---
title: Why the White House Strategy Makes PQC Operational
description: See why the White House cybersecurity strategy makes post-quantum cryptography an immediate operational priority for organisations.
image: https://arqitgroup.com/hubfs/White%20House-1.jpg
---

[Skip to content](https://arqitgroup.com/resources/blog/the-white-house-cybersecurity-strategy-makes-pqc-an-operational-problem#main-content)

[ Close ](https://arqitgroup.com/resources/blog/the-white-house-cybersecurity-strategy-makes-pqc-an-operational-problem#)

- Solutions 
    - [PQC Migration](https://arqitgroup.com/products/encryption-intelligence)
    - [Key Sovereignty ](https://arqitgroup.com/products/ska-platform) 
          - [SKA Edge Controller](https://arqitgroup.com/products/ska-ec)
          - [SKA Central Controller](https://arqitgroup.com/products/ska-cc)
    - [Network Security](https://arqitgroup.com/products/networksecure)
- Sectors 
    - [Telecoms](https://arqitgroup.com/sectors/telecoms)
    - [Defense](https://arqitgroup.com/sectors/defense)
    - [Govt & CNI](https://arqitgroup.com/sectors/govt-cni)
    - [U.S Markets](https://arqitgroup.com/mission-readiness)
- [Resources](https://arqitgroup.com/resource) 
    - [Case Studies](https://arqitgroup.com/resources/tag/case-studies)
    - [Product sheets](https://arqitgroup.com/resources/tag/product-sheets)
    - [White Papers](https://arqitgroup.com/resources/tag/white-papers)
    - [Arqit Terms](https://arqitgroup.com/resources/tag/legal)
    - [Blog](https://arqitgroup.com/resources/blog)
- About 
    - [Our Approach](https://arqitgroup.com/company/our-approach) 
          - [Strong](https://arqitgroup.com/company/our-approach#strong)
          - [Simple](https://arqitgroup.com/company/our-approach#simple)
          - [Scalable](https://arqitgroup.com/company/our-approach#scalable)
          - [Standards-based](https://arqitgroup.com/company/our-approach#standards-based)
    - Our Technology 
          - [Simplicity](https://arqitgroup.com/company/simplicity)
          - [Agility](https://arqitgroup.com/company/agility)
          - [Trust](https://arqitgroup.com/company/trust)
          - [Compliance](https://arqitgroup.com/company/compliance)
    - [Company](https://arqitgroup.com/who-we-are) 
          - [Leadership](https://arqitgroup.com/who-we-are#leadership)
          - [Awards](https://arqitgroup.com/who-we-are#awards)
    - [Partners](https://arqitgroup.com/partners/partners)
    - [Press](https://arqitgroup.com/resources/tag/press-releases)
    - [Careers](https://arqitgroup.com/careers)
    - [Investors](https://ir.arqit.uk/)
- [Book a demo](https://arqitgroup.com/demo/demo-hub)

[![Arqit_Logo_Midnight_Citrus_Horizontal](https://arqitgroup.com/hubfs/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_Midnight_Citrus_Horizontal.svg)](https://arqitgroup.com/)[![Arqit_Logo_Midnight_Citrus_Horizontal](https://arqitgroup.com/hubfs/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_Midnight_Citrus_Horizontal.svg)](https://arqitgroup.com/)

