Back to Blog

Government Telecom Operators and Quantum Readiness: Where Most Programs Fall Short

Government telecom operators face longer procurement cycles than commercial carriers, which compresses the time available for quantum-safe migration. This article identifies where most programs fall short and what effective programs do differently.

Government telecom quantum readiness program assessment

The Procurement Cycle Problem

Government telecom operators in South and Southeast Asia face a structural problem that commercial carriers do not. Their equipment replacement cycles are 12 to 18 years for core infrastructure, driven by procurement processes that require multi-year budget allocation, tender processes, vendor qualification, and compliance documentation before any deployment decision can be made. By the time a quantum-safe migration procurement completes the approval process, the threat environment may have already changed materially.

Consider the timeline for a state-owned telecommunications company in a country where major infrastructure procurement requires parliamentary budget approval. An initiative that begins with a threat assessment in 2025, proceeds through internal risk classification, escalates to a ministerial working group on cybersecurity, is included in a capital budget submission, is approved in a budget cycle, goes through a tender process, and then enters a multi-year deployment contract could easily reach 2030 or 2031 before new quantum-safe equipment is in production service. That timeline is comparable to or later than many forecasts for cryptographically relevant quantum computing capability.

The procurement cycle problem cannot be solved by simply wanting to move faster. It reflects real institutional requirements for accountability and audit trails in public sector technology procurement. What it does mean is that quantum-safe migration in government telecom contexts needs to start much earlier in the planning cycle than commercial operators, and needs to use migration approaches that can make progress within the existing procurement framework rather than requiring a complete parallel track.

The Equipment Longevity Problem

The second structural problem is equipment longevity. Government telecom operators in the region often operate equipment that was installed 10 to 15 years ago, with vendor support contracts that have been extended because procurement for replacement equipment has not been approved. This equipment typically runs firmware with cryptographic implementations that predate the post-quantum cryptography standards and cannot be updated to support them.

For fiber backbone equipment, core routers and optical transport nodes that provide TLS-encrypted management channels and MPLS tunnel encryption, the cryptographic capabilities are baked into the line card hardware and ASIC firmware. A router purchased in 2012 may have hardware cryptographic acceleration for AES-128 and RSA-2048, but no mechanism to support the larger key sizes and different algorithms required by ML-KEM. The vendor may have end-of-lifed the hardware, meaning no firmware updates are available regardless of what the procurement timeline looks like.

This creates a gap in the remediation path that overlay encryption is designed to bridge. If core backbone equipment cannot be updated in the required timeframe, the practical option is to deploy quantum-safe encryption at the network layer above it: at the customer premises equipment, at the data center ingress points, or at dedicated encryption appliances that sit inline in the traffic path. The sensitive data is then quantum-safe encrypted before it reaches the legacy equipment that cannot support PQC natively.

What Effective Programs Do Differently

The government telecom programs that are making genuine quantum migration progress, based on published initiative descriptions from several national cybersecurity agencies in the region, share a set of characteristics that distinguish them from programs that are producing documentation without deployment progress.

The first characteristic is early identification of high-sensitivity traffic flows. Rather than attempting a comprehensive migration of all encrypted communications simultaneously, effective programs identify the 5 to 10 percent of traffic flows that carry the highest-sensitivity data (inter-agency secure voice, classified data links, critical infrastructure management channels) and concentrate early deployment resources on those paths. These high-sensitivity paths are typically served by dedicated infrastructure rather than shared commercial equipment, making targeted quantum-safe deployment more tractable.

The second characteristic is using overlay encryption as the bridging mechanism. Rather than waiting for a full equipment replacement cycle, effective programs deploy purpose-built quantum-safe encryption appliances inline on the identified high-sensitivity paths. These appliances can be procured, qualified, and deployed on timelines compatible with operational security procurement, rather than the multi-year infrastructure procurement cycle. They provide quantum-safe protection for the traffic flowing through them without requiring changes to the underlying equipment.

The third characteristic is piloting before committing to large-scale procurement. A pilot deployment covering a single high-sensitivity traffic path, from one data center to a ministry headquarters or between two regional nodes, provides the operational experience needed to write accurate specifications for the larger procurement. Organizations that write procurement specifications for technology they have not operated at small scale produce specifications that are inaccurate in practice, which causes expensive scope changes during deployment.

Supplier Concentration Risk

Government telecom operators in South and Southeast Asia often have high dependence on a small number of equipment vendors for their core network infrastructure. The quantum-safe migration posture of those vendors directly determines the migration options available to the operator.

The major network infrastructure vendors have varying quantum-safe roadmaps. Some have published specific timelines for ML-KEM support in their current product lines. Others are less specific. For operators locked into a single vendor for core routing equipment, the practical question is not "which PQC algorithm should we deploy" but "when will our vendor support it, and in which hardware generations?"

Supplier concentration risk in the quantum migration context has a specific form: if a vendor's quantum-safe firmware update requires hardware replacement (because the existing line card ASICs cannot support the required operations), then the migration timeline is constrained by the hardware procurement cycle, not just the software update cycle. Operators with high supplier concentration should be asking their vendors specifically which hardware generations will support PQC via firmware update and which will require hardware replacement. This information dramatically changes the migration cost and timeline estimate.

The Gap Between Assessment and Deployment

Many government telecom operators in the region have completed threat assessments or commissioned quantum readiness studies. The gap that most programs fall into is between the assessment phase (documenting the risk) and the deployment phase (actually changing the encryption posture). Assessments are relatively easy to fund and execute; they produce a document that satisfies audit requirements and demonstrates institutional awareness. Deployment requires budget, vendor qualification, change management, and operational risk tolerance that are harder to obtain.

The programs that bridge this gap successfully use the assessment phase to identify a small, well-scoped pilot deployment that can be funded from existing operational security budgets rather than requiring a new capital budget submission. A pilot deployment that protects one high-sensitivity traffic path with a purpose-built quantum-safe encryption appliance costs a fraction of a full infrastructure migration, can be completed in 6 to 12 months, and produces the operational experience and internal advocacy needed to justify the larger procurement in the next budget cycle.

We are not suggesting that pilots are a substitute for full migration programs. They are not. A pilot covering one traffic path does not address the harvest-now exposure on the other 95 percent of the network. The argument for starting with a pilot is tactical: it builds institutional capacity for quantum-safe deployment, creates a concrete evidence base for larger budget requests, and provides the technical foundation for writing accurate procurement specifications for the larger program. Starting with a pilot is better than waiting for the conditions to be perfect for a full program, because those conditions will not arrive before the threat matures.

Quantum-safe infrastructure

Ready to start your deployment?

Satellite QKD key delivery for financial networks, critical infrastructure, and government communications.

Request Access View Pricing
Related articles
Critical Infrastructure Threat Model
Threat Model for Critical Infrastructure: Why OT Encryption Has a Shorter Window Than IT
Zero Trust Meets Quantum-Safe
Zero Trust Meets Quantum-Safe: Key Distribution in a Perimeter-Free Architecture
The Harvest-Now, Decrypt-Later Threat
The Harvest-Now, Decrypt-Later Threat: What Operators Need to Know Now