Skip to main content
Home > The $7.1bn question: budgeting for post-quantum credential migration

The $7.1bn question: budgeting for post-quantum credential migration

The quantum threat used to be a slide near the end of the deck, the part where someone said “not yet, but soon.” That framing is over. The cost of responding is now a line in a federal budget.

A number, not a warning

The US Office of Management and Budget has estimated the cost of migrating federal systems to post-quantum cryptography at $7.1bn between 2025 and 2035, and that figure covers prioritised systems alone. Read that back. It is not a projection of what a breach might cost, or a scare number attached to a hypothetical. It is what the migration itself is expected to cost, on the systems that matter most, over a fixed ten-year window.

When a threat reaches the point of being budgeted, the conversation changes. The question is no longer whether to act. It is how to spend the least money getting it done.

Where the money goes

Most of a $7.1bn migration is spent on the systems being rebuilt: the applications, the protocols, the hardware that has to be reworked to speak new cryptography. That is unavoidable engineering, and it is where the bulk of the cost sits.

There is a quieter part of the problem, and it is the part organisations tend to underestimate. Every user, device and service holding a credential needs a new one, issued on quantum-safe algorithms. In a large government or defence estate that means hundreds of thousands of credentials, each with its own lifecycle, its own policy, its own expiry. Handle that badly and reissuance becomes a second migration project running alongside the first, with its own integration work and its own budget line.

Handle it well and it barely registers. The credentials are reissued at scale, on the new algorithms, without touching the systems around them.

Reissue, don’t rebuild

This is the distinction that decides how much of that $7.1bn an organisation spends. Public Key Infrastructure (PKI) and Fast IDentity Online (FIDO) credentials have a full lifecycle: request, issue, renew, revoke, recover. A platform that already manages that lifecycle can swap the underlying algorithms without forcing a rebuild of the issuance workflow, the policy engine or the systems that consume the credentials.

MyID® manages exactly that. It handles the lifecycle of PKI and FIDO credentials for government, defence and financial services customers, and it now issues post-quantum certificates using the algorithms the National Institute of Standards and Technology (NIST) standardised in 2024. The migration path for the credential estate is the same path customers already use to issue and renew every day. The algorithm changes underneath. The process does not.

Why the timing matters

The 2025 to 2035 window is not generous. “Harvest now, decrypt later” attacks mean data captured today can be stored and broken once a working quantum computer arrives, so anything with a long confidentiality requirement is already exposed. For defence and government, that is most of it.

The organisations that treated credential management as infrastructure, rather than something bolted on per project, are the ones that will move fastest and spend least. They already have a single system of record for every credential they issue. Migrating it is a configuration change, not a capital programme. The organisations that spread credential issuance across a dozen disconnected tools will discover during migration exactly how much that decision cost them.

$7.1bn is the price of doing this at national scale. How much of it any single organisation spends comes down to a choice made long before the quantum computer arrives: whether credentials were ever managed as a system in the first place.