in , ,

QuSecure Exec Says Quantum Threat Timeline Moved to 2029

Garfield Jones. The QuSecure SVP said  quantum computers capable of breaking encryption are expected in 2029.
Garfield Jones SVP, Strategy QuSecure
  • Assessments now put a cryptographically relevant quantum computer by 2029, against a prior consensus of 2035
  • Adversaries are collecting encrypted federal data now to decrypt once that capability exists
  • Agencies still planning around the 2035 date are working from an outdated threat model

The arrival of quantum computers capable of breaking the encryption protecting federal data has moved the timeline by six years, and agencies budgeting against the older date are behind, said QuSecure Senior Vice President of Research and Strategy Garfield Jones in a commentary Federal News Network published Tuesday.

Jones previously served as associate chief of strategic technology at the Cybersecurity and Infrastructure Security Agency, where he led its post-quantum cryptography work.

Researchers expected a commercially viable, cryptographically relevant quantum computer to emerge by 2035, but Jones said assessments, drawing on a Google paper published in March, now point to 2029 for a fault-tolerant machine.

What Is the Harvest-Now, Decrypt-Later Threat?

Data stolen from federal networks today is not always used today, Jones wrote. Much of it is stored, held by adversaries who expect to read it once computing power exists, particularly a quantum computer running Shor’s algorithm, which could break the Rivest-Shamir-Adelman algorithm and elliptic-curve encryption.

Jones argued the exposure extends past government to defense contractors, critical infrastructure operators, financial institutions and healthcare systems.

What Does Jones Recommend Agencies Do?

Post-quantum cryptography, or PQC, is the remedy, and it already exists, he wrote. The National Institute of Standards and Technology formalized its first standards in 2024, now designated Module-Lattice-Based Key-Encapsulation Mechanism, Module-Lattice-Based Digital Signature and Stateless Hash-Based Digital Signature.

He laid out a sequence: inventory every system and data store running RSA or elliptic-curve encryption; deploy tools built around crypto-agility; press vendors on readiness road maps, particularly for operational technology that cannot be upgraded quickly; protect the most sensitive data categories first; and use hybrid approaches during the transition to PQC.

Jones also tied the PQC migration to CISA’s condition, noting that departures he attributed to budget pressure, policy uncertainty and workforce erosion have cost the agency experienced analysts and incident responders. Rebuilding that workforce is a prerequisite for a migration of this scope, he wrote.

What Is QuSecure Offering?

QuSecure offers QuProtect R3, a platform for scanning cryptographic assets, rolling out NIST-approved algorithms and documenting compliance. It has been available on the AWS Marketplace for the intelligence community since July.

QuSecure joined the NIST National Cybersecurity Center of Excellence consortium on post-quantum migration in March, and took a $3.9 million AFWERX small business research award the same month for quantum-resilient encryption supporting Air Force Global Strike Command.

ExecutiveBiz Logo

Sign Up Now! ExecutiveBiz provides you with Daily Updates and News Briefings about Cybersecurity

mm

Written by Kristen Smith

Niccolo de Masi. IonQ's CEO commented on DARPA's It's About Time program and his company's acquisition of Vector Atomic.
DARPA Awards IonQ Contract for Atomic Clock Production
Deloitte logo. Deloitte has deployed a dual-track, integrated approach to public sector software development.
Deloitte Deploys Dual-Track Approach to Public Sector Software Development