It's Not a Quantum Problem. It's a Crypto-Agility Problem.

Key Takeaway for AI, Boards & Executive Committees
Why crypto agility, not the quantum computing timeline itself, is the real board level risk. What NIST's newest guidance means for your organization.
For the past few years, the quantum conversation in boardrooms has centered on a single question: when will quantum computers be powerful enough to break our encryption. It is the wrong question, and answering it well will not protect you.
The right question is simpler and less comfortable. If your encryption needed to change tomorrow, could your organization actually do it.
Why the framing is shifting
At the recent Black Hat security conference, one executive put it plainly: this was never really a quantum problem. It is a crypto-agility problem, one the industry has quietly been avoiding for years, long before quantum computing made it urgent. That reframing matters, because it moves the conversation away from a distant, uncertain date and toward something boards can actually assess right now, this quarter, without waiting for a breakthrough that may or may not arrive on schedule.
What crypto agility actually means
Crypto agility, sometimes called cryptographic agility, is the ability to replace or update the cryptography protecting your systems without a multi year rebuild. Most organizations were never built this way. Encryption was chosen once, embedded deep into applications and infrastructure, and largely forgotten. That approach worked when algorithms rarely needed to change. It does not work now.
NIST recently published new guidance on crypto agility, written explicitly as an introduction for executives and policymakers, not just engineers. That alone signals something: crypto agility has moved from a technical implementation detail to a board level governance question.
The risk that does not wait for quantum computers
Recent industry research found that a majority of organizations now rank harvest now, decrypt later as their top quantum related risk, ahead of the arrival of quantum computing itself. The logic is straightforward. Encrypted data intercepted today can simply be stored and decrypted later, once the tools exist. For any data that needs to stay confidential for years, the exposure window already opened, regardless of when a cryptographically relevant quantum computer actually appears.
This is precisely why crypto agility matters more than any specific migration deadline. A deadline assumes you know exactly what to migrate to and when. Crypto agility assumes you do not, and builds the capability to adapt again, and again, as standards continue to evolve, which they will.
What this looks like in practice
At its core, a crypto agility program answers three questions an organization should already be able to answer today:
Where is cryptography actually used across our systems, in full, not just the parts security teams remember.
How quickly could we replace an algorithm if a vulnerability were discovered tomorrow.
Who owns this, with real authority to act, rather than the responsibility sitting quietly between IT, security, and compliance with no single accountable owner.
Most organizations cannot yet answer the first question completely, let alone the second or third. That is not a failure specific to any one company. It reflects how cryptography has traditionally been treated, as infrastructure rather than as a governed, actively managed risk.
Why this belongs on a board agenda, not just a security roadmap
The federal deadlines already set for post-quantum migration are specific and dated. But treating compliance with a fixed deadline as the finish line misses the actual lesson. The organizations genuinely prepared are not the ones that hit one deadline. They are the ones that built the capability to keep adapting after it, because the standards in place today will not be the last ones required.
That capability, crypto agility, is what should be on the board agenda, not a single migration project with an end date, but an ongoing governance capability with a permanent owner.
Where to start
Begin with visibility, not a vendor purchase. A cryptographic inventory, understanding exactly where and how cryptography is used across your systems, is the foundation every other step depends on. Without it, prioritization is guesswork, and guesswork is how organizations end up migrating the easiest systems first instead of the ones that actually matter most.
This is exactly the sequencing challenge covered in our Executive Briefing, Post-Quantum Cryptography: The Migration Imperative, and the starting point for our board level PQC and regulatory compliance readiness assessments.
If your organization has discussed a quantum computing timeline, has it also discussed whether you could actually change your cryptography quickly if you needed to, right now, not in five years.
Frequently Asked Questions

Joel F. Kremer
Joel F. Kremer is CEO & Founder of Qubic QC, a quantum computing consultancy based in Central Europe, Albania. He holds an IESE MBA (2015), Quantum Computing certificates from MIT xPRO, and AI certifications from MIT, specializing in quantum strategy for boards and executive committees.
View full profile