The technical argument about post-quantum cryptography is over. NIST has published the standards, the NSA has set migration timelines for national-security systems, and no serious security leader I talk to still debates whether the transition happens. The argument that is very much alive — the one I keep having in budget meetings with defense suppliers and finance leaders — is how to pay for it, and when.
That is the conversation that actually decides outcomes, because a cryptographic migration is not a purchase; it is a multi-year program that touches nearly every system that authenticates or encrypts anything. Treat it as a line item you'll get to later and the deadline will set the timeline for you — at the worst possible moment and the highest possible cost.
Why this is a budget problem, not a technology problem
The algorithms exist. NIST finalized its first post-quantum standards in 2024, and the drop-in libraries are shipping. What does not exist in most organizations is a funded plan to find every place cryptography is used, prioritize it, and replace it across a portfolio of systems that were never designed to have their cryptography swapped. That is program money and program time, spread across several fiscal years.
The leaders who get this right stop framing it as a security purchase and start framing it as a capital program with a fixed external deadline — closer in character to a regulatory compliance build than to buying a tool. The framing matters because it determines which budget it comes out of and who owns it.
The clock you don't control: harvest now, decrypt later
The reason this cannot wait for a comfortable budget cycle is that the exposure is already accruing. Adversaries do not need a quantum computer today to damage you today; they need only to capture encrypted traffic now and store it until decryption becomes feasible. Every dataset with a long secrecy requirement — defense communications, financial records, health data, intellectual property — is already sitting on a clock you don't control.
That reframes the budgeting question entirely. You are not funding protection against a future event; you are funding the containment of a leak that has already started. Any data that must stay secret for a decade, and could plausibly be exposed within that decade, is effectively at risk right now — and the cost of that risk belongs in this year's plan, not a future one.
Where defense and finance diverge — and where they don't
For defense suppliers, the post-quantum transition arrives entangled with existing compliance obligations. The same programs already funding CMMC evidence and controlled-information handling are the natural home for cryptographic inventory and migration, because the auditors will eventually ask the same question: prove what you encrypt, how, and with what. Folding post-quantum readiness into the compliance program that already has a budget line is usually cheaper than standing up a parallel effort.
For finance, the pressure is different but the deadline is the same. Payment rails, settlement systems, and long-lived signed records all rest on the public-key cryptography that quantum breaks, and regulators are beginning to ask boards for a transition posture. What both sectors share is that the migration is bounded by an external date, not an internal appetite — which is exactly the condition under which underfunding early guarantees overspending later.
A budgeting sequence that survives contact with reality
The first dollar should fund an inventory, not a purchase. You cannot budget a migration you cannot see, and almost no organization can currently answer, on demand, every place it depends on RSA or elliptic-curve cryptography and how long each of those secrets must hold. That inventory, mapped against secrecy horizons, is what turns an unbounded fear into a costed, sequenced plan.
The second tranche funds migration in priority order: longest-lived secrets and highest-value channels first, hybrid cryptography where a cutover is risky, and crypto-agility built in so the next transition is a configuration change rather than another multi-year program. Sequencing by secrecy horizon is what lets you spread the spend across fiscal years without leaving the most exposed data for last.
The third, and the one leaders forget, funds the operating cost of staying migrated — key rotation, monitoring, and the discipline that keeps the old algorithms from creeping back in through a new vendor or an un-reviewed integration. A migration you don't maintain quietly un-migrates itself.
What I tell leaders to put in this year's plan
Even if the full migration spans years, three things belong in the current budget: the cryptographic inventory, the migration of the single most exposed system, and the crypto-agility work that makes every future step cheaper. Those three are affordable now, they are defensible to a board, and they convert a vague existential risk into a program with a first milestone.
The organizations that treat Q-Day as a 2030 problem will fund it in a panic in 2029, with the worst leverage and the least time. The ones budgeting for it now are the ones who will set their own sequence and their own price. The math has already changed; the only decision left is whether you fund the transition on your schedule or on the adversary's.