New Trump executive orders on quantum computing

New Trump executive orders on quantum computing
Photo by Nicolas Arnold / Unsplash

The Trump administration in June issued two new orders on quantum computing:

  • The cryptography order assigns leadership to OMB and the National Cyber Director, with Commerce, NSA and DHS issuing guidance, and requires agencies to name postquantum cryptography (PQC) transition leads within thirty days. QuSecure describes the shift as moving "from awareness to execution”: inventory your cryptographic assets, establish ownership, migrate against milestones.
  • The order also calls for a new procurement clause requiring federal contractors to comply with postquantum standards by 31 December 2030. Legal analysts note the corollary that vendors may prefer not to think about: enforcement and litigation exposure around cybersecurity representations rises alongside the funding opportunity.

Pulling the federal target from Biden-era NSM-10’s 2035 to 2030 and 2031 compresses the largest cryptographic replacement project ever attempted. Bad actors are scooping up encrypted data in transit for Q-day, for quantum computers can decrypt. Data at rest should theoretically be safe, but cloud providers often encrypt the rested data’s private encryption keys with a public key.

While the federal PQM deadline moved up roughly five years, the estimated time frame for breaking RSA-2048 fell by orders of magnitude in about twelve months. The standing reference point was Gidney and Ekerå's 2019 estimate: RSA-2048 factored in eight hours by a machine with 20 million noisy qubits. In May 2025, Gidney cut the qubit count to fewer than one million on identical hardware assumptions, but the runtime stretched from eight hours to a week.

In February 2026, Iceberg Quantum's Pinnacle Architecture preprint claimed RSA-2048 with fewer than 100,000 physical qubits by swapping surface codes for quantum LDPC codes (surface codes burn about a thousand real qubits to produce one usable one; LDPC codes get closer to fifty at the cost of complex chip wiring).

In March 2026, an Oratomic-led group proposed Shor's algorithm on as few as 10,000 reconfigurable neutral atoms—a platform whose error-correction cycle is about a thousand times slower than superconducting, and whose 10,000-qubit case is not RSA-2048. Such neutral atoms are held in laser traps rather than superconducting circuits (ahem), but are about a thousand times slower per error-correction cycle. Hence, the 10,000-qubit figure describes cracking a 256-bit elliptic-curve key over roughly nine months. RSA-2048 would take many more.

Google has set its own PQM deadline at 2029, a year ahead of the federal key-establishment deadline and two years ahead of the signature deadline.