The arrival of cryptographically relevant quantum computers, known as “Q-day,” is becoming an urgent timeline requiring immediate security planning. Malicious actors are already executing “harvest now, decrypt later” tactics, capturing and storing encrypted enterprise traffic, intellectual property, and data logs to decrypt once quantum hardware becomes available.
Red Hat advocates addressing this threat prior to a crisis by embedding post-quantum cryptography (PQC) capabilities directly into foundational hybrid cloud infrastructure layers.
The urgency is supported by regulatory timelines. U.S. White House Executive Order 14412 mandates federal agencies to pilot PQC migration by 2027 and execute full-scale implementation by 2029. Additionally, the National Security Agency’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) requires quantum-safe algorithms for national security systems, setting strict enforcement deadlines for commercial TLS implementations by 2030. Organizations delaying migration until quantum hardware arrives risk lagging three to five years behind, leaving archived data vulnerable.
To address these security challenges, Red Hat Enterprise Linux (RHEL) 10 is shipping with NIST-standardized post-quantum algorithms, including ML-KEM and ML-DSA, enabled natively at the operating system level. Red Hat OpenShift inherits these capabilities from RHEL rather than constructing distinct cryptographic libraries, operationalizing compliance and security math across distributed environments. Shifting security from application layers down to unified infrastructure protects artificial intelligence (AI) assets from future decryption and regulatory exposure while reducing operational complexity.
Red Hat outlines four key actions for organizations to prepare for Q-day:
- Inventory Cryptographic Footprints Across Hybrid Cloud: Organizations must gain visibility into data encryption and key creation locations across distributed systems, identifying automated software connections relying on outdated public security algorithms. RHEL 10 provides system-wide cryptographic policies that enable quantum-resistant algorithms by default, allowing teams to test host communication, application performance, and latency prior to production deployment.
- Test Next-Generation Cryptographic Primitives in Non-Production Environments: Transitioning to quantum-resistant encryption requires evaluating impacts on application performance and network overhead. RHEL 10’s system-wide crypto-policy profiles, including the FUTURE policy, allow operators to shift a host’s cryptographic stance via single-command updates. Furthermore, Red Hat OpenShift 4.22 offers production-ready quantum-safe key exchange, with ML-KEM hybrid key exchange active by default for TLS handshakes between control plane components without requiring application code changes.
- Shift Security Boundaries from Application to Platform Layer: Requiring individual development teams to manually rewrite code for PQC introduces operational friction and configuration errors. Because adversaries can record current network traffic—such as GPU training data, model weights, or credentials—for future decryption, Red Hat OpenShift applies quantum-resistant algorithms at the platform level. Upgrades made in RHEL propagate through OpenShift automatically, removing the need for developers to manage algorithms or rewrite TLS code.
- Assert Operational Control Over Data Placement and Execution: Operational control over data residency and execution paths is critical for quantum readiness. Relying entirely on centralized public cloud control planes leaves systems vulnerable to external policies. Operators can utilize isolated environments and hardware-enforced solutions, such as confidential containers, to maintain strict data boundaries and protect sensitive information during active processing.
Red Hat advises organizations to begin preparations by auditing their current cryptographic footprints, reviewing RHEL and OpenShift documentation, and assessing migration roadmaps before regulatory deadlines take effect.
Microsoft WTI 2026: Thai workforce leads AI adoption, Organizations lag behind
Thais lead Southeast Asia in Gemini lifestyle use, 87% prompts in local language


