Governments and industry watchdogs have spent years warning that quantum computers could one day break the encryption protecting everything from bank transfers to state secrets. A new commentary published by CircleID argues that warnings alone are no longer enough.
The piece, titled "Quantum Readiness Governance: Why Regulators Must Measure, Not Just Warn," makes the case that regulators need to move from issuing cautionary statements to actively measuring how prepared organizations are for the arrival of powerful quantum machines. In other words, according to CircleID, oversight should be built around evidence and metrics rather than general alarm.
The framing points to a governance gap. Warnings tell organizations that a risk exists, but they do not reveal whether anyone is actually doing the work to counter it — inventorying vulnerable systems, testing new cryptography, or setting timelines for upgrades. By calling on regulators to measure readiness, the CircleID commentary suggests that accountability and standardized assessment should become part of how quantum risk is governed.
The underlying concern is often summarized in the security community as "harvest now, decrypt later": the possibility that sensitive data intercepted today could be stored and unlocked once quantum computers mature. That threat model has pushed regulators and standards bodies toward the idea of "quantum readiness," but the CircleID argument is that readiness only means something if it can be observed and quantified.
This story matters because it reframes a distant-sounding technological threat as a present-day governance question: if regulators can measure quantum readiness rather than merely warn about quantum risk, businesses and critical infrastructure operators may be held to concrete standards long before the first code-breaking quantum computer arrives.