- Solutions 
    - [PQC Migration](https://arqitgroup.com/products/encryption-intelligence)
    - [Key Sovereignty ](https://arqitgroup.com/products/ska-platform) 
          - [SKA Edge Controller](https://arqitgroup.com/products/ska-ec)
          - [SKA Central Controller](https://arqitgroup.com/products/ska-cc)
    - [Network Security](https://arqitgroup.com/products/networksecure)
- Sectors 
    - [Telecoms](https://arqitgroup.com/sectors/telecoms)
    - [Defense](https://arqitgroup.com/sectors/defense)
    - [Govt & CNI](https://arqitgroup.com/sectors/govt-cni)
    - [U.S Markets](https://arqitgroup.com/mission-readiness)
- [Resources](https://arqitgroup.com/resource) 
    - [Case Studies](https://arqitgroup.com/resources/tag/case-studies)
    - [Product sheets](https://arqitgroup.com/resources/tag/product-sheets)
    - [White Papers](https://arqitgroup.com/resources/tag/white-papers)
    - [Arqit Terms](https://arqitgroup.com/resources/tag/legal)
    - [Blog](https://arqitgroup.com/resources/blog)
- About 
    - [Our Approach](https://arqitgroup.com/company/our-approach) 
          - [Strong](https://arqitgroup.com/company/our-approach#strong)
          - [Simple](https://arqitgroup.com/company/our-approach#simple)
          - [Scalable](https://arqitgroup.com/company/our-approach#scalable)
          - [Standards-based](https://arqitgroup.com/company/our-approach#standards-based)
    - Our Technology 
          - [Simplicity](https://arqitgroup.com/company/simplicity)
          - [Agility](https://arqitgroup.com/company/agility)
          - [Trust](https://arqitgroup.com/company/trust)
          - [Compliance](https://arqitgroup.com/company/compliance)
    - [Company](https://arqitgroup.com/who-we-are) 
          - [Leadership](https://arqitgroup.com/who-we-are#leadership)
          - [Awards](https://arqitgroup.com/who-we-are#awards)
    - [Partners](https://arqitgroup.com/partners/partners)
    - [Press](https://arqitgroup.com/resources/tag/press-releases)
    - [Careers](https://arqitgroup.com/careers)
    - [Investors](https://ir.arqit.uk/)
- [Book a demo](https://arqitgroup.com/demo/demo-hub)

<https://arqitgroup.com/resources/blog/the-white-house-cybersecurity-strategy-makes-pqc-an-operational-problem#>

![](https://arqitgroup.com/hs-fs/hubfs/White%20House.jpg?width=300&name=White%20House.jpg)

[Arqit](https://arqitgroup.com/resources/blog/author/arqit)Mar 31, 2026 11:35:38 AM5 min read

# Why the White House Strategy Makes PQC Operational

*The federal deadline is not the decision point. The procurement cycle you are entering today is.*

**The Problem is Operational, Not Theoretical**

Let’s fast forward to 2031. A regional power utility is running a quantum-readiness audit when the inventory tool flags a Schweitzer SEL-351 protective relay (a device that automatically trips a circuit breaker to isolate a fault before a blackout). It was installed in 2009. It is still executing RSA-2048 for SCADA authentication, running its original firmware, and cannot be physically accessed without a scheduled outage requiring 90-day regulatory notice. The device has eleven years of remaining life. The vendor stopped issuing updates in 2024. Replacement lead time is fourteen months.

In isolation, it’s just legacy infrastructure. In aggregate, it’s something else: a predictable, long-lived trust anchor built on aging, deployed, and un-patchable cryptography. An attacker doesn’t need to break in; they can wait. The target is stable, the constraints are known, and the adversary is patient. Once RSA-2048 is no longer a barrier, authentication becomes impersonation, and a device designed to protect the grid becomes a path to disrupt it. Nobody forged a firmware signature that day. Nobody needed to. The window was already open.

An even more immediate concern is that five years of authentication traffic may already be in an adversary's collection, waiting for a quantum computer. This relay is not an edge case. It is the landscape across energy, water, transportation, and industrial manufacturing. The Operational Technology (OT) installed base reflects purpose-built hardware deployed for decades, certified under frameworks that treat firmware changes as safety events, and maintained by vendors whose roadmaps predate PQC as a procurement consideration.

The 2026 White House Cyber Strategy correctly calls for modernization. Yet, for a significant fraction of OT, migration is not a configuration change or library upgrade. It requires capital expenditure, regulatory filings, vendor negotiation, and outage windows. For some devices, full PQC compliance will not be possible before a cryptographically relevant quantum computer (CRQC). That reality needs a plan.

 

**What the Strategy Establishes and What It Doesn’t**

The 2026 strategy avoids prescribing implementation architecture. That is the right call. No federal document can enumerate the constraints between a municipal water utility’s SCADA network and a DoD mission system running on legacy-certified HSMs. What it does provide is procurement latitude: agencies and Critical Infrastructure operators can move faster on PQC adoption without waiting for additional guidance cycles.

NIST has finalized the algorithms, but crypto-agility is the real finish line. Engineers still must determine parameters, hybrid versus pure-PQC approaches, and migration sequencing across heterogeneous environments. And this will not be the last cryptographic transition. The 2026 strategy reflects that reality, accelerating access to private sector capabilities. Sustained partnerships with industry and domain experts will be essential to maintain readiness as requirements evolve.

