White House Quantum Order Meets a 0.029 Percent Security GapWhite House Quantum Order Meets a 0.029 Percent Security GapWhite House Quantum Order Meets a 0.029 Percent Security GapWhite House Quantum Order Meets a 0.029 Percent Security Gap
July 2, 2026
On June 22, 2025, the White House signed an executive order accelerating quantum computing efforts and placing post-quantum cryptography (PQC) (the discipline of developing encryption algorithms resistant to attacks by quantum computers) squarely on the national security agenda.

On June 22, 2025, the White House signed an executive order accelerating quantum computing efforts and placing post-quantum cryptography (PQC) (the discipline of developing encryption algorithms resistant to attacks by quantum computers) squarely on the national security agenda. The directive arrived against a backdrop that makes the urgency concrete: peer-reviewed research published in 2025 found PQC deployment sitting at just 0.029 percent, even within national supercomputing clusters - the very infrastructure most exposed to quantum-era threats. If IBM's estimate that a full cryptographic migration takes approximately 12 years holds, organizations that have not yet started are already behind.
The Asia-Pacific region now leads the world in public quantum funding, with more than $19 billion committed, representing close to 54 percent of the global total. China's hardware roadmap has moved from the 105-qubit Zuchongzhi 3.0 processor to the 504-qubit Tianyan-504 within a single year - a nearly five-fold increase in qubit count. Hardware capability is scaling on a curve that migration timelines cannot yet match.
What Happened
The White House executive order signed on June 22 does more than endorse quantum research funding. Section 4(f) directs U.S. intelligence and defense leadership to assess the national security implications of commercial quantum computers, with explicit attention to what accelerating hardware development means for PQC migration. The order also calls for closer international coordination on supply chains, export controls, and research security related to quantum resilience, treating cryptographic readiness as a defense matter rather than a procurement detail.
The policy context sits inside a broader investment surge. Asia-Pacific's more than $19 billion in committed public funding - roughly 54 percent of the global total - reflects a sustained, multi-government bet on quantum as strategic infrastructure. Japan has committed around ¥1 trillion (approximately US$6.7 billion). South Korea has put forward roughly €2 billion. India has committed close to €0.8 billion. Singapore has directed more than S$300 million (approximately US$222 million) toward research and talent. These are not research grants; they are industrial policy commitments from governments determined not to repeat the pattern of falling behind in semiconductors.

The Merics analysis organization has framed the situation plainly, noting that the United States and European Union are "playing catch-up" to China's approach to quantum technology, drawing a parallel to Cold War-era technology competition.
The Technical Breakthrough
Qubit count is not a complete measure of quantum computing capability, but the pace of China's hardware progression is significant as a signal of engineering velocity. The Zuchongzhi 3.0 processor carried 105 qubits (quantum bits, the basic unit of quantum information, capable of representing 0, 1, or a superposition of both simultaneously, unlike classical binary bits). The Tianyan-504, developed within a single year, scales that count to 504 superconducting qubits. The architectural challenge in scaling quantum systems is not simply adding more qubits; it requires maintaining coherence (the fragile quantum state that enables computation) across a larger array while managing noise and error rates that grow with system size.
Research from UCF's Han Zhao, an assistant professor of physics, illustrates the direction of current engineering work. Zhao is combining superconducting quantum systems with nanomechanical devices to make quantum operations more resistant to noise and decoherence. As Zhao stated in published commentary: "The future of quantum computing will be its real-world breakthrough applications in science and the economy. So it is absolutely true that practical quantum computers need to address the fragility of quantum states."
China's industrial infrastructure build-out accompanies the hardware milestones. Shanghai's Quantum Computing Future Industry Incubation Zone opened with an initial cohort of 26 quantum companies, reportedly providing up to 100 million yuan (approximately US$14.73 million) for foundational research and shared platforms, with individual support of reportedly up to 20 million yuan per company developing first commercial quantum products.
Why It Matters for Industry
The 0.029 percent PQC deployment figure from peer-reviewed 2025 research is not a rounding error. It describes a systemic condition: the infrastructure most critical to protect against quantum-era attacks has barely begun migrating to algorithms that can withstand those attacks. The algorithms most organizations rely on for public-key encryption - including the integer factorization and elliptic-curve discrete logarithm problems underlying widely deployed systems - are solvable by quantum computers running Shor's algorithm (a quantum algorithm that can factor large integers and solve discrete logarithm problems exponentially faster than classical computers, breaking most current public-key encryption). NIST finalized its first three post-quantum cryptography standards in August 2024, publishing FIPS 203 (ML-KEM, based on CRYSTALS-Kyber), FIPS 204 (ML-DSA, based on CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, based on SPHINCS+), giving organizations a concrete algorithmic foundation to migrate toward. The gap between standard availability and deployment remains vast.

