Ask ten security leaders about post-quantum cryptography and you'll get ten versions of the same nervous shrug. The word "quantum" alone scares off half the room. But talk to the people actually running PQC migrations at scale, and a much more concrete picture shows up — one with a real deadline, a real budget conversation, and a real technical playbook.
Two conversations ahead of Black Hat USA 2026 gave a good look at that picture from two different angles: Tom Patterson, emerging tech cybersecurity lead at Accenture, who has spent a decade helping the world's largest organizations plan their migrations, and Anusha Vaidyanathan and Dhiraj Sehgal at Versa Networks, who are building PQC directly into the network fabric those organizations run on.
The deadline is real, and it's closer than "someday"
Patterson has been doing this long enough to have a 2017 White House workshop transcript to compare notes against. "It's pretty much on track or faster than we had expected," he said, pointing to the chip advances that landed late last year — Google's Willow chip followed a week later by a rival claiming 5x the speed. Quantum computers stopped being theoretical the day you could rent time on one in the cloud for $100 a minute.
NIST's deprecation notice made it official: 2030 is the date to start deprecating RSA and ECC. Patterson said Accenture's clients have broadly accepted 2030, plus or minus two years, as their finish line — not 100% complete, but with their most critical systems, continuity of operations, and crown-jewel data locked down against harvest-now-decrypt-later attacks.
Versa's Vaidyanathan sees the same urgency, but from the traffic itself. "Harvest now, decrypt later is a today's problem. It's a past problem," she said. "It's not a future problem." The data adversaries want to decrypt once quantum computers mature is already sitting on the wire, encrypted with algorithms that won't hold. That's driving fast movement from regulated and critical-infrastructure customers — oil, electricity, financial services — well ahead of the rest of the market.
Where the two views converge: it's a coordination problem, not a shopping problem
Patterson's biggest finding after ten years of this work isn't technical. "The cost of a post-quantum algorithm is exactly the same as the cost of a classical algorithm," he said. "It's just a matter of there's a transition program you've got to fund." Done right, it can be net-neutral over a ten-year lifecycle, because you end up using encryption more efficiently across the whole estate.
The real barrier is coordination — inside the organization and across it. Accenture's eight-step methodology, which the firm has published at Davos for years, walks clients through strategy, discovery, and ecosystem coordination before they touch architecture. "It's not just you that's making this change," Patterson said. "Thousands of your suppliers are also changing the way they're going to communicate with you." Most of Accenture's clients are still in the first half of that eight-step process.
Versa's Dhiraj Sehgal described a similar coordination gap playing out inside client organizations right now, just at the team level: the infrastructure group handling PQC plumbing and the team exploring agentic AI security aren't talking to each other yet. "That converges" eventually, he said, "but it's too early" today.
What "PQC-ready" actually means at the network layer
This is where Versa's side of the conversation gets useful for anyone building or buying network security today. PQC-ready doesn't mean ripping out existing crypto — it means hybrid key exchange, combining classical elliptic-curve Diffie-Hellman with the NIST-approved ML-KEM algorithm. "We don't want to just take and go completely PQC-native with just ML-KEM," Vaidyanathan said. "We want to crawl, walk, run." Data encryption itself stays on AES-GCM, which is already considered quantum-safe — the vulnerability is in how keys get negotiated, not in the encryption of the data itself.
Versa's architecture protects that key exchange across the data plane, control plane, and management plane alike — branch-to-hub traffic, but also the Versa Controller, Concerto/Director, and the analytics and messaging layers that manage the network. That last part matters: "A lot of people don't think about the management plane," Vaidyanathan said. "They only think about protecting the data."

Versa's PQC crypto engine sits in the data plane (SD-WAN hub or SASE gateway), the control plane (Versa Controller), and the management plane (Concerto/Director, Analytics, Messaging Service) alike — using hybrid ECDH + ML-KEM key exchange with AES-GCM data encryption.
For enterprises not ready for a full rollout, there's a lighter first step: quantum-resistant IPsec, using pre-shared post-quantum key negotiation, layered onto existing branch-to-hub tunnels. Vaidyanathan described a regulated, latency-sensitive customer — a trading environment — starting exactly there. "There's no migration involved," she said. "It's just one knob, and then the key negotiation happens automatically. There's no forklift involved."
The interoperability problem is real, but not everywhere
Patterson raised a pointed challenge for anyone evaluating vendors right now: put a reporter's skeptical eye on "PQC-ready" marketing claims. Accenture built a quantum test lab specifically to check whether products that claim readiness actually work together. "We just take all the products that say that they're PQC-ready and we plug them together," he said. "An HSM from here and a PKI from here, and they don't work. They don't communicate together. They each work individually."
Versa's answer is more nuanced than the blanket complaint suggests. Versa-to-Versa interoperability is solid by design. Client-to-server interoperability — a browser talking to Gmail or Salesforce — already works as long as both ends support the same hybrid standard. Where it genuinely doesn't exist yet is site-to-site interoperability between different vendors' PQC implementations — Versa talking to a Cisco PQC deployment, for instance. But per Vaidyanathan, that's less a broken promise than an unasked question so far: "People are not asking for that kind of interoperability yet."
The most common mistake, from both sides
Patterson's version: organizations underestimate how much of their environment actually depends on legacy encryption, and nobody owns the problem. "They didn't realize how big the encryption issue was," he said. Most clients don't have anyone in charge of encryption today; by 2030, Accenture expects most will have a VP-level owner and a dedicated cryptographic center of excellence.
Versa's version is more granular: teams focus on key management and forget data encryption, or they underestimate the hardware acceleration PQC algorithms need at scale — one reason Versa works directly with Intel and AMD on their acceleration roadmaps rather than assuming commodity hardware will keep up.
What to check in your own environment this week
Both sources converged on a practical starting list for network engineers and architects:
- Map every data-in-transit deployment — who's talking to whom, and how it's architected
- Confirm whether your management plane is protected, not just your data plane
- Build a cryptographic bill of materials (a C-BOM) rather than trying to brute-force an inventory with spreadsheets
- Check what algorithms your vendors actually support in transit, not just what their marketing claims
- Watch for NIST's CNSA 2.0 suite and upcoming digital signature and code-signing standards — the data-in-transit algorithms are only the first wave
Where this is headed
Patterson expects the second half of this year to bring real movement on PKI standards specifically — "not a lot of go-buy-my-whiz-bang," as he put it, but genuine technical progress that should mostly land by 2027. And after years of quantum being a niche Black Hat topic — "maybe 100 people in the room" five or six years ago — both sources expect the subject to draw a crowd this year.
Agentic AI is the wild card on both sides of this conversation, but for different reasons. For Accenture, generative AI has compressed the timeline enterprises are working against — Patterson pointed to those decades-old, deeply buried certificates with 50-year lifespans that used to be safely forgotten. "Now, with generative AI, you can just expect that an adversary is going to be able to find some way in and get it." For Versa, agentic AI and PQC are still two separate workstreams inside most client organizations — related, but not yet convinced they need each other. Expect that to change.