Prioritizing the Post-Quantum Migration: What the Federal Government Already Told Us

In 2022 CISA had RAND triage all 55 National Critical Functions for quantum risk; the finding was that a small number of upstream dependencies carry a disproportionate share of national risk.

Key Findings
  1. 1PQC risk is not uniform: RAND rated 34 of 55 National Critical Functions low priority and only 6 high priority.
  2. 2Three chokepoints — internet and content services, identity and trust services, and IT products — must ship PQC before anyone downstream can migrate.
  3. 3Harvest Now, Decrypt Later is real but narrow, rational mainly against long-secrecy national-security data.

Recommendations
  • Sequence migration spend by data secrecy lifetime and OT cost and latency constraints rather than migrating everything at once.
  • Monitor the three critical enablers, since delays there delay everyone downstream.
  • Treat vendors claiming a fully mapped, all-encompassing PQC solution with skepticism.

Source: RAND HSOAC, RR-A1367-6 (commissioned by CISA), 2022

Executive summary

In 2022, the Cybersecurity and Infrastructure Security Agency (CISA) did something most organizations still have not done: it commissioned a federally funded think tank to run a portfolio-level risk assessment on the entire U.S. economy. The question was simple. When quantum computers become powerful enough to break today's encryption, which parts of the country break first, and where should the government put its limited attention?

The answer came from RAND's Homeland Security Operational Analysis Center (HSOAC), the FFRDC RAND operates under contract to DHS. Analysts triaged all 55 National Critical Functions (NCFs) — the government's official list of the sectors and activities that keep the country running — and scored each one for urgency, scope, cost, and priority.

The headline finding for any executive building a business case: this is not a uniform problem, and it does not require a uniform response. A small number of dependencies carry a disproportionate share of national risk. Fix those first, and the rest of the economy gets a meaningfully easier migration.

That is a resource-allocation story, not a technology story, and it is exactly the kind of finding a board wants stated in plain terms before it approves budget.


Who funded this and why it matters

CISA does not commission independent, arm's-length risk assessments casually. This one was sponsored by CISA's National Risk Management Center and executed by RAND's HSOAC under a standing DHS task order. In other words, this is not vendor research, not a think-tank thought piece, and not marketing collateral from a cybersecurity company with a product to sell. It is the closest thing the private sector has to a government-validated risk map for post-quantum cryptography.

For any executive vetting vendor claims about quantum risk, this report is a useful baseline. It predates most commercial PQC marketing, and it was built with no incentive to inflate urgency across the board. In fact, the analysts explicitly rated 34 of the 55 functions as low priority. A study designed to sell fear would not have done that.


The methodology, in plain terms

Think of this as a classic risk-adjusted prioritization exercise — the kind an operating committee would run before allocating capital across business units. RAND scored each of the 55 functions on four dimensions:

  • Urgency — how soon does this need to be fixed, based on how long sensitive data must stay confidential
  • Scope — how many organizations have to act
  • Cost — how expensive is the fix per organization
  • Other factors — anything that makes the problem structurally easier or harder (workforce availability, existing modernization efforts, regulatory fragmentation, and so on)

Those four scores rolled up into a single priority-for-assistance rating: high, medium, or low. This is a portfolio triage model, not a checklist. It is designed to tell a resource-constrained principal — in this case, the federal government — where to spend its attention first.


The core finding: three chokepoints carry the portfolio

RAND identified three functions as critical enablers of the entire national migration. These are the vendors and infrastructure providers who build the tools everyone else needs in order to move to post-quantum cryptography at all.

Critical enablerWhat it actually does
Provide Internet-Based Content, Information, and Communication ServicesBuilds the browsers, TLS implementations, and communication protocols the rest of the internet runs on
Provide Identity Management and Associated Trust Support ServicesIssues and manages the digital certificates that underpin authentication everywhere
Provide Information Technology Products and ServicesBuilds the hardware and software the rest of the economy buys and deploys

The business logic here is straightforward: nobody else can migrate until these three groups ship PQC-capable products first. A hospital, a bank, or a pipeline operator cannot encrypt traffic with an algorithm their software vendor hasn't built yet. This is a supply chain dependency problem before it is anything else, and RAND's most important strategic recommendation was to monitor these three chokepoints closely, because a delay here delays everyone downstream.


