when agencies talk about post-quantum crypto in this context, are they mostly thinking about replacing tls and signing systems first, or the long-lived data they need to protect for years?
> replacing tls and signing systems first
Not usually. The boring answer is “protect what must still be readable in 10, 20, 30 years,” because harvest now, decrypt later is the real pain point. TLS and signing get inventory attention because they are visible and centralized, but the migration pressure comes from long-lived records and firmware, not from swapping out every session key on day one.