Insights
CIO Insights: 5 Questions on Post-Quantum Cryptography
In his recent article, Ryan Haylock, Chief Information Officer of Evolver, analyzed the mandate for Post-Quantum Cryptography (PQC) as a fundamental technical debt challenge facing federal IT leaders, rather than a simple procurement decision. To dive deeper into the strategic execution required for quantum readiness, we sat down with Ryan with five questions related to the PQC technical debt issue.
Q: You describe post-quantum cryptography as “technical debt that chose you.” What do you mean by that?
Ryan Haylock: Most technical debt has an origin story. It comes from decisions organizations make over time: deferred upgrades, legacy platforms, competing priorities. You can usually explain how it accumulated and why it exists.
Post-quantum cryptography is different. No federal CIO chose this debt. It arrived because the cryptographic world changed. NIST has finalized new standards, established a timeline for retiring today’s algorithms, and every federal agency now has an obligation to migrate. Whether an agency planned for it or not, the work is here. That is why I describe it as technical debt that chose you.
Q: Many vendors position PQC as a product. Is this really a procurement decision?
Ryan Haylock: No. That framing sends organizations down a path the underlying problem does not actually fit.
You cannot procure your way out of this. There is no single platform that makes an agency post-quantum ready. The migration touches certificates, VPNs, identity providers, applications, embedded systems, cloud services, and countless cryptographic implementations that have accumulated over decades. The work is to understand what cryptography you have, prioritize it against the deprecation timeline, and migrate it in phases that your organization can sustain.
That is technical debt management. Tools are part of the answer, but not the answer itself.
Q: If you’re advising a federal CIO in 2026, where should they begin?
Ryan Haylock: Begin with the inventory. The federal guidance is already telling agencies where to start. OMB requires annual inventories because you cannot prioritize or migrate what you have not identified.
The first inventory will almost certainly be incomplete. That is not a failure; it is the nature of environments where cryptography has been embedded across decades of technology investments. Each annual cycle should deepen the inventory, improve visibility, and strengthen the migration plan. Agencies that build that discipline early will move faster, at lower cost, and with less operational risk over the rest of the transition.
Q: What does a successful post-quantum migration program look like?
Ryan Haylock: The successful programs will share a common characteristic: they treat PQC as a continuous operational discipline rather than a one-time project.
They build inventories that mature over time. They prioritize high-value systems before attempting broad migration. They design for crypto-agility, recognizing that today’s standards are unlikely to be the last evolution in quantum-safe cryptography. And they pace the work according to operational capacity rather than the calendar.
That is how long-term technical debt gets managed. It is sustained, deliberate work, not a sprint to a milestone.
Q: How should CIOs think about the “harvest now, decrypt later” threat?
Ryan Haylock: It is a real threat, and it deserves to be acknowledged. Adversaries can collect encrypted information today with the expectation that future quantum capabilities may allow that data to be decrypted years from now. For information with a long sensitivity lifetime, that changes the conversation.
At the same time, I do not think fear is the right organizing principle for this work. The right response is the same disciplined technical debt management the migration requires regardless. The threat explains why the timeline matters. It does not change the nature of the work itself. The agencies that build sustained operational capacity for discovery, prioritization, and migration will be better positioned than those looking for a single technology to solve the problem.
About Evolver
Evolver, headquartered in Reston, Virginia, is a technology company serving government and commercial customers by addressing client challenges in the present and transitioning clients to the future through innovative IT transformation and cybersecurity services and solutions.
Founded in 2000, Evolver delivers mission-driven services and solutions that improve security, promote innovation, and maximize operational efficiency. For more information, visit us at www.evolverinc.com or on LinkedIn.