The six functions rated highest priority

Beyond the three enablers, RAND flagged six functions overall as high priority for federal assistance:

  1. Internet-Based Content and Communication Services (also a critical enabler)
  2. Distribute Electricity
  3. Protect Sensitive Information
  4. Generate Electricity
  5. Information Technology Products and Services (also a critical enabler)
  6. Provide Materiel and Operational Support to Defense

Two patterns explain why electricity and defense made this list even though they are not enablers themselves.

The grid is a special case of a broader operational technology problem. Eighteen of the 55 functions depend heavily on industrial control systems, and most of those were rated low priority because ICS equipment tends to get replaced on a normal hardware refresh cycle anyway. Electricity generation and distribution broke from that pattern because of three compounding factors: equipment is spread across enormous geography, control systems require real-time low-latency response with little tolerance for disruption, and the regulatory and technology standards vary widely across regions and providers. In plain terms, the grid has the same underlying problem as every other OT-heavy sector, just with a materially harder cost and coordination profile layered on top.

Defense support made the list for a different reason entirely: it is a genuine "harvest now, decrypt later" target. RAND's report makes a subtle but important distinction. Most industries transmit data with a short enough shelf life — personal records, trade secrets — that an adversary capturing encrypted traffic today and cracking it in ten years gains little of value. National security data is the exception. It is exactly the kind of information a sophisticated nation-state adversary would find worth the multi-year investment to steal now and unlock later.


The business takeaway: not all risk is created equal, and that's good news

The report's four cross-cutting conclusions translate directly into a prioritization framework any operator can use:

1. Everyone has homework, but not everyone has the same amount. Every organization, regardless of sector, should be building cryptographic agility into its technology roadmap now. But "everyone must eventually act" is not the same message as "everyone must act with equal urgency," and conflating the two wastes budget.

2. A small number of upstream fixes de-risk a large number of downstream dependents. This is the single most useful sentence in the report for a capital allocation conversation: a relatively small number of critical changes by a relatively small number of stakeholders will mitigate a significant share of the nation's aggregate exposure. That is a leverage argument, and leverage arguments win budget approvals.

3. The harvest now, decrypt later threat is real but narrow. Running a multi-year data-harvesting campaign against encrypted traffic is expensive and logistically hard. It is only rational for an adversary to do this against a small number of very high-value targets, primarily national security data. Most organizations do not need to treat this scenario as an emergency; they need to treat it as a normal item on the modernization roadmap.

4. This field is still young, and vendors claiming certainty should be treated with skepticism. RAND is candid that a comprehensive inventory of what needs to change across the American technology stack did not exist at the time of the report, and still largely does not. Anyone selling a fully mapped, all-encompassing PQC solution today is getting ahead of where the underlying standards work actually is.


Why this matters for anyone building a PQC business case

This report gives operators, CISOs, and boards three things a vendor pitch deck cannot: government-validated framing, a defensible prioritization logic, and permission to not treat every system as equally urgent. The organizations best positioned to benefit are the ones that use this kind of independent risk stratification to sequence their migration spend, starting with genuine long-secrecy-lifetime data and OT environments with real cost and latency constraints, rather than migrating everything at once out of generalized anxiety.

The federal government already did the hard work of separating signal from noise. The opportunity now is operational: turn that prioritization into an actual migration program.

Sources

  1. M. J. D. Vermeer, E. Parker, and A. K. Kochhar, "Preparing for Post-Quantum Critical Infrastructure: Assessments of Quantum Computing Vulnerabilities of National Critical Functions," RAND Corporation, Homeland Security Operational Analysis Center, RR-A1367-6, 2022. Sponsored by CISA's National Risk Management Center.
  2. Cybersecurity and Infrastructure Security Agency, "CISA Insights: Preparing Critical Infrastructure for Post-Quantum Cryptography," August 2022.
  3. Cybersecurity and Infrastructure Security Agency, "Post-Quantum Cryptography Initiative," 2024.
  4. National Institute of Standards and Technology, "Module-Lattice-Based Key-Encapsulation Mechanism Standard," FIPS 203, August 2024.
  5. National Institute of Standards and Technology, "Module-Lattice-Based Digital Signature Standard," FIPS 204, August 2024.
  6. National Institute of Standards and Technology, "Stateless Hash-Based Digital Signature Standard," FIPS 205, August 2024.
  7. Cybersecurity and Infrastructure Security Agency, "Automated Cryptography Discovery and Inventory (ACDI)," Strategic Framework, 2024.
  8. Executive Office of the President, "Presidential Policy Directive 21 (PPD-21) — Critical Infrastructure Security and Resilience," February 2013.

Turn the research
into a plan.

Get the analysis for your own stack. Start with a scan or a working session.