The Quantum Threat and the Federal Mandate for Post-Quantum Cryptography The Quantum Threat and the Federal Mandate for Post-Quantum Cryptography The Quantum Threat and the Federal Mandate for Post-Quantum Cryptography The Quantum Threat and the Federal Mandate for Post-Quantum Cryptography 
  • About
    • Our Story
    • FRC Use Cases
    • Leadership
    • Events
      • Events
      • FRC Erie Summit
      • Trellix WISE and Hyperautomation
      • Event: Partner Webinar – Radiant Logic
    • Video Series
      • FRC Introduces Zero Trust
    • Community
    • Contracts
      • SEWP
      • Elastic ESI
      • Trellix ESI
  • Zero Trust
    • FRC Zero Trust Architecture
    • Zero Trust Pillar Activities
  • Services
    • Global Services & Solutions Group
    • Customer Advocacy Program (CAP)
  • Solutions
    • Solutions
    • OEM Partners
    • Achieve OPORD 8600 Compliance with Federal Resources Corporation & Trellix
  • News
  • Contact
    • Contact Us
    • CAREERS
    • EMPLOYEES
✕
EO 14409 and BOD 26-04: AI is compressing the gap between vulnerability disclosure and weaponized exploitation 
July 14, 2026
FRC Awarded State Grant to Accelerate Mercantile Building Redevelopment and Expand Technology Careers in Erie
July 17, 2026
July 16, 2026

The Quantum Threat and the Federal Mandate for Post-Quantum Cryptography 

For decades, modern digital security has relied on mathematical problems that are practically impossible for classical computers to solve. When you log into a secure government portal, send an encrypted message, or verify a digital signature, your data is shielded by public-key cryptography. A standard computer trying to brute-force these mathematical shields would take thousands of years. 

Quantum computers are not simply faster versions of today’s machines. For certain mathematical problems, they can use different algorithms that change what is practical. That matters because many public-key systems, including RSA, Diffie-Hellman, and elliptic-curve cryptography, rely on problems that a cryptographically relevant quantum computer could solve far more efficiently than a classical computer. While a cryptographically relevant quantum computer (CRQC) is not yet known to exist, OMB–26–15 states that steady advancements in the quantum computing field may yield a CRQC in the coming decade. When this happens, these computers will possess the capability to break widely used asymmetric encryption algorithms. 

This does not mean all encryption breaks overnight. The most immediate concern is public-key, or asymmetric, cryptography: the cryptography used for key exchange, digital signatures, certificates, PKI, TLS, VPNs, code signing, and authentication. These are the systems that allow users, devices, applications, and agencies to trust each other online. 

While a quantum computer of this scale does not yet exist, the threat is not sci-fi or a distant concern for the next generation. The concern is “harvest now, decrypt later”: adversaries can steal encrypted federal and commercial data today and store it until quantum capabilities make decryption possible. So, even though it may take a decade for CRQCs to become reality, data that is currently encrypted without using quantum-resistant algorithms are still at risk. 

To defend national security, critical infrastructure, and the digital economy against this capability, the federal government began laying the policy foundation in 2022 with National Security Memorandum 10, Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems. That memorandum framed quantum computing as both a strategic opportunity and a cybersecurity risk. In 2026, the White House followed with Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, and OMB Memorandum M-26-15. Together, these documents turn the post-quantum transition from a long-term planning issue into an accelerated federal execution mandate. 

The Policy Chain: NSM-10, EO 14412, and OMB M-26-15 

1. NSM-10: The Strategic Foundation 

Issued in May 2022, National Security Memorandum 10 set the initial groundwork. It formally stated that the United States must maintain its leadership in quantum information science while simultaneously mitigating the risks of quantum-vulnerable cryptography. NSM-10 recognized that future quantum capabilities could threaten civilian and military communications, critical infrastructure control systems, and internet-based financial transactions. 

NSM-10 introduced the split between National Security Systems (NSS) and non-NSS federal systems. For NSS environments, it directed NSA, acting as the National Manager for National Security Systems, to provide guidance on quantum-resistant cryptography migration, implementation, and oversight. 

NSM-10 also initiated the mandatory process for federal agencies to inventory their cryptographic assets. It reinforced the importance of identifying high-impact systems, meaning systems where a compromise of confidentiality, integrity, or availability would cause severe harm to agency operations, assets, or individuals. It also tied the federal migration timeline to the release of standardized commercial algorithms from the National Institute of Standards and Technology, making NIST’s post-quantum cryptography standards the foundation for future agency migration work. 