 

**Where the Math Stops Working**

The SEL-351 scenario has a hardware-level equivalent: an RTU deployed in 2014 running an ARM Cortex-M3 with 128KB of flash. It has no path to running a post-quantum key exchange. The silicon cannot support it. Hardware replacement is the only option, and Industrial Control Systems procurement cycles span five to seven years from specification to commissioning. That’s 2032.

This is where the strategy offers realism. OT systems are expected to be the last platforms to achieve PQC compliance due to patching constraints, hardware timelines, and governance. PQC in OT will be a sustained challenge. This is where innovation can help.

Key size illustrates the issue. ECDH over P-256 fits into ~64 bytes. ML-KEM-768 requires a 1,184-byte public key and a 1,088-byte ciphertext. For a PLC running tight scan cycles over low-bandwidth serial links, such as RS-485 at 9,600 baud, that delta is not an optimization problem; it is an architectural incompatibility. While not universal, these constraints still exist in the field and they are the ones that matter most because they cannot be easily changed.

OT cryptographic constraints are not performance inconveniences; in many cases, they are hard physical limits. Acknowledging that is not defeatism. It is the starting point for a realistic plan. Fortunately, the OT asymmetric attack surface is narrow: VPN gateways, firmware signing, secure boot chains, and industrial protocol authentication. That scope is small enough to address systematically. This begins with cryptographic inventory and prioritization. Automated Cryptography Discovery & Inventory tools such as Arqit’s Encryption Intelligence provide the sophistication to catalogue and quantify cryptography and associated risks.

An adversary who can forge firmware signatures using a CRQC can compromise entire fleets in a single operation. CNSA 2.0 prioritizes this attack surface. NIST SP 800-208 already approves stateful hash-based signatures for firmware signing, and viable implementations exist today. More and more, near-term approaches include deploying PQC wrappers to protect existing systems.

In OT environments, cryptographic implementations are owned by the vendors of PLC, SCADA, and relay manufacturers. Procurement must require migration paths to NIST FIPS 203/204/205-compliant firmware and support for algorithm and key replacement over device lifetimes, with no hardcoded cryptography. Where migration is not feasible, compensating controls such as segmentation, unidirectional gateways, out-of-band authentication, and even air gaps, are necessary. That is not failure; it is engineering.

PQC innovations such as Arqit’s NetworkSecure leverage lightweight symmetric keys for quantum-safe protection, reducing dependence on public-key infrastructure while enabling rapid rotation, forward secrecy, and dynamic control. This provides a near-term, cost-effective path to quantum-safe security.

The implication is straightforward: post-quantum readiness is not a single migration event; it is an architectural posture. The systems that will matter most in a CRQC scenario are those that cannot move quickly due to operational constraints and embedded cryptography. That shifts the focus from algorithm selection to control over key distribution, rotation, and trust boundaries. This is where solutions such as Arqit’s symmetric key infrastructure become relevant, not as a replacement for standards-based PQC, but as a complement delivering immediate quantum-safe protection as the ecosystem transitions.

The strategy, the constraints, and the timelines all point to the same conclusion: resilience will come from crypto-agility implemented through procurement, partnerships, and architectures that assume this will not be the last cryptographic transition.

To find out how Arqit can help your organization prepare for PQC migration and remain compliant in the post-quantum world, [get in touch](https://arqitgroup.com/contact-us).

 

---

 

31 March 2026

 

#### **Arqit** 

 

## RELATED ARTICLES

[![Arqit_Logo_White_Citrus_Horizontal](https://7543877.fs1.hubspotusercontent-na1.net/hubfs/7543877/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_White_Citrus_Horizontal.svg) ](https://arqitgroup.com/)

<https://www.linkedin.com/company/arqit>

- [Get in Touch](https://arqitgroup.com/contact-us)

![NQA_ISO27001_CMYK_UKAS (1)](https://arqitgroup.com/hubfs/NQA_ISO27001_CMYK_UKAS%20(1).webp)

![FIPS 140-3 validated product logo image in color (1)](https://arqitgroup.com/hubfs/FIPS%20140-3%20validated%20product%20logo%20image%20in%20color%20(1).webp)

[![Consultancy_Post-Quantum Cryptography (Discovery and Migration Planning) (1)](https://arqitgroup.com/hubfs/Consultancy_Post-Quantum%20Cryptography%20(Discovery%20and%20Migration%20Planning)%20(1).webp) ](https://www.ncsc.gov.uk/schemes/assured-cyber-security-consultancy/pqc-pilot)