The harvest-now-decrypt-later (HNDL) threat model (a strategy in which adversaries collect encrypted data today and store it until quantum computers capable of breaking the encryption become available) transforms migration timelines into a current operational risk. For data with long confidentiality lifetimes - diplomatic communications, health records, critical infrastructure logs, and intellectual property - the risk begins at the moment of transmission or storage, not at some future "Q-Day."
Singapore's financial regulator moved earliest among its regional peers. In February 2025, the Monetary Authority of Singapore issued guidance to the chief executives of every financial institution in the country on quantum cryptographic risk, translating the threat model into board-level accountability. The MAS subsequently ran a quantum-safe communications sandbox with four major institutions - DBS, HSBC, OCBC, and UOB - testing real-world deployment of quantum-safe protocols. The program was supported by S$100 million in government funding for quantum and AI innovation in financial services. Singtel has since reportedly launched what it describes as Southeast Asia's first nationwide quantum-safe network.
Competitive Landscape
The global quantum investment picture shows pronounced concentration by country, with China's ¥1 trillion government-backed venture fund commitment dwarfing every other regional player. Three analytical and policy organizations have mapped the competitive dynamics explicitly:

- Merics frames China's quantum posture as analogous to Cold War-era technology competition, arguing the United States and European Union are playing catch-up to China's "long view on quantum tech" - positioning quantum not as a commercial technology race but as a strategic infrastructure contest with decades-long compounding effects.
- U.S.-China Economic and Security Review Commission (USCC) published "Vying for Quantum Supremacy: U.S.-China Competition in Quantum Technologies," noting that over 30 Chinese companies have launched quantum computing businesses, though as of 2025 only a handful are globally competitive. The report frames the question as diffuse national investment translating into selective commercial leadership over time.
- PostQuantum.com covers China's 15th Five-Year Plan, which designates quantum as an industrial priority, framing China's shift from research ambition to industrial policy as something security leaders outside China must treat as "operational, not aspirational."
The BSA / The Software Alliance has stated: "The upgrade to post-quantum cryptography is an urgent priority. Governments should act now to develop migration road maps, launch pilot programs..." The BSA positions PQC migration as a policy prerequisite, not a technology-readiness question, given that NIST has already finalized the standards.
According to IQM's State of Quantum 2026 report, enterprise engagement with quantum computing is now widespread and early movers are building an advantage later entrants will struggle to close. The MAS sandbox with four named major banks represents the most concrete published example of financial-sector early adoption.
The Bigger Picture
The asymmetry between quantum hardware investment and post-quantum security deployment is structural, not accidental. Quantum hardware development follows an engineering roadmap with measurable milestones and concentrated funding. PQC migration is an organizational process requiring coordination across IT, procurement, legal, third-party relationships, and executive governance - with no single point of control and no analogous funding mechanism to accelerate it.
The White House executive order's Section 4(f) direction represents an acknowledgment that the 12-year migration estimate is not fixed. If hardware scaling continues at the pace China has demonstrated - from 105 to 504 qubits in a single year - the window between today's investment commitments and tomorrow's cryptographically relevant machines may compress. Mosca's theorem (a framework comparing three time horizons: how long data must remain confidential, how long migration takes, and when cryptographically relevant quantum computers arrive - with migration becoming urgent when the first two together exceed the third) makes this arithmetic explicit. At 0.029 percent deployment and a 12-year migration estimate, the numbers are uncomfortable for most organizations.

What's Next
The MAS approach offers the clearest institutional template for coordinated readiness. The February 2025 guidance to every financial institution CEO established quantum cryptographic risk as a governance obligation. The subsequent sandbox with DBS, HSBC, OCBC, and UOB moved the conversation from policy to operational testing. The sequence - from regulatory guidance to institutional pilot to deployed infrastructure - is replicable by other regulators and in other sectors.
The challenge for most organizations outside Singapore is that no equivalent regulatory trigger has forced the inventory and migration planning work to begin. The White House executive order's Section 4(f) assessment requirement may function as that trigger for U.S. national security infrastructure. Whether that mandate cascades into civilian and commercial sectors depends on follow-on rulemaking the order does not yet specify.
For IT decision-makers and security procurement teams: The NIST standards (FIPS 203, 204, and 205) are finalized. According to published benchmarks, ML-KEM (Module Lattice-based Key Encapsulation Mechanism, the post-quantum key exchange algorithm standardized as FIPS 203) introduces roughly 70 times more data overhead than ECDH (Elliptic Curve Diffie-Hellman, a widely used classical key exchange protocol) and increases runtime by approximately 2.3 times - costs that are manageable at current hardware speeds but require infrastructure planning. The cryptographic inventory required before migration begins is where organizations consistently underestimate the workload. Asia-Pacific has committed $19 billion to close the quantum hardware gap. Closing the security gap requires a different investment - measured not in research funding but in organizational process, regulatory pressure, and the unglamorous work of cryptographic inventory. Start there.
-- Aria Lin, Enterprise Technology Analyst
Sources: The Quantum Insider, "Asia's Quantum Race Needs a Security Strategy That Can Keep Pace," July 2, 2026 - George Mason University Cryptography Engineering, Post-Quantum Cryptography Overview