| | || A year ago, the quantum-security conversation in policy circles was about persuasion: convincing regulators that “harvest now, decrypt later” was real, and that the threat would not wait for the hardware. That argument is largely won. In June 2026, the United States signed Executive Order 14412, turning years of advisories into dated federal deadlines. The European Union has a coordinated roadmap; China has a decade of state-built quantum infrastructure. The standards are finished. Which surfaces a harder question—and it is the one regulators now actually face: not whether to act, but how to know who is ready. We have migration guides, algorithm catalogues, and executive orders. What we do not have is a governance instrument: a way for a board to ask “how ready are we?”, an auditor to verify the answer, and a regulator to compare answers across licensees. Closing that gap is the next task. The premise no longer needs labouring. In 2021, the NSA stated plainly that “adversaries may be collecting encrypted data now, waiting for the day when quantum computers can decrypt it.” The tactic needs no quantum hardware—only interception, cheap storage, and patience—and it targets data whose value outlives its encryption: subscriber identities, location and billing archives, lawful-intercept material, long-horizon intellectual property. For telecommunications, the calculus is not close. Mosca’s inequality holds that if the years data must stay secret (X) plus the years to migrate (Y) exceed the years to a capable quantum computer (Z), exposure exists now. Telecom data carries confidentiality obligations of a decade or more; enterprise migration realistically takes five to seven years; the prudent horizon sits near 2030—2031. Ten plus five exceeds eight. The migration start date is set by arithmetic, not by quantum optimism. And the threat is targeted, not total. Shor’s algorithm breaks the public-key