[![Cyber Essentials Badge (1)](https://arqitgroup.com/hubfs/Cyber%20Essentials%20Badge%20(1).webp) ](https://www.ncsc.gov.uk/cyberessentials/overview)

[![IDC-Innovator-2024-badge-blue-withlabel (1)](https://arqitgroup.com/hubfs/IDC-Innovator-2024-badge-blue-withlabel%20(1).webp) ](https://arqitgroup.com/who-we-are?hsLang=en#awards)

[![GLOMO (1)](https://arqitgroup.com/hubfs/GLOMO%20(1).webp) ](https://www.mwcbarcelona.com/articles/2024-glomo-award-winners-unveiled-at-mwc-barcelona)

[![e_sig_the_cyber_defence_product_of_the_year_33 (1)](https://arqitgroup.com/hubfs/e_sig_the_cyber_defence_product_of_the_year_33%20(1).webp) ](https://thenationalcyberawards.org/2024-winners/)

[![CTGSEA25-Winner+Cat_Endpoint Security Solution Award (1)](https://arqitgroup.com/hubfs/CTGSEA25-Winner+Cat_Endpoint%20Security%20Solution%20Award%20(1).webp) ](https://arqitgroup.com/who-we-are?hsLang=en#awards)

[![NaaS Innovation 1080x1080 (1) (1)](https://arqitgroup.com/hubfs/NaaS%20Innovation%201080x1080%20(1)%20(1).webp) ](https://www.mplify.net/news/mplify-names-winners-of-the-2025-naas-excellence-awards/)

All rights reserved

- [Terms of Use](https://arqitgroup.com/resources/arqit-terms)
- [Privacy Policy](https://arqitgroup.com/privacy-policy)
- [Visit the Arqit website](https://arqitgroup.com)

<https://arqitgroup.com/resources/blog/the-white-house-cybersecurity-strategy-makes-pqc-an-operational-problem#>

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "",
    "addressLocality" : "London",
    "addressRegion" : "United Kingdom",
    "postalCode" : "SW1H 0BF",
    "streetAddress" : "1st Floor, 3 Orchard Place"
  },
  "knowsLanguage" : "en",
  "name" : "Arqit Quantum Inc",
  "url" : "https://arqitgroup.com/resources/blog/the-white-house-cybersecurity-strategy-makes-pqc-an-operational-problem"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Arqit",
    "url" : "https://arqitgroup.com/resources/blog/author/arqit"
  },
  "dateModified" : "2026-07-24T14:35:41.003Z",
  "datePublished" : "2026-03-31T10:35:38.000Z",
  "headline" : "Why the White House Strategy Makes PQC Operational",
  "image" : [ "https://arqitgroup.com/hubfs/White%20House-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://arqitgroup.com/resources/blog/the-white-house-cybersecurity-strategy-makes-pqc-an-operational-problem",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://arqitgroup.com/hubfs/Arqit_Logo_Horizontal_Night.png"
    },
    "name" : "Arqit"
  }
}
```