Just as important, NSM-10 introduced the idea that agencies should build toward cryptographic agility. A system is cryptographically agile when its encryption algorithms can be updated or replaced without requiring a complete redesign of the surrounding software, hardware, or network architecture. That concept appears again in EO 14412 and OMB M-26-15 because PQC migration is  a long-term modernization effort. 

2. EO 14412: The Federal Mandate 

Executive Order 14412 builds on NSM-10 by accelerating the transition. It establishes clear national policy: the United States must secure its information systems by migrating to cryptographic algorithms that resist both classical and quantum attacks. The order centralizes strategic oversight under the Office of Management and Budget and the Office of the National Cyber Director, while tasking NIST and the Cybersecurity and Infrastructure Security Agency with providing technical and risk-management guidance. 

EO 14412 also sets specific agency deadlines. Agencies must identify a PQC Migration Lead, review High Value Assets and high-impact systems, and begin preparing priority systems for migration. The order requires agencies to transition those systems to PQC for key establishment by December 31, 2030, and to PQC for digital signatures by December 31, 2031. 

3. OMB M-26-15: The Execution Blueprint 

OMB Memorandum M-26-15 serves as the operational execution blueprint for EO 14412. It applies to all executive departments and agencies, excluding National Security Systems, which are governed under NSM-10, mentioned above. It requires agencies to integrate PQC readiness into existing IT governance frameworks, software development lifecycles, asset management processes, and procurement workflows. 

In practical terms, NSM-10 defined the strategic problem, EO 14412 accelerated the mandate, and M-26-15 tells agencies how to execute. 

The Multi-Phase Migration Timeline 

The migration of the federal government’s large, complex IT ecosystem cannot happen overnight. Recognizing this, OMB M-26-15 outlines a structured, five-phase roadmap stretching from immediate strategic planning to full ecosystem modernization by 2035. 

Phase Timeframe Focus 
Phase 1 2026–2027 Strategy, planning, and discovery 
Phase 2 2027–2028 Pilots and early migration 
Phase 3 2028–2030 PQC key establishment for priority systems 
Phase 4 2031 PQC digital signatures for priority systems 
Phase 5 By 2035 Remaining systems, based on risk and commercial availability 

Phase 1: Strategy, Planning, and Discovery: 2026–2027 

Agencies must lay their organizational foundation immediately. By July 22nd, 2026(30 days from the Executive Order), each agency head is required to designate a PQC Migration Lead to oversee cross-agency coordination and cryptographic inventory management. By October 20th, 2026 (120 days from the Executive Order), agencies must submit a formal PQC Migration Plan to OMB and ONCD. The primary focus of this initial phase is establishing governance structures, conducting comprehensive asset discovery, and identifying High Value Assets and high-impact systems vulnerable to quantum attacks. 

Phase 2: Pilots and Early Migration: 2027–2028 

During this stage, agencies will initiate pilot programs to test PQC-ready implementations in controlled environments. GSA’s Federal Identity, Credential, and Access Management Office will work alongside participating agencies to test quantum-resistant physical and logical access systems. Lessons learned from these early pilots will be used to refine and mature the broader agency migration plans. 

Phase 3: Prioritized Key Establishment Migration: Deadline: December 31, 2030 

By the end of 2030, all federal High Value Assets, high-impact systems, and environments containing highly sensitive data must transition to NIST-approved PQC algorithms for key establishment, the methods used to securely exchange encryption keys over a network. 

Agencies should also treat TLS modernization as part of the PQC migration. OMB requires support for TLS 1.3 or a successor by January 2, 2030, because TLS 1.3 provides a cleaner foundation for PQC and hybrid key exchange at the network layer. 

Phase 4: Digital Signature Migration: Deadline: December 31, 2031 

One year after the key establishment deadline, agencies must transition these same high-priority systems to use PQC for digital signatures, the mechanisms used to authenticate identity and verify that data or software has not been altered. 

Phase 5: Full Migration: Target: 2035 

The final phase focuses on completing the migration of all remaining, lower-risk legacy systems, aligned with the broader availability of commercial PQC tools and cloud-based offerings. 

Technical Foundations: The New Cryptographic Standards 

The transition relies on new standards vetted during a multi-year global evaluation process led by NIST. Appendix A of OMB M-26-15 highlights three primary Federal Information Processing Standards that agencies must adopt to replace legacy, quantum-vulnerable public-key protocols. 

FIPS 203: ML-KEM: A Module-Lattice-Based Key-Encapsulation Mechanism standard used for secure key establishment. It is highly efficient but introduces larger public keys and ciphertext overhead than classical elliptic-curve systems. 

FIPS 204: ML-DSA: A lattice-based digital signature algorithm designed for general authentication. It provides balanced performance but generates signatures of roughly 1 to 2 kilobytes, which can strain legacy network bandwidth. 

