
On July 21, 2026, Google dropped a whitepaper that recalibrated the quantum threat timeline. Future quantum computers can break elliptic curve cryptography with fewer qubits and gates than previously realized. The finding guts the assumption that the cryptography securing blockchains, web traffic, and financial systems has another decade on the clock. Google didn't just publish the finding. The company engaged with the U.S. government and developed a zero-knowledge proof method to describe the vulnerabilities so they could be verified without handing attackers a blueprint.
The same day, two other things happened. The IACR ePrint Archive published a benchmark for post-quantum cryptography readiness called CARS, and a team of cryptographers gave identity-based encryption a second mathematical foundation. The next morning, July 22, the 30-day deadline in Executive Order 14412 landed. Every federal agency had to designate a PQC migration lead.

This was not coincidence. It was the moment the quantum security transition stopped being a planning exercise.
The Plan Is Not the Problem
DigiCert's 2026 Quantum Readiness Outlook surveyed 1,001 IT and cybersecurity decision-makers in the US, UK, and Australia. The headline number looks fine: 87% of organizations report they have a PQC plan. The deployment number does not: 7% have deployed quantum-safe protections across most of their infrastructure. That figure grew by two percentage points year over year.
Two percentage points. Against a threat that the NSA and CISA describe as already active. Adversaries are harvesting encrypted traffic now, storing it, and waiting for the hardware that breaks it. The attack is complete at the point of collection. Decryption is a formality that arrives later.
The compliance landscape is hardening around this gap. PCI's inventory requirement and DORA are already in force. CMMC entered contracts in late 2025. FIPS 140-2 sunsets in September 2026 alongside the first obligations under the Cyber Resilience Act. Then 2030 arrives carrying three federal marks at once. The window closes in 2035. A dozen separate mandates, written by different governments and standards bodies for different reasons, are all landing in the same narrow band.
Every one of them requires organizations to know their cryptography. Most still don't.
The Benchmark and the Backup Plan
Allan D.B. Costa, a researcher at the Federal Rural University of the Amazon, published the Crypto-Agility Readiness Score on July 21. Costa evaluated 43 open-source cryptographic repositories. Most scored one-quarter ready. The framework measures five dimensions and produces a single composite index, the same way CVSS scores turn vulnerability severity into a number that drives decisions.
The CARS finding is a lagging indicator for open-source projects and a leading indicator for everyone else. If the code that the private sector depends on is one-quarter ready, the organizations consuming that code are not further along. They are further behind.
The same day, Shweta Agrawal of IIT Madras, Andrea Basso of IBM Research Zurich, and Sikhar Patranabis of IBM Research India published the first identity-based encryption construction built on elliptic-curve isogenies. IBE lets a sender encrypt a message using the recipient's identity, a string like an email address, without querying a directory for a public key. Until this paper, the only post-quantum foundation for IBE and related primitives was lattice-based cryptography.
The new construction delivers a second, independent mathematical foundation, built on supersingular elliptic curves. That matters because cryptographic monocultures are fragile. If a weakness is found in lattice assumptions, every system relying on them breaks at once. A second foundation is insurance. It reduces the single-point-of-failure risk that keeps cryptographers awake.
But cryptographic diversity only helps if organizations actually migrate. The 7% deployment rate says they are not.
The Harvest-Now Panic Will Arrive in 12 to 24 Months
Google's whitepaper destroys the timeline consensus. The default assumption has been that cryptographically relevant quantum computers are 10 to 15 years away. The new finding, that elliptic curve cryptography breaks with fewer qubits and gates than previously realized, pulls that in. Five to seven years is the more honest estimate. Some classified assessments may already be shorter.
Here is the chain that follows from that.
First, the 7% deployment rate means 93% of data in transit and at rest is protected only by algorithms that will fall inside that window. The harvest-now attack model does not require a quantum computer today. It requires one before the data loses its value. Financial records, health data, diplomatic cables, intellectual property: all of it has a shelf life measured in years or decades, not weeks.
Second, within 12 to 24 months, at least two major breaches will be publicly attributed to harvest-now-decrypt-later attacks on data encrypted with pre-quantum algorithms. The attribution will come not from a quantum computer cracking the encryption, but from the data surfacing, in decrypted form, in places it should not be. The breach will be retroactive. The encryption was broken years before anyone knew.
Third, that retroactive attribution will trigger a regulatory panic. Organizations that had a PQC plan but did not deploy will face liability for data they knew was vulnerable. The 80% of organizations with plans sitting on shelves will be forced to execute them. The compliance timelines will shift from aspirational to punitive. The CARS benchmark will become a de facto regulatory requirement, cited in audits and enforcement actions, not just a research paper.
For Bitcoin, the path is narrower and sharper. The Bitcoin Security Consortium, announced July 23, 2026, brings together nine institutional names, BlackRock, Coinbase, Strategy, Anchorage Digital, ARK Invest, Block, Blockstream, Fidelity Digital Assets, and Galaxy. They pledged $15 million over three years to fund Bitcoin's long-term security, including quantum defenses.
The structure is the problem. The $15 million is not a pooled fund. Each member directs its own money to whatever developers, researchers, or organizations it chooses. That is not a coordinated defense. It is a fragmented grant program. It will produce research and debate. It will not produce a unified upgrade protocol on the timeline that Google's whitepaper demands.
The miner-enforced upgrade is the fallback, and it is the more likely outcome. Bitcoin's largest mining pools control enough hash rate to enforce a soft fork. When the quantum threat becomes undeniable, those miners will not wait for consensus among nine institutional members with separate agendas. They will enforce a mandatory quantum upgrade protocol, because the alternative is a network whose cryptographic foundations are publicly known to be breakable. The mechanism is miner consolidation and hash rate concentration forcing compliance. The timing: late 2027.
The IBE isogeny breakthrough makes this technically feasible. Post-quantum identity for blockchain wallets, built on a mathematical foundation independent of lattices, gives the upgrade a concrete target. It is no longer a research problem. It is an engineering problem with a deadline.
What to Do Before the Panic Hits
Inventory cryptographic assets now. You cannot migrate what you do not know you have. Adopt CARS or an equivalent metric to measure readiness against a defensible standard. Prioritize data with long-term value for immediate PQC migration: financial records, health data, state secrets, anything with a shelf life beyond five years.
Watch the Bitcoin Security Consortium's progress. If it coalesces around a unified protocol, that is the path. If it does not, the miner-enforced upgrade is the fallback, and it will be less orderly than anyone wants.
The compliance timelines are not suggestions. They are deadlines with enforcement mechanisms arriving in sequence. September 2026 brings the FIPS 140-2 sunset and first CRA obligations. 2030 brings three federal marks. 2035 closes the window. The organizations that move now will have tested their migrations before the panic forces everyone else to rush.
The Qubit That Broke the Plan
Google's whitepaper did not just shorten the timeline. It proved that the planning era was a bet on a longer clock that does not exist. The 7% deployment rate is not a lagging indicator of slow adoption. It is a liability that 93% of the market is carrying on its balance sheet.
The consensus assumed quantum computers were 10 to 15 years away. The consensus was wrong. The next breach will be the one that was preventable. The quantum security transition was never about being early. It was about not being the one caught harvesting.