Red Hat has published a blog outlining steps organisations can take to prepare hybrid cloud environments for “Q-day”, the point at which quantum computers could break widely used public key cryptography.
The post argues that preparation should begin now due to the risk of “harvest now, decrypt later” activity, in which attackers collect encrypted traffic, intellectual property and logs today in the expectation they can be decrypted when quantum capabilities mature.
The blog also links quantum-readiness planning to US government timelines. It cites White House Executive Order 14412, which it says sets expectations for federal agencies to reach pilot post-quantum cryptography readiness by 2027 and complete full execution by 2029. It also points to the National Security Agency’s Commercial National Security Algorithm Suite 2.0, including an enforcement deadline for commercial TLS implementations by 2030.
In the post, author JP Jung outlines four steps for organisations preparing their hybrid cloud environments. These include inventorying cryptographic usage across environments; testing post-quantum cryptography in non-production settings to understand performance and compatibility impacts; shifting security controls from individual applications to platform layers; and maintaining stronger control over where sensitive data is stored and processed.
The blog includes product-specific examples, stating that Red Hat Enterprise Linux 10 ships with NIST-standardised post-quantum algorithms including ML-KEM and ML-DSA, and that Red Hat OpenShift 4.22 provides quantum-safe key exchange with ML-KEM hybrid key exchange enabled by default for TLS handshakes between control-plane components.
The post concludes by recommending organisations start with cryptographic inventory work, review Red Hat documentation and release notes, and plan a migration path ahead of expected deadlines.

