• 4 mins read
  • Published

Intel Details Hardware Steps for US Post-Quantum Crypto Deadlines

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Intel Details Hardware Steps for US Post-Quantum Crypto Deadlines Science.Report © science.report
Intel Details Hardware Steps for US Post-Quantum Crypto Deadlines © science.report

Intel Federal's Steve Orrin explains the technical and policy challenges facing US agencies as they prepare for post-quantum cryptography mandates, including hardware migration timelines, crypto asset inventory, and the need for crypto agility

US government agencies and their suppliers are facing a complex transition to post-quantum cryptography (PQC) as federal deadlines approach. Intel Federal's Chief Technology Officer, Steve Orrin, has outlined the technical and operational requirements for meeting these mandates, which are designed to protect sensitive data against future quantum-enabled attacks. The transition is driven by the risk that encrypted information harvested today could be decrypted in the future, once large-scale quantum computers become available.

Federal Deadlines and Technical Scope

The US government has set a series of staged deadlines for PQC adoption. By 2030-2031, agencies must be able to use PQC algorithms, with a requirement to remove all legacy cryptography by 2035. For national security systems, any new acquisition after January 1, 2027, must require PQC support. These requirements extend beyond software to include hardware, firmware, and networked peripherals, making the migration a multi-layered engineering challenge. The scale is significant: a typical Windows laptop may contain around 20,000 cryptographic assets, though only a subset are critical for security and must be prioritized for migration.

Hardware Integration and Crypto Agility

Unlike software, which can often be updated rapidly, hardware and firmware require long lead times for design, certification, and deployment. Intel reports embedding PQC capabilities such as XMSS (eXtended Merkle Signature Scheme) and LMS (Leighton-Micali Signature) for firmware signing into its silicon over five chip generations, reflecting the five-year development cycle typical for hardware platforms. This approach aims to ensure that devices entering the supply chain now will be ready for PQC requirements as deadlines arrive. Crypto agility-the ability to switch cryptographic algorithms as standards evolve or vulnerabilities are discovered-is emphasized as a critical engineering goal, given that no PQC algorithm can be guaranteed secure against all future quantum or classical attacks.

Inventory, Certification, and Supply Chain

Agencies are advised to begin with a comprehensive cryptographic inventory, identifying not only application-level assets but also those embedded in firmware and connected devices such as printers. Certification of PQC readiness is complicated by the need to verify hardware, firmware, and software components across diverse platforms and vendors. The absence of dedicated funding for this migration adds further complexity, requiring agencies to balance operational continuity with security mandates. The integrity of the supply chain is also a concern, as PQC adoption must extend to all suppliers and contractors handling sensitive data or systems.

Quantum Threats and Policy Context

The urgency of the transition is underscored by the reality of "harvest now, decrypt later" attacks, in which adversaries collect encrypted data today in anticipation of future quantum decryption capabilities. While quantum key distribution (QKD) is sometimes discussed as a complementary technology, the current focus remains on deploying standardized PQC algorithms that can run on conventional hardware. The complexity of the migration is comparable to other national quantum initiatives, such as those described in recent state-federal quantum computing grant expansions, which highlight the scale of coordination required across agencies, industry, and standards bodies.

Understanding the distinction between post-quantum cryptography and quantum cryptography is essential for interpreting these mandates. PQC refers to cryptographic algorithms designed to resist attacks from both classical and quantum computers, but which run on ordinary digital hardware. In contrast, quantum cryptography-such as quantum key distribution-relies on quantum physical effects for security. The current US policy focus is on PQC because it can be deployed at scale using existing infrastructure, but the engineering challenge lies in identifying, updating, and certifying every relevant cryptographic component across complex hardware and software stacks. The transition will require sustained technical effort, careful inventory, and ongoing adaptation as quantum and classical threats evolve.

Related articles