Ninety-nine percent safe is 0% safe: The fatal flaw in the Pentagon’s post-quantum defense

.

Five days ago, the National Security Agency moved the post-quantum clock forward. Beginning in 2027, new commercial National Security Systems are expected to support quantum-resistant algorithms, while legacy systems that cannot support them are to be phased out by 2030. President Donald Trump had already accelerated the broader federal transition through an executive order titled “Securing the nation against advanced cryptographic attacks.”

The Pentagon has its own deadline: systems must support post-quantum cryptography by the end of 2030 and use it by the end of 2031, subject to stated exceptions. Those are necessary targets. They are not, by themselves, a mission-readiness test.

The Pentagon’s own post-quantum strategy contains the clue. It says a mission thread is not quantum-resistant until vulnerable algorithms and protocols are gone across the critical data pathway and lifecycle. That is the right standard. A mission thread is what warfighters actually consume: communications, identity, software updates, command-and-control data, sensor information, and the recovery paths that keep those services usable.

But migration programs naturally produce a different kind of scoreboard: how many devices have been updated, how many are left, how quickly the industry can produce replacements, and when legacy equipment will disappear. Those figures are useful for managing a program. They can still conceal the one unresolved dependency that matters most.

Consider a deliberately small, synthetic example from my research. Twelve cryptographic assets support two services. In one configuration, 10 of 12 assets have migrated and both services remain supported because the two unresolved assets sit outside their critical paths. In another configuration, the dashboard still reads 10 of 12, or 83.3%, but neither service is supported because one unresolved asset is shared by both. Raise the total to 11 of 12, or 91.7%, and neither service is supported if the one remaining gap is still that shared dependency.

This is not a finding about a Pentagon network. No operational military or NASA system was evaluated. It is a reproducible counterexample to a management assumption: an enterprise migration percentage cannot tell you whether the mission behind it is ready.

That distinction should change what Washington asks for as the deadline approaches.

First, report readiness by mission thread as well as by asset count. Program offices should identify the cryptographic dependencies required for each priority service and show which unresolved components sit on shared or mission-critical paths. A weak component that no critical service uses is not equivalent to a weak component that every critical service uses.

Second, bind test evidence to the configuration it actually covered. A product label saying “PQC supported” is not enough. The relevant question is whether the delivered software, firmware, protocol, trust anchors, credentials, and operating mode were tested together. If one of those changes materially, the program should determine whether the old evidence still applies instead of inheriting a green status automatically.

Third, test disconnection and recovery. The Pentagon’s strategy specifically covers space systems, tactical radios, data links, and secure edge devices, and states tactical radio refresh should minimize interruption of warfighting capability. Those systems cannot assume perfect connectivity. A credential can remain authentic while the status information behind it becomes stale. A restored computer can boot successfully while loading an older configuration that quietly re-enables cryptography the migration was supposed to retire.

Fourth, give uncertainty its own status. “Pass” and “fail” are not enough. Sometimes the correct answer is “not demonstrated.” Missing or stale evidence does not prove compromise, nor does it justify approval. That third state tells leaders what requires investigation without forcing them into either a false green light or an unnecessary shutdown.

The White House has already directed NIST to complete a federal post-quantum migration pilot by the end of 2027. The Pentagon can run a bounded companion test now. Give experienced reviewers the same benign systems and the same evidence. Let one team use an ordinary migration inventory and another add mission dependencies, configuration applicability, and recovery conditions. Measure unsupported approvals, false alarms, review time, and maintenance burden.

If the richer method adds nothing, discard it. That outcome would save money and bureaucracy. If it catches consequential gaps that the percentage dashboard misses, then Washington will have learned something before the deadline rather than after.

AMERICA IS WINNING THE AI BUILDOUT. ONE BLIND SPOT COULD COST US THE RACE

The quantum transition is moving from standards to implementation. That is progress. It is also the moment when a program-management metric can quietly become a national-security assumption.

The Pentagon can hit every percentage target on time and still miss the mission if the remaining 1% is the dependency everything else needs.

Burak Oktenli is a graduate student in applied intelligence at Georgetown University and an independent researcher focused on trustworthy artificial intelligence, cybersecurity, autonomous systems, and high-consequence technology governance. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and a Master of Business Administration.

Related Content