Skip to content

Video companion

After NIST's Dustin Moody: your 12-month post-quantum strategy

Dustin Moody leads NIST's post-quantum cryptography standardization project. His guidance: 2035 is closer than it sounds, and large organizations should start migration planning now.

NIST post-quantum migration timeline.
How to Build Your 12-Month Post-Quantum Strategy With NIST's Dustin Moody Watch on YouTube

What the video gets right

Moody debunks common myths:

  • "We can wait until quantum computers exist." HNDL means data encrypted today may be decrypted later — migration timelines must account for data shelf life.
  • "PQC is a plug-and-play swap." Real systems span libraries, load balancers, HSMs, and third-party SaaS — coordinated change takes years.
  • "Standards aren't ready." FIPS 203, 204, and 205 are finalized; organizations can begin hybrid deployments now.

NIST IR 8547 provides deprecation and disallowance dates. The NCCoE Migration to PQC project demonstrates discovery and prioritization tooling.

What it does not cover

Moody describes the national playbook; your team needs asset-level proof. CISA's PQC initiative recommends automated discovery — but evidence for auditors requires signed, reproducible scan artifacts.

This quarter

  1. Conduct a cryptographic inventory aligned to NIST IR 8547 Phase 1 guidance.
  2. Join or review NCCoE migration demos for interoperable tooling patterns.
  3. Pilot hybrid key exchange on a non-production path and document before/after algorithm tags.

Continue on the Q-Day hub: PQC deadlines guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.