compliance horizon it cannot staff. Flow-down clauses will follow, then insurance underwriting questionnaires, then private-sector paper. Confidentiality is being marked to shelf-life, and trade secrets, health records, and M&A data rooms that must remain sealed past 2030 are the first assets to carry the new premium.

The second is a bottleneck the press releases omit: certification, not mathematics, is the binding constraint. As of early 2026 no hardware security module vendor had completed a FIPS 140-3 Level 3 validation with post-quantum algorithms inside the module boundary. The algorithms are standardized; the procurement pipeline is not. Early movers in finance — SWIFT’s planned PQC-enabled SwiftNet 8.0 with its 15-month migration window, JPMorgan’s quantum-secured Singapore link — will set de facto terms that smaller institutions must later accept on a take-it-or-leave-it basis.

The third is settlement-layer exposure. A public blockchain cannot retroactively re-encrypt its history; every recorded transaction becomes readable the day the underlying curve falls, which is why Federal Reserve research in 2025 flagged Bitcoin’s quantum exposure as structurally distinct from any bank’s. Ethereum’s researchers, by contrast, co-authored the March 2026 Google paper placing elliptic-curve compromise under 500,000 physical qubits and minutes of runtime — “a monumentous day for quantum computing and cryptography,” in co-author Justin Drake’s words, whose confidence in a cryptographically relevant machine by 2032 has “shot up significantly.” For a municipal treasury or a local credit union, the implication is direct: digital-asset custody and the clearing rails behind it have entered the threat model whether or not anyone on staff owns a coin.

The Skeptics’ Ledger: Simulation Is Not Silicon

Precision requires stating what these numbers are not. Sub-100,000-qubit estimates are architectural simulations, not hardware; Scott Aaronson, reviewing the Pinnacle work, drew an explicit line between what simulation demonstrates and what silicon must still prove. Quantinuum’s 94 error-protected logical qubits remain orders of magnitude below Shor scale, and quantum timelines have slipped before. A treasurer who strips budget from ransomware response, business-email compromise, and patch debt to chase a late-decade threat is optimizing for the wrong war, and a migration run as an audit exercise produces compliance theater: an inventory that ends in a PDF rather than in crypto-agility. As Bitcoin developer Bit Paine observed, “I still think roughly 10 years is the more likely timeframe, but I assign an uncomfortably high likelihood that we see something disruptive within five years.” That is a distribution to hedge, not a deadline to panic-buy.

The Risk of Racing: Immature Primitives, Fragmented Stacks

The opposite failure mode also deserves airtime. Urgency is fragmenting the standards map the way data-locality laws fragmented cloud architecture: the U.S. FIPS stack, the EU’s quantum-safe-by-design trajectory, and China’s parallel commercial drive are not converging on one baseline, and incompatible cryptographic stacks are themselves an interoperability liability. Newer primitives carry a shorter cryptanalytic pedigree than RSA’s four decades, and hybrid handshakes, while prudent, widen the near-term attack surface. For a regional bank, sovereignty-driven urgency can price out the defenders it claims to protect: a security budget spent on post-quantum consulting while phishing lures go unfunded is neglect at a higher price point.

The 90-Day Playbook

The response that survives both failure modes is inventory-first, not purchase-first. Run a cryptographic bill of materials now — rotation is impossible for assets you cannot see — and rank exposures by confidentiality shelf-life, not value alone. In every RFP, require a post-quantum roadmap and hybrid ML-KEM support; every major browser has negotiated it by default since 2025, so its absence in a vendor stack is a choice, not a constraint. Federal contractors should review flow-down language before the FAR Council’s proposed rule lands. NIST’s Dustin Moody framed the standards release as a “starting gun rather than a finish line,” and the advice holds for citizens too: keep browsers and devices current, where post-quantum key exchange already runs by default, and discount consumer VPNs advertising themselves as “quantum-proof” — the endpoint, not the tunnel, remains the weak point.

Six Months Out

The picture sharpens by February 2027. The OMB guidance mandated for September 2026 will convert the executive order into agency inventories and contractor audits; the January 2027 CNSA 2.0 deadline will force national-security vendors into public compliance claims; and the first FIPS 140-3 Level 3 post-quantum module validation will likely clear, unlocking the stalled HSM procurement cycle. Bitcoin’s BIP-361 freeze proposal will either advance or collapse, importing quantum anxiety into digital-asset prices for the first time. And by the first quarter of 2027, post-quantum posture should appear in enterprise RFPs the way SOC 2 reports do today — not as a differentiator, but as the price of admission. The burglar may never come. The photographs are already in the warehouse.