FIPS 205: SLH-DSA: A stateless hash-based digital signature algorithm. Because its security relies on entirely different mathematical assumptions than lattice-based cryptography, it serves as a robust fallback standard. However, it requires significantly larger signatures, tens of kilobytes, and greater computational processing time during signing operations. 

Core Operational Requirements for Success 

To successfully execute this transition without disrupting mission operations, the directives outline several critical operational mandates. 

1. Risk-Based Prioritization 

Agencies are instructed to target their migration based on risk. High Value Assets, systems with an assigned FIPS 199 potential impact value of “high” for confidentiality or integrity, and logical access control systems must be prioritized. Systems holding data expected to remain sensitive in 2030 and beyond must be migrated first to protect against historical data harvesting. 

2. Cryptographic Agility 

A system is cryptographically agile when its underlying cryptographic algorithms can be updated or replaced without requiring major re-engineering of the software or hardware architecture. OMB M-26-15 explicitly requires that modernized systems achieve cryptographic agility, ensuring that if future mathematical breakthroughs compromise an early PQC algorithm, the system can rapidly pivot to an alternate standard. 

3. Automated Inventory and Discovery 

Given the scale of federal infrastructure, manual asset tracking is insufficient. The directives instruct agencies to leverage automated discovery tools to map out where encryption is being used across their ecosystems. To facilitate this automation, CISA and NIST are tasked with releasing public guidance defining a Cryptographic Bill of Materials, a structured metadata record that enables automated tools to inspect and report on the specific cryptographic components used within any software or hardware product. 

Automated inventory will also be necessary. Agencies cannot migrate what they cannot see. They will need tools that can identify where cryptography is used across applications, networks, cloud services, certificates, APIs, identity systems, software dependencies, and vendor-managed platforms. A continuously updated cryptographic inventory will be essential for prioritizing migration work, validating compliance, and reducing the risk of legacy algorithms remaining hidden in production systems. 

4. Procurement 

Agencies will need to procure and deploy cryptographic algorithms, tools, and platforms that support NIST-approved PQC standards. This includes technology that can support PQC key establishment, PQC digital signatures, TLS 1.3 or successor protocols, and hybrid cryptographic approaches during the transition period. 

Procurement teams should also evaluate whether vendors can demonstrate cryptographic agility. New systems should not lock agencies into algorithms that are difficult to replace later. As PQC standards mature and implementation guidance evolves, agencies will need technology that can adapt without requiring major redesign, replacement, or disruption to mission operations. 

Looking Ahead 

The PQC migration will touch nearly every place agencies use public-key cryptography: TLS, PKI, VPNs, identity systems, code signing, cloud services, APIs, and vendor-managed platforms. Agencies that start with inventory, prioritization, and cryptographic agility will have a much easier path than those that wait until the deadline. By treating PQC upgrades as a core component of standard lifecycle hardware refreshes, cloud migrations, and software updates, agencies can minimize operational friction and build a modern, agile defense capable of protecting public sector data well into the quantum era. 

FRC helps public sector organizations understand what these mandates mean in practical terms and identify the technology solutions needed to support post-quantum cryptography migration. From cryptographic inventory and risk prioritization to procurement, FRC can help agencies and partners translate NSM-10, EO 14412, and OMB M-26-15 into an actionable modernization path. Contact us today to discuss the path forward. 

Join Us at the Erie Summit

We are excited to announce that Eran Abramowitz of QIZ Security will be on-site speaking directly on Post-Quantum Cryptography, providing practical, real-world steps for agencies preparing their defense strategies. FRC will be hosting the Erie Summit on July 29th, and public sector IT and security leaders can register for free at the FRC Erie Summit page to secure their spot.

Related

Share
1

Related posts

August 4, 2026

Cryptographic Posture Management: The Foundation for Post-Quantum Readiness 


Read more
July 17, 2026

FRC Awarded State Grant to Accelerate Mercantile Building Redevelopment and Expand Technology Careers in Erie


Read more
July 14, 2026

EO 14409 and BOD 26-04: AI is compressing the gap between vulnerability disclosure and weaponized exploitation 


Read more

PRIMARY NAICS CODES:
541519 - Other Computer-Related Services

Compliance & Certifications:
CMMI® Maturity Level 3
ISO 9001:2015

FRC SALES TEAM
814.636.8020
sales@fedresources.com

CONTRACT VEHICLES:
NASA SEWP V: #NNG15SC61B
GSA IT-70 Schedule: GS-35F-0585T

© Copyright Federal Resources Corporation | Return Policy
CONTACT