The world’s largest powers now treat cryptography as critical national infrastructure. We cannot afford to be spectators.
In June 2026, the United States issued two executive orders that accelerate the nation’s transition to post-quantum cryptography while expanding investment in quantum technologies. Together, they send a clear message: computation has become an instrument of national sovereignty. Just as nations protect their airspace, energy grids and telecommunications networks, they must now protect the cryptographic foundations that make the digital economy possible.
For decades, national security was measured primarily in physical terms – territory, military capability and economic strength. Today, however, one of the greatest strategic vulnerabilities is technological dependency. A nation may retain full political independence while relying on cryptographic systems, cloud platforms, semiconductor supply chains or digital infrastructure that it neither designs nor controls. Dependency rarely arrives through conquest. It arrives through infrastructure that others own.
Nowhere is this more evident than in public-key cryptography – the invisible foundation of digital trust. Every day, billions of digital certificates authenticate websites, software updates, financial transactions, government services and connected devices. Public and private cryptographic keys establish secure communications, verify identities and protect sensitive information. This infrastructure underpins everything from online banking and healthcare systems to military communications and critical infrastructure.
Quantum computers threaten this foundation. While they are not yet capable of breaking today’s widely deployed public-key algorithms at scale, sufficiently powerful quantum computers (referred to as Cryptographically Relevant Quantum Computers) are expected to compromise the classic cryptographic methods used for key exchange, public-key encryption, and digital signatures.
The risk is not merely that future systems become vulnerable; it is that adversaries are already harvesting encrypted communications today with the intention of decrypting them once quantum capabilities mature. For governments and institutions responsible for information that must remain confidential for years or decades, the transition to post-quantum cryptography is not a future project. It is a present obligation.
The significance of the new US mandates extends well beyond Washington. They signal a shift from research to implementation that will influence procurement requirements, technology supply chains and international standards. Global software vendors, cloud providers, financial institutions and technology manufacturers will increasingly require cryptographic discovery services and quantum-resistant security across their products and services. Organizations throughout the UAE and the wider region will inherit these expectations whether they prepare for them or not.
The real question is therefore not whether the region will adopt post-quantum cryptography, but whether it will help shape the technologies and standards that define it.
The UAE recognised this challenge early. At the Technology Innovation Institute (TII), researchers have contributed directly to the international standardization of post-quantum cryptography within the US National Institute of Standards and Technology’s global standardization process. These are the very standards now being studied and adopted through the latest US federal mandates. QuantumGate provides a comprehensive platform designed to help organizations prepare for the post-quantum transition. Rather than treating migration as a one-time software upgrade, QuantumGate enables enterprises to discover cryptographic assets across complex environments, inventory keys and certificates, identify quantum-vulnerable algorithms, assess risk based on the sensitivity and longevity of protected data, and develop phased and prioritized migration strategies. By providing visibility into cryptographic dependencies and supporting crypto-agile architectures, it helps organizations transition to quantum-safe security with minimal operational disruption.
Research developed in Abu Dhabi is also helping secure sensitive data across financial services, healthcare and government on multiple continents. Following the acquisition of TII-developed cryptographic technologies – including post-quantum protections- by US confidential computing company OPAQUE, technology is flowing from the Middle East, not simply into it. That represents an important shift in how the region contributes to the global security ecosystem.
Yet sovereignty is never the achievement of a single institution. It is built through sustained investment across an entire innovation ecosystem. Through TII and the wider Advanced Technology Research Council, the UAE has invested across the technologies that increasingly define national resilience: quantum computing, post-quantum cryptography and quantum sensing. Together, these capabilities enable nations not only to compute and innovate, but also to secure communications, authenticate digital identities and protect critical infrastructure without relying entirely on technologies controlled elsewhere.
The implications extend well beyond national security. Modern economies depend on trusted digital infrastructure. Every financial transaction, software update, AI service, electronic passport, medical record and industrial control system ultimately relies on cryptographic trust. Nations that build quantum-resilient infrastructure will be better positioned to attract investment, support innovation and participate in the next generation of the global digital economy. Those that delay may find themselves paying more for emergency migration while becoming increasingly dependent on foreign technology providers.
For governments and enterprises alike, migration cannot begin with replacing a few algorithms. Every organization should first understand where cryptography exists across its systems: certificate authorities, hardware security modules, identity management platforms, virtual private networks, cloud services, embedded devices, industrial control systems and software signing infrastructure. Many organisations do not have a complete inventory of where cryptographic keys, certificates and public-key algorithms are deployed, making migration far more complex than expected.
The next priority is crypto-agility – the ability to replace cryptographic algorithms without redesigning entire systems. Earlier cryptographic transitions generally involved replacing one algorithm with a stronger version of the same mathematical approach. Post-quantum cryptography is fundamentally different. It replaces the mathematical foundations of public-key infrastructure itself. Keys become larger, certificates change, protocols evolve, and every layer of digital infrastructure – from browsers and servers to connected devices and cloud services – must adapt. This is not a software patch. It is a multi-year re-engineering effort.
The nations and institutions that begin this transition today will enter the quantum era with trust intact. Those that wait will be forced to migrate under pressure, exposing critical systems while relying on others to secure what they could no longer secure themselves.
In the twenty-first century, sovereignty will be defined less by the territory a nation controls than by the trust infrastructure it builds. The UAE possesses the talent, the resources and the strategic vision to help shape that future. The question is no longer whether the quantum era is coming. It is whether we will enter it as architects of digital trust – or merely as consumers of technologies designed elsewhere.
This opinion piece is authored by Dr. Najwa Aaraj, Chief Executive Officer, Technology Innovation Institute, and Chief Executive Officer, QuantumGate.
Source: Tahawul Tech
