\Why read this
Most quantum-readiness plans ask “how strong is our encryption?” That’s the wrong question. The right one is “how long does this data need to stay secret — and will our encryption still hold when that clock runs out?” This week, a hard federal deadline, a hyperscaler’s rollout schedule, and a healthcare compliance ruling all landed on the same answer: retention, not algorithm strength, is what decides your actual exposure. If your data classification policy doesn’t have a column for “years until this stops mattering,” this edition is about building one.
Every edition of The Imperative & The Important uses two lenses. The Imperative is what happened this month that demands a reaction. The Important is what will still be true after the headlines fade.
First, the acronyms. Post-quantum cryptography (PQC) is the family of encryption algorithms designed to resist attack by quantum computers, standardized by the U.S. National Institute of Standards and Technology (NIST). Harvest-now-decrypt-later (HNDL) is the practice of an adversary capturing your encrypted data today and simply waiting to decrypt it once quantum computers can. The Federal Information Processing Standard (FIPS) 140 series governs which cryptographic modules the government — and much of the vendor ecosystem selling to it — is allowed to buy. Keep all three in mind: this story is about the countdown clock each one starts.
The Imperative
1. A federal cryptography deadline most companies don’t know applies to them arrives September 21. NIST’s Cryptographic Module Validation Program (CMVP) moves every remaining FIPS 140-2 certificate to Historical status on that date. Nothing already deployed breaks — but Historical-listed modules can no longer be specified in new federal procurement, and the consequence reaches past government buyers: audit frameworks like CMMC 2.0 and NIST SP 800-171 Control 3.13.11 require “FIPS-validated cryptography” for controlled information, and a Historical certificate may not satisfy that requirement going forward. CMVP’s own validation queue currently averages more than 500 days (SafeLogic, ComplianceHub). Business impact: if any product, HSM, or VPN gateway you sell or depend on cites a FIPS 140-2 certificate, that citation stops carrying procurement weight in three weeks — and the replacement pipeline is more than a year long.
2. A hyperscaler just told its customers exactly when their defaults will change — and it isn’t now. Google Cloud published its full PQC roadmap in August: quantum-safe key exchange on load balancers is available today but disabled by default, flips to enabled-by-default in October 2026, and becomes mandatory — no deferral option — in October 2027. Cloud KMS reached general availability for NIST-standardized ML-KEM, ML-DSA, and SLH-DSA algorithms this same window (Google Cloud). Business impact: “our cloud provider handles this” is true on a specific published timeline, not immediately. Any workload that needs quantum-safe transport before October 2027 has to opt in — the default won’t save you early.
3. Healthcare just got a preview of what “long-lived data” means in dollars and years, not just theory. A peer-reviewed analysis in Frontiers in Health Services mapped HIPAA’s technical safeguards against quantum risk and found the mismatch is structural: the HIPAA Security Rule treats encryption as an “addressable” safeguard with no algorithm mandate, while state retention laws routinely keep electronic protected health information (ePHI) in active systems and backups for 10 to 21 years — sometimes decades longer for minors’ records (Frontiers in Health Services; PQC Information). Business impact: this isn’t unique to healthcare. Any sector with multi-year retention obligations — financial records, legal files, R&D archives, critical infrastructure telemetry — has the identical mismatch between “encrypted today” and “safe for as long as retention requires.”
The Important: The Data You Encrypted Today Has an Expiration Date You Didn’t Set
Every edition this quarter has widened the same trio — discovery, agility, governance — one layer at a time: identities, then the cryptographic estate itself. This week the trio applies to something even more foundational: the clock already running on every dataset you’re storing.
The Cloud Security Alliance’s applied research puts a number on it: data with a confidentiality requirement longer than five years should be treated as high HNDL exposure today, and data needing ten-plus years of confidentiality is the highest-priority asset class for action, full stop (Cloud Security Alliance). That threshold isn’t exotic. Most enterprise data blows past it without anyone noticing: financial records, signed contracts, source code, litigation holds, customer PII in backup tapes, and — per this week’s healthcare evidence — anything touching regulated records at all.
Here’s the classification most data policies are still missing: sensitivity today and confidentiality horizon are two different axes, and only the second one determines HNDL risk. A dataset can be low-sensitivity now and still be high-risk, if it must stay confidential for a decade. A dataset can look protected today — strong encryption, access controls, the works — and still be a liability the moment someone captures the ciphertext and waits.
The discipline, applied to retention specifically:
· Discovery — classify data by confidentiality horizon, not just current sensitivity. Ask “how many years must this stay secret,” not just “how sensitive is this now.” Include backups, archives, and cold storage — the copies nobody classifies because nobody looks at them.
· Agility — for anything crossing the five-year horizon, confirm there’s a realistic re-encryption path, not just a strong current cipher. A vault full of AES-256 you can’t re-key without downtime is agility on paper only.
· Governance — reducing what you retain is itself a control. Shorter retention windows, fewer redundant copies, and deletion of data that’s outlived its purpose shrink the pool of ciphertext an adversary can harvest in the first place. That’s a policy decision, not a cryptography purchase.
The Imperative changes weekly. The Important is your homework either way.
Three Questions for Your Board
1. Do we classify data by how long it must stay confidential — not just by how sensitive it is today? If the answer is no, we don’t actually know our harvest-now-decrypt-later exposure; we’re guessing.
2. Which of our cryptographic modules, HSMs, or vendor certifications still cite FIPS 140-2 — and do we have a funded path to FIPS 140-3 before that citation stops satisfying procurement and audit requirements? The queue is over 500 days. Waiting is not a plan.
3. What is our retention-reduction policy, and when did we last delete data that no longer needs to exist? Every redundant copy of long-lived encrypted data sitting in cold storage is inventory for an adversary who is already collecting.
The Imperative & The Important is the briefing from Carl’s Corner — timely developments and the durable ideas underneath them, across post-quantum cryptography, IoT and OT security, cybersecurity, and enterprise AI.
Sources
· SafeLogic — Cryptography Compliance Deadlines 2026–2027: https://www.safelogic.com/blog/cryptography-compliance-deadlines-2026-2027
· ComplianceHub — The Quiet Post-Quantum Deadline: On September 21, 2026: https://compliancehub.wiki/post-quantum-fips-140-2-historical-list-september-2026-cnsa-procurement-deadline/
· Google Cloud — PQC in Plaintext: Google Cloud’s Post-Quantum Cryptography Roadmap: https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap
· Frontiers in Health Services — Post-quantum cryptography for healthcare: securing electronic protected health information: https://www.frontiersin.org/journals/health-services/articles/10.3389/frhs.2026.1901282/full
· PQC Information — PQC and HIPAA: What Healthcare Compliance Officers Must Do: https://www.pqcinformation.com/pqc-and-hipaa-what-healthcare-compliance-officers-must-do-before-the-security-rule-rewrites-the-rules/
· Cloud Security Alliance — Harvest Now, Decrypt Later: Quantum Risk to AI Infrastructure: https://labs.cloudsecurityalliance.org/research/ai-infrastructure-post-quantum-harvest-now-decrypt-later-v1/
#PostQuantumCryptography #PQC #QuantumReadiness #Cybersecurity #DataRetention #TheImperativeAndTheImportant
