Dell is now shipping personal computers with quantum-resistant BIOS verification, embedded controller signing and off-host integrity checks, a capability Lenovo has not publicly documented. This move addresses an immediate threat: the “Harvest Now, Decrypt Later” (HNDL) risk, where financial records, health data, intellectual property, and government communications are captured for future decryption. “Adversaries don’t need quantum computers to do damage now,” highlighting that compromised data and forged firmware updates represent present-day vulnerabilities as organizations face approaching deadlines for post-quantum cryptography compliance.
Harvest Now, Decrypt Later: The Current Data Confidentiality Risk
The potential for retroactive decryption highlights that the threat isn’t limited to the future arrival of powerful quantum computers. The lifespan of current cryptographic methods is a key factor driving this immediate concern, as most public-key cryptography used for data protection has a defined expiration date in a post-quantum computing environment. This timeframe is particularly critical when considered alongside typical PC refresh cycles, which average three to five years.
A device purchased without a quantum-resistant migration path may fall out of compliance with standards like the U.S. National Security Systems CNSA 2.0 procurement deadline of January 1, 2027, before it is even replaced, leaving data vulnerable to the HNDL attack vector. Google’s estimation that Q-Day could arrive as early as 2029 further compresses this window of risk. The implications extend beyond simple compliance. The integrity of firmware is also at stake.
Firmware attacks are already a significant security concern, and quantum computing capabilities will worsen them, potentially allowing attackers to bypass traditional security measures. Compromised firmware integrity relies on public-key algorithms that a sufficiently powerful quantum computer will eventually break, enabling the forgery of signatures and the delivery of malicious updates that appear authentic. According to Dell, this vulnerability exists below the operating system level, outside the reach of conventional security tools, and threatens classified data, sensitive intellectual property and locally run artificial intelligence models.
Trust Now, Forge Later: Quantum Threats to Firmware Integrity
Firmware attacks pose an escalating threat because compromised integrity relies on public-key algorithms susceptible to future quantum computers, and Dell is addressing this risk with current shipments. Unlike other major manufacturers, Dell implements quantum-resistant cryptography across the entire firmware trust chain, including its embedded controller and BIOS updates, using the NIST SP 800-208 Leighton-Micali Signature verification scheme.
This proactive approach extends to off-host BIOS verification, employing SHA-512 hashing, and Dell validates BIOS integrity against an external reference, a capability not publicly documented in competitors like Lenovo, the company says. The absence of publicly available documentation detailing post-quantum cryptography (PQC) integration at the hardware root of trust in Lenovo’s commercial PCs creates a significant security gap, as organizations lack evidence of protected firmware verification and clear migration paths to post-quantum algorithms.
This deficiency is particularly concerning given that devices may reach their natural end-of-life before quantum resistance becomes a requirement, potentially necessitating costly early retirement or remediation efforts. “Once quantum decryption arrives, attackers could forge these signatures, making malicious content appear authentic and trusted,” highlighting the potential for attackers to bypass network defenses and directly compromise device integrity. This capability means attackers do not require a network foothold to manipulate firmware, instead forging a signature and having a device accept the tampered update as legitimate, a scenario that emphasises the importance of proactive, hardware-level security measures.
Dell’s PQC Implementation: BIOS Verification & Secure Signing
This off-host verification uses SHA-512 hashing, ensuring a quantum-resistant check of the BIOS before system startup and providing a critical layer of defense against compromised firmware. This comprehensive implementation addresses a potential longevity issue for devices lacking proactive post-quantum cryptography, as systems may require early retirement or costly remediation before reaching their natural end-of-life.
Dell’s protections are available now in current commercial PCs, a contrast to Lenovo’s absence of publicly documented hardware-level post-quantum cryptography for its equivalent offerings. The company frames this as a “systems problem, not a single checkpoint,” emphasizing the importance of cohesive firmware verification, BIOS integrity and endpoint resilience across the entire trust architecture.
The significance of this layered approach lies in its ability to secure the hardware root of trust, a foundational element for overall system security, and to establish a platform-level decision rather than relying on application-level patches. “Dell can point to protections tied directly to the post-quantum trust chain on the PC itself, while Lenovo has not publicly documented a comparable implementation,” according to the company, highlighting a specific gap in competitor offerings.
Buyers should prioritize these features when evaluating PC refresh cycles, specifically inquiring whether BIOS integrity is verified off-host against a trusted, immutable reference using NIST-standardized hashing, as this ensures a robust defense against future quantum-based attacks.
CNSA 2.0 & Q-Day: PC Lifecycles and Post-Quantum Compliance
The significance of this proactive approach lies in the timeline surrounding both CNSA 2.0 requirements and the projected arrival of “Q-Day,” when sufficiently powerful quantum computers could break current encryption standards. While the U.S. National Security Systems face a procurement deadline of January 1, 2027, estimates suggest quantum decryption could arrive as early as 2029, creating a narrow window for data compromise. Has estimated Q-Day could arrive as early as 2029.
The lack of public documentation regarding Lenovo’s equivalent protections raises concerns about long-term data security for purchasers of their commercial PCs. Currently, there is no public evidence that Lenovo validates BIOS integrity against quantum-resistant algorithms, nor any announced architecture for transitioning embedded controllers or BIOS integrity paths.
This gap is not minor, as it leaves organizations with limited visibility into the quantum-resistant capabilities of Lenovo systems. Highlighting the potential for compromised firmware to bypass traditional security measures, Dell’s protections, in contrast, offer a verifiable layer of defense against this evolving threat, securing the foundational elements of system trust and providing a clearer path toward sustained post-quantum security.



See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
