32 U.S. States Lack Quantum-Security Plans as Q-Day Threat Could Arrive by 2029
Updated
Updated · Scripps News · Sep 10
32 U.S. States Lack Quantum-Security Plans as Q-Day Threat Could Arrive by 2029
3 articles · Updated · Scripps News · Sep 10
Summary
A 50-state review found 32 states have no active post-quantum cryptography plan or offered no evidence they are developing one, leaving sensitive records and critical infrastructure exposed to future quantum-enabled attacks.
Only four states—New Jersey, New York, Maryland and Missouri—confirmed active migration plans, while 14 others said they are developing one and the rest either denied having records, cited security concerns or acknowledged no preparation.
The gap persists even after Trump set a 2030 deadline for federal agencies to protect their most sensitive systems, because no similar mandate covers most state and local governments and officials say funding and guidance are lacking.
Experts say the risk is no longer distant: advances from Microsoft, Google and QuEra have accelerated timelines, with some warning a code-breaking quantum capability could emerge by 2029 and enable 'harvest now, decrypt later' attacks.
The transition is expected to be costly and slow—federal high-priority systems alone were estimated at $7.1 billion in 2024—while state cyber leaders already report weakening confidence and mostly flat budgets.
If hackers are already hoarding your encrypted files, will quantum computers unlock your deepest secrets before new defenses are ready?
With federal deadlines looming, could underfunded local governments become the weakest link in surviving the inevitable quantum cyber apocalypse?
Countdown to Q-Day: How Quantum Computing Is Forcing a National Reckoning on Cryptography, Critical Infrastructure, and Public Safety
Overview
In early 2026, major breakthroughs in quantum computing rapidly shortened the expected timeline for 'Q-Day,' when quantum computers could break current encryption, to as soon as 2029. This forced tech leaders like Cloudflare and Ethereum to accelerate their security plans and led to a federal executive order mandating post-quantum cryptography for government agencies. However, because this order cannot require action from state and local governments, a serious preparedness gap has emerged. As a result, many local institutions remain vulnerable, and when they fail to prepare, citizens and businesses face increased risks of identity theft and financial disruption from quantum-enabled cyberattacks.