US States Show Widespread Unpreparedness for Quantum Computing Encryption Threat
US states are largely unprepared for the looming threat of quantum computers, which are expected to break current encryption standards around 2029. While the federal government is mandating a transition to quantum-resistant cryptography by 2030, a recent analysis found that…

Denver, CO, September 10, 2026 —
A significant number of United States states are failing to prepare for the potential disruption posed by quantum computers, which are projected to compromise current encryption methods as early as 2029. Despite federal mandates for a transition to quantum-resistant cryptography by 2030, analysis indicates a widespread lack of preparedness among state governments.
According to a recent assessment, 32 U.S. states do not have active plans in place to safeguard their sensitive data and critical infrastructure against the anticipated cyber threats stemming from advanced quantum computing capabilities. This gap leaves state-level digital assets vulnerable to future decryption and exploitation.
The impending threat is rooted in the projected ability of quantum computers to solve complex mathematical problems that underpin much of today’s standard encryption, commonly referred to as public-key cryptography. The timeline suggests this capability could emerge within the next five to six years, posing a significant risk to government operations, financial systems, and personal data stored and transmitted digitally.
Recognizing this future challenge, the U.S. federal government has established a deadline of 2030 for its agencies to transition to quantum-resistant cryptography. This directive aims to ensure that federal systems can withstand the cryptographic advancements expected from quantum technology. However, the recent analysis highlights that this nationwide push for security is not being uniformly adopted or planned for at the state level.
The specific details of the analysis, including the methodology used to assess state plans and the entities that conducted the review, were not provided. Similarly, the names of the 32 states identified as lacking active plans, as well as the types of sensitive data and critical infrastructure at particular risk, were not specified. The potential consequences of these vulnerabilities, such as data breaches or infrastructure disruptions, have not been detailed in the available information.
Without active planning and implementation of new cryptographic standards, states risk exposing vital information and services to potential adversaries capable of leveraging quantum computing power. The transition to quantum-resistant cryptography is a complex undertaking that requires significant foresight, investment, and technical expertise. The current preparedness level suggests that many states may face considerable challenges in meeting future security demands and timelines if proactive measures are not initiated.
Story summarized from the original created by Grant Johnson, Emily Mosier and Gaige Davila/Howard Center for Investigative Journalism ASU on www.denver7.com, see more information here.