Passed on Monday, vulnerable on Tuesday: The most dangerous green check mark in national security

.

On Oct. 1, the National Security Agency sharpened America’s post-quantum deadline. Beginning in 2027, new commercial National Security Systems must be capable of supporting quantum-resistant algorithms, and legacy systems that cannot do so are to be phased out by 2030.

That deadline focuses attention on migration. But even a fully migrated system can carry a stale green check mark. The cryptography can be current, while the evidence used to approve that configuration is not.

Imagine a system that passes its post-quantum test on Monday. On Tuesday, the software changes. On Wednesday, the firmware is updated. A trust anchor rotates. A credential expires. A recovery image is replaced. The next disconnected operating window lasts longer than the one used in the test. The report is still authentic. The harder question is whether it still applies.

Every assurance claim has an evidence applicability lifetime. In public shorthand, think of it as an assurance half-life. It is not a fixed countdown, and there is no universal number of days. Evidence stops supporting a claim when the assumptions that made it relevant materially change.

President Donald Trump’s June Executive Order 14412 accelerated the federal move to post-quantum cryptography. The Office of Management and Budget has since directed agencies toward dynamic, continuously updated cryptographic inventories and monitoring dashboards. The Pentagon’s own post-quantum strategy requires its systems to support PQC by the end of 2030 and use it by the end of 2031, while prioritizing mission criticality, interoperability, and testing.

The policy is moving toward dynamic inventories. The assurance record has to become dynamic too.

A constructed research model I developed shows the logic. In one case, every modeled cryptographic asset has completed migration, and both selected services have supporting evidence. Make the evidence for one shared dependency stale, without changing the algorithm inventory, and both service claims become “not demonstrated.” Tie the evidence to the wrong configuration, and only the service that depends on it loses support. No operational military system was evaluated; this is a logical counterexample, not a Pentagon finding. Asset state and evidence state are different things.

Washington should turn that distinction into four practical rules:

First, every consequential test result should carry a scope label. Record the software and firmware versions, cryptographic profile, trust anchors, operating configuration, environment, and time window the evidence actually covers. A signed report should not become a lifetime warranty for every later version.

Second, define the events that shorten the evidence lifetime. A material software change, firmware revision, trust-anchor change, credential expiry, a newly enabled fallback path, or a recovery-path change should trigger an applicability review. That does not mean every patch requires a full retest. It means someone has to establish why the earlier evidence still applies instead of assuming that it does.

Third, separate migration status from assurance status on the dashboard. A component can be “PQC migrated” while the evidence for its current configuration is stale, incomplete, or inapplicable. The dashboard should be able to say “migrated, evidence current,” “migrated, evidence review required,” or “not demonstrated.” Missing evidence is not proof of compromise. It is also not proof of readiness.

Fourth, treat recovery as a new assurance decision. A reboot can restore software; it does not automatically restore assurance. A recovery image can re-enable cryptography or configuration states that the migration was meant to retire. Recovery checks should confirm that the restored configuration still meets the current profile before the system returns to full operational status.

The Department of War’s own Post Quantum Cryptography Strategy already points in the right direction. It calls for modernization based on mission criticality, new processes for testing critical cryptographic updates and patches, streamlined certification, and migration roadmaps that are maintained and updated as the transition proceeds. Evidence applicability is the missing connective tissue between those activities.

This does not require another large bureaucracy. Trump’s order directs the National Institute of Standards and Technology to complete a post-quantum migration pilot by Dec. 31, 2027. A defense laboratory could add one simple test: approve a benign configuration, change one material dependency, and ask whether reviewers correctly determine which evidence still applies. Measure unsupported approvals, unnecessary retesting, review time, and maintenance burden. If the existing process performs just as well, keep it. If it carries stale evidence forward, fix the process before deadline pressure gets worse.

OPINION — NINETY-NINE PERCENT SAFE IS 0% SAFE: THE FATAL FLAW IN THE PENTAGON’S POST-QUANTUM DEFENSE

Post-quantum migration will succeed only if Washington manages two lifecycles at once: the lifecycle of the cryptography and the lifecycle of the evidence used to trust it.

The most dangerous green check mark is the one that outlives the assumptions that made it green.

Burak Oktenli is a graduate student in applied intelligence at Georgetown University and an independent researcher focused on trustworthy artificial intelligence, cybersecurity, autonomous systems, and high-consequence technology governance. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and a Master of Business Administration.

Related Content