White House Quantum Push Forces Midmarket IT To Rethink Security Now

A new U.S. quantum push won’t change IT roadmaps yet—but it accelerates security, talent, and ecosystem shifts midmarket leaders can’t afford to ignore.

The White House’s latest quantum executive order represents a shift that IT leaders should not ignore: quantum computing is no longer in the long-term research realm; it’s moving into deployment, workforce planning, and security response strategies.

Federal agencies have been attempting to get ahead of quantum risk. The Cybersecurity and Infrastructure Security Agency (CISA) published federal guidelines in January 2023 urging agencies to invest in post-quantum computing (PQC) technologies where available.

And since 2025, The National Institute of Standards and Technology has urged organizations to plan their PQC migration strategies sooner rather than later due to the anticipated complexities associated with PQC.

The EO outlines several quantum goals for agencies, including updating the National Quantum Strategy within 180 days. It also focuses on deployment and partnerships—pushing for quantum workforce programs, infrastructure rollout in five years; and strengthening domestic supply chains.

Clearly, the government is attempting to build a quantum ecosystem. But what does that mean for the private sector and particularly for the midmarket that is still navigating AI?

What The New Quantum EO Means For The Midmarket

This EO suggests quantum priorities — it does not provide concrete technical implementation details. It signals to IT leaders that planning is underway for a post-quantum world. IT leaders aren’t likely to change their roadmaps anytime in the near future because of this EO, but conversations about PQC should be taking place between IT executives and senior leadership if they haven’t already.

MES Computing coverage has already highlighted growing concern among IT leaders around “Q-Day”—the point when quantum systems could break today’s encryption—making workforce and readiness signals more relevant than the technology’s long-term promise.

[RELATED: ‘Q Day:’ What Midmarket IT Leaders Need To Do To Prepare Now]

Of course, the most pressing concern for the midmarket is the “harvest now, decrypt later” current tactic of threat actors. They are searching for sensitive, valuable data within organizations and stealing it and holding onto it, waiting for that time when PQC can break today’s encryption standards.

[RELATED: Quantum Risk Is Moving Into The Boardroom. Why Aren’t IT Leaders In The Room?]

“The White House is right to treat post-quantum cryptography as a national migration program, not a research project. Quantum does not break encryption someday. It changes the risk calculation today,” said Jeff Williams, founder of OWASP, and founder/CTO of Contrast Security, in a statement to MES Computing.

The most critical step CIOs and CISOs can take right now is conducting an internal cryptographic assessment, Williams said.

“The organizations that succeed will be the ones that start by understanding their cryptographic posture, grounded in what is actually running in production. Otherwise, PQC migration will become the next massive security backlog. I’m glad to see the PQC EO put a clock on this migration,” Williams said.