Every CTO now fields the board question: "What's our quantum strategy?" The honest answer for most enterprises has three parts — one urgent, one worth watching, one safely ignorable — and conflating them is how organizations end up funding science projects while neglecting the single quantum risk that's already on the clock.
Urgent: post-quantum cryptography is a migration, and migrations take years
The only quantum threat with a deadline you don't control is cryptographic. "Harvest now, decrypt later" is a present-tense attack: adversaries are recording encrypted traffic today to decrypt when fault-tolerant machines arrive. If your data has a confidentiality lifetime beyond roughly a decade — health records, financial archives, IP, government contracts — the exposure window is already open. NIST's standards (ML-KEM, ML-DSA, SLH-DSA) finalized in 2024; US federal deadlines and sector regulators are now pulling timelines forward. The work — cryptographic inventory, vendor pressure, hybrid TLS rollouts, HSM upgrades — is a multi-year program for any real estate of systems. This is the quantum line item your 2026 budget should actually contain.
Watch: hybrid quantum-classical algorithms, with a falsifiable trigger
Quantum processors won't replace your AI stack; the plausible near-term role is as specialized accelerators inside classical pipelines for narrow problem classes — certain optimization, sampling, and simulation workloads. Pilot results in logistics and materials are interesting but remain at scales classical heuristics still dominate. The disciplined posture is a watch trigger, not a program: define the demonstration that would change your mind (e.g., a published, audited advantage on a problem isomorphic to one you own, at production scale), assign one architect to track the field quarterly, and pre-design where a quantum subroutine would slot into your optimization stack if the trigger fires. Cost: a few engineer-days a quarter. Option value: real.
Ignore: quantum machine learning for mainstream workloads
For the LLM, vision, and tabular workloads that constitute enterprise AI, there is no credible evidence path to quantum advantage on any planning horizon a CTO is paid to manage. Today's hardware — hundreds to thousands of noisy qubits against error-corrected requirements in the millions for relevant algorithms — isn't a gap that roadmap optimism closes. Vendor decks claiming quantum-enhanced enterprise AI deserve the same scrutiny as blockchain CRM did. Spend the attention budget on the AI engineering deficits you verifiably have: evaluation, data foundations, inference economics.
Quantum readiness is 90% cryptography, 9% watchful option-keeping, 1% physics enthusiasm. Budget in that ratio.
The one-page program
- Quarter 1: Cryptographic inventory — where do you use RSA/ECC, with what data lifetimes, through which vendors. This is unglamorous and is the entire foundation.
- Quarters 2–4: Hybrid PQC rollout on external-facing TLS; PQC requirements written into every new vendor contract and HSM refresh.
- Ongoing: Crypto-agility as an architecture principle — abstract your cryptographic providers so the next migration is a configuration project, not an archaeology project.
- Quarterly: One-page quantum-watch memo against your pre-defined triggers. No trigger, no spend.
The CTOs who navigate this well are doing something deeply unfashionable: treating quantum as a risk-management and option-pricing problem rather than an innovation theater opportunity. The board question deserves a confident answer. This is what one looks like.