Schumpeter's cold douche: What quantum destroys before it creates.
There is a certificate sitting in a server rack at a defense supplier somewhere in the Midwest, and it expires in 2031.
Nobody in that building thinks about it. It renews automatically. It is plumbing. It has the same standing in the capital allocation conversation as the parking lot resurfacing, which is to say none, and it has held that standing for twenty years without anyone being wrong to grant it.
That certificate, and the roughly four hundred thousand others like it across that firm's estate, are not plumbing. They are inventory. They have a shelf life, the shelf life has been published, and the write-down date is on a federal document that anyone can read.
I want to be careful here, because this is the point in the argument where quantum commentary usually reaches for the doomsday slide, and the doomsday slide is both tedious and analytically useless. So let me put the emotional register where it belongs and leave it there: nothing about this is frightening. It is arithmetic. What follows is an attempt to do the arithmetic properly, which almost nobody in this market is doing, and which is the entire reason the numbers are as bad as they are.
What Schumpeter actually said, and why it is not a motivational poster.
Joseph Schumpeter published Capitalism, Socialism and Democracy in 1942, and in it he described what he called the perennial gale of creative destruction: the process of industrial mutation that incessantly revolutionizes the economic structure from within, incessantly destroying the old one, incessantly creating a new one.
The phrase has since been laundered into a business cliché, which is a shame, because Schumpeter was making a considerably harder claim than the cliché carries. He was not saying that progress has costs. He was saying that the destruction is the mechanism. It is not a regrettable side effect of the creation. It is how the creation is financed. Capital tied up in the old structure has to be released before it can be redeployed into the new one, and the releasing is not gentle.
Schumpeter also had a name for the phase of the cycle in which this bill comes due. He called it a cold douche: the corrective shock that forces a system to reorganize around what is actually true rather than what was assumed during the boom.
Here is what the cold douche looks like on a balance sheet, stated in the language of a chief financial officer rather than an economic historian. Creative destruction is the event in which an asset's economic life turns out to be shorter than its accounting life. The asset still functions. It still appears on the schedule at book value. And it is worth materially less than the schedule says, because the world has quietly stopped valuing what it does.
That is the whole concept. Unanticipated economic obsolescence, arriving faster than the depreciation schedule that was built for it.
The asset being destroyed is not hardware. It is an assumption.
Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC) are not products your firm owns. That is precisely what makes this difficult to see.
They are the assumption underneath the products you own. They authenticate your suppliers. They sign your firmware. They protect the design data moving between your engineering team and your tier two machine shop. They establish that the maintenance package arriving at an airframe in service is the package your firm actually sent. They are not a line item. They are the condition that makes several thousand line items worth what they are carried at.
Peter Shor demonstrated in 1994 that a sufficiently capable quantum computer factors large integers and solves discrete logarithms efficiently, which is to say it dissolves the mathematical hardness that both schemes rest on. Nothing about that result has been contested in thirty-two years. The only open variable has ever been timing.
And here is where this instance of creative destruction is genuinely unusual, in a way that ought to matter far more to boards than it currently does.
Schumpeter's gale normally arrives without a calendar. Firms do not get advance written notice that their capital stock is about to be revalued. This time they did.
The National Institute of Standards and Technology (NIST) published the replacement standards on August 13, 2024: FIPS 203, 204, and 205. NIST Internal Report 8547 then set the schedule for what is being replaced. RSA and ECC at current strengths are deprecated in 2030 and disallowed in 2035. The National Security Agency's Commercial National Security Algorithm Suite (CNSA) 2.0 tightens it further for anyone touching national security systems: from January 1, 2027, new acquisitions are expected to be compliant by default.
A published obsolescence date is an extraordinary gift. It converts an unquantifiable risk into a dated liability, and a dated liability can be modeled, financed, and governed. Most of the firms holding it are treating it as a reprieve instead, which is the single most expensive interpretive error available in this market right now.
There is also one component of the destruction that is not scheduled, because it has already happened. Encrypted data exfiltrated today can be stored and decrypted later. If your firm holds design data, program information, or contract material with a confidentiality life longer than the remaining life of the cryptography protecting it, that loss has already occurred. You simply have not booked it yet. I state that as an economic fact rather than a threat, because it changes a number rather than a mood: it means part of your exposure is not a future contingency at all, and should stop being discounted like one.
Why deferral costs more than deferral appears to cost.
Now to the part that decides the money, and the reason the migration case does not need fear to make itself.
In 1963, Robert Eisner and Robert Strotz introduced a result that Robert Lucas and John Gould developed into the standard model of investment behavior over the following five years. The result is this: the cost of adjusting a firm's capital stock is a convex function of the rate of adjustment. Adjusting quickly does not cost proportionally more than adjusting slowly. It costs more than proportionally more.
This is one of the least glamorous findings in neoclassical economics and one of the most consistently ignored in practice. Every operator already knows it in their bones. Pulling a product launch forward by half does not double the cost, it triples it. The theory simply says that this is a general property of adjustment, not a local failure of planning.
Cryptographic migration is an adjustment problem of exactly this type, and the quantity of work is fixed regardless of when you start it. You have to discover every cryptographic asset in the estate, including the ones nobody documented and the ones embedded in equipment whose original vendor no longer exists. You have to inventory certificates, keys, protocols, and supplier interfaces. You have to identify long-life products already in the field carrying firmware you cannot update remotely. You have to sequence the replacements so the plant does not stop. Then you have to prove all of it to an assessor.
