Automated cryptographic inventory and CBOM, PQC key establishment by end of 2030, PQC signatures by end of 2031, full migration by 2035.
At a glance
| Type | Government policy |
|---|---|
| Jurisdiction | US |
| Who it applies to | US federal agencies and, through upcoming FAR rules, federal contractors and their software suppliers. |
Cryptography requirements
| Reference | Requirement | What a scan and inventory can evidence |
|---|---|---|
| OMB M-26-15 | Maintain an automated, continuously updated cryptographic inventory; submit a PQC migration plan; TLS 1.3 required by 2030-01-02. |
|
Key dates
- Agency PQC migration plans due (120 days after OMB M-26-15).
- High-value and high-impact systems on PQC key establishment; federal contractors expected to comply with FIPS including PQC (FAR rule pending).
- High-value and high-impact systems on PQC signatures.
- Mitigate as much quantum risk as feasible (NSM-10); full migration.
Sources
- Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks · The White House
- OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography · The White House (OMB)
- National Security Memorandum 10 (NSM-10) on quantum computing · The White House (archived)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.