```json
{
      "@context": "https://schema.org",
      "@type": "BlogPosting",
      "headline": "The New Face of Cyber Warfare:  A Warning for Critical Infrastructure Security",
      "image": 
        "https://7543877.fs1.hubspotusercontent-na1.net/hub/7543877/hubfs/Website/Website%20Imagery%202025/1200%20x%20450/1200x800_0039_arqit_new_brand_general-%2827%29.webp?width=2000&name=1200x800_0039_arqit_new_brand_general-%2827%29.webp",
      "datePublished": "2025-05-01T11:08:34.000Z",
      "text": "In 2024, sophisticated cyberattacks targeted major U.S. telecommunications providers, marking a pivotal moment in the evolution of nation-state cyber aggression. Unlike conventional distributed denial-of-service (DDoS) attacks or financially motivated ransomware campaigns, the Chinese cyber hackers, Salt Typhoon launched a highly coordinated, multi-vector intrusion designed to exploit vulnerabilities at the intersection of network infrastructure, cloud services, and software supply chains. This advanced persistent threat compromised data integrity, disrupted services, and raised concerns about national cybersecurity resilience.  
The scale and precision of this attack have raised critical concerns about the resilience of national communications networks, as well as the broader implications for 5G, IoT, and critical infrastructure. As the digital backbone of modern society, telecommunications infrastructure represents both a strategic asset and a prime target for adversarial entities seeking to disrupt economic, military, and civilian communications. 
The Unprecedented Attack 
Salt Typhoon exploited multiple layers of telecommunications infrastructure, employing zero-day vulnerabilities, advanced persistent threats (APTs), and supply-chain infiltration to bypass traditional security measures. 
Telecom networks are built on legacy protocols that, while robust, were not originally designed to withstand modern cyber threats. Salt Typhoon leveraged critical vulnerabilities in network management interfaces, DNS hijacking, and Border Gateway Protocol (BGP) route manipulation to intercept and reroute traffic between telecom providers, enabling large-scale data exfiltration.  The attacker injected malware into core network components, to allow for long-term persistence. Finally, the attacks were able to compromise SS7 signaling which allowed them to intercept SMS-based authentication messages and disrupt services. 
This was exacerbated by the increased reliance on cloud-native architectures and API-driven services. This enabled Salt Typhoon to target weaknesses in multi-tenant cloud environments, exploiting misconfigured Kubernetes clusters, unsecured API gateways, and credential stuffing attacks.  This allowed unauthorized lateral movement, the compromise of telecom employee accounts, and ultimately unauthorized access to critical backend functions. 
A particularly insidious aspect of Salt Typhoon was its use of supply chain infiltration. By compromising third-party software vendors, attackers injected malicious updates into telecom systems, granting backdoor access to network monitoring tools, customer data repositories, and real-time call routing systems. 
These tactics illustrate a fundamental shift in cyberattack strategies: rather than breaching individual devices, adversaries weaponize the dependencies that underpin entire industries. 
The Implications 
The implications of Salt Typhoon extend beyond the immediate data breaches, network downtime, and operational disruptions experienced by telcos. The attack underscores a larger geopolitical struggle over digital sovereignty, cryptographic resilience, and  
Telecommunications networks are not just commercial assets—they are essential to mlitary communications and logistics, government intelligence operations, and critical infrastructure coordination (energy, finance, emergency services). A breach at this scale exposes vulnerabilities in both civilian and military command-and-control systems, making Salt Typhoon not just a cybercrime but an act of asymmetric cyber warfare. 
The financial damage of the Salt Typhoon is estimated in the billions.  This consists of firect costs (network restoration, security audits, regulatory fines), indirect costs (customer churn, reputational damage, loss of investor confidence), and legal liabilities (class-action lawsuits from affected consumers and businesses). A breach of this magnitude erodes consumer trust in telecom providers, raising questions about data privacy, accountability, and the long-term viability of centralized network models. 
The sophistication of Salt Typhoon also highlights the impending vulnerability of traditional cryptographic defenses. Current encryption standards, including RSA-2048 and ECC, are vulnerable to quantum computing advancements. If quantum-capable adversaries obtain exfiltrated data today, they can store it for future decryption - a tactic known as 'store now, decrypt later.' This makes quantum-safe security an urgent priority for telecommunications and critical infrastructure providers. 
Mitigating the Threat 
In response to Salt Typhoon and similar threats, organizations must proactively enhance their encryption frameworks, particularly for secure communications and remote access. One of the most effective countermeasures is the adoption of Quantum-Safe VPNs, which integrate quantum-safe cryptographic algorithms to ensure long-term security. 
 
By replacing classical cryptographic primitives with quantum-resistant alternatives, organizations can prevent data exfiltration from being decrypted in the future, ensure secure long-term key exchanges, and protect high-value assets such as telecom routing tables, call logs, and metadata. 
For organizations seeking to implement next-generation security, essential features include the option for hybrid cryptography. Zero Trust Architecture further ensures that no device or user is inherently trusted, rather every endpoint is continuously authenticated. 
While full-scale quantum computing threats may still years away, Salt Typhoon is a warning shot—traditional VPNs relying on RSA-based key exchanges will soon become defunct against quantum adversaries. 
The Salt Typhoon attack is a stark reminder that telecommunications security is no longer just a corporate responsibility - it is a national imperative. The breach exposed fundamental weaknesses in network design, encryption protocols, and supply chain security, signaling an urgent need for next-generation cybersecurity frameworks. 
As cyber adversaries evolve, so must our defenses. Quantum-safe cryptography is no longer a theoretical safeguard - it is an operational necessity for securing global telecommunications infrastructure. The race to protect critical infrastructure is not against hackers alone—it is against time.",
      "author": {
         "@type": "Person",
         "name": "Arqit",
         "sameAs": "http://arqitgroup.com/"
     }
    }
```