That body of work executed across eight years and the same body of work executed across two years are not the same project at different prices. They are different projects. The compressed version carries premium labor rates for a specialist skill in structurally short supply, parallel workstreams that should have run sequentially, elevated error rates, the rework those errors generate, and one cost that never appears in the business case: the total collapse of your negotiating position.
A firm migrating under time compression does not conduct price discovery. It accepts terms. Every vendor in the transaction can see the deadline as clearly as you can, and a buyer with no option to walk is not a buyer, it is a captive. This is the same information asymmetry problem the lemon market piece described earlier in this series, except that time compression removes the one defense a buyer had left, which was patience.
The Department of War just proved this in public.
On July 13, 2026, the Department of War suspended CMMC Phase 2, along with the third-party assessment requirements scheduled to enter contracts on November 10.
I wrote in June that November 10 was a revenue event rather than a compliance burden. The date moved. I want to be direct about that rather than quiet about it, because what moved the date is the most instructive thing that has happened in defense sector governance this year.
The stated reason was capacity. More than 100,000 defense industrial base firms required a third-party assessment. Roughly 100 assessors existed. Small Business Administration data suggested future phases could cost small and midsize firms more than seven billion dollars annually. A reform task force was stood up with a report due around September 13, 2026.
Read that capacity ratio again, because it is the adjustment cost function made visible. The convexity is not only a firm-level effect. When an entire industry is compelled to adjust simultaneously, every firm bids for the same scarce specialist capacity at the same moment, and the input price rises for everyone. The system did not fail because the standard was wrong. It failed because a hundred thousand firms tried to adjust in the same window, and the window was the only variable soft enough to move.
Most executives will read the suspension as more time. That is the expensive reading, and here is the correct one.
The regulator moved the date because the capacity was not there. Post-quantum migration has the same industry-wide simultaneity, a worse capacity ratio, a larger scope of work, and a deadline set by mathematics rather than by policy. NIST can move a date. It cannot move Shor's algorithm. There is no task force for number theory.
Firms that begin adjusting now do so at the flat part of the cost curve, while capacity is available and terms are negotiable. Firms that wait will adjust on the steep part, alongside everyone else, at whatever price the market sets for scarcity.
What this does to defense and aerospace specifically.
Two structural features make this sector's exposure larger than the compliance framing suggests.
The first is product life. A component shipped into an airframe or a platform in 2026 may still be in service in 2050. Its embedded cryptography has to survive a disallowance date of 2035. That is not a future information technology project. It is a design decision being made this quarter, on parts currently in production, by engineers who have not been told the constraint exists.
The second is supply chain depth. You are not migrating your firm. You are migrating your tier three suppliers' ability to authenticate to you. Your migration is complete when your slowest supplier's migration is complete, which makes this a portfolio adjustment problem across hundreds of counterparties with wildly different capital positions and adjustment speeds. Governing that is a capital allocation function. It has never been a chief information security officer function, which is why assigning it there has produced the results it has.
The delta, stated plainly.
Two firms with identical cryptographic exposure, identical scope, and identical eventual compliance can end up with materially different economics. Not because one bought better technology. Because one adjusted at a rate the cost function rewarded and the other did not.
That difference is the delta. It is the gap between what the full quantum journey makes available and what a manufacturer actually captures, and in this stage of the journey it is almost entirely a function of governance timing rather than technology selection. LFI models the value-to-cost multiple across the full journey at three to five times, archetype-dependent. That figure is modeled and illustrative, and we label it that way every time. What is not modeled is the direction of the adjustment cost curve, which has been settled economics for sixty years.
Security is the entry fee. It is the stage where the destruction happens and none of the creation does, which is exactly why it is the stage firms defer, and exactly why deferring it is the most expensive thing they can do. The cryptographic foundation rebuilt here is the data integrity infrastructure that Quantum Utility requires, and the operational discipline of Utility is what makes Quantum Advantage affordable. Stop at compliance and you have paid the entry fee for a prize you then decline to collect.
Schumpeter's point was never that destruction is unfortunate. It was that destruction is the mechanism, and that the firms which survive the gale are the ones that recognized which of their assets were already worth less than the schedule claimed.
Your certificate estate is on a schedule. The schedule is published. The only variable your board actually controls is the rate at which you adjust, and that variable is priced.
The cold douche is coming either way. You get to choose whether you walk into it or get pushed.
Contact LFI to scope a Quantum Readiness Enterprise Assessment and put a defensible number on your cryptographic adjustment cost before the curve steepens.
About the author
Shayne De la Force has spent thirty years leading executive functions across Japan, Germany, Switzerland, Australia, and the United States, working with organizations from semiconductor manufacturers to global industrial brands, and is the Founder and Chief Executive Officer of LFI, author of Strategic Entanglement, and a sitting member of the Quantum Economic Development Consortium (QED-C) Technical Advisory Committee in Washington D.C.
LFI (www.lfiusa.com) was built on that operational foundation to govern quantum decisions with discipline and independence: vendor-independent, with no equity in quantum vendors and no referral fees, so its only commercial interest is in the quality of the governance outcome, not in which technology you buy. Full bio here.