Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST officials say staff reductions are forcing the agency to prioritize work, including the review of cryptographic products. The available figures point to pressure on capacity, but they do not show that staffing cuts have delayed a particular encryption standard or post-quantum cryptography (PQC) deadline.

What NIST officials said about staffing pressure

NIST’s workforce figures describe different periods and scopes. In a June 2025 budget presentation, NIST said it had reduced staffing by 420 employees as of May 2025, through voluntary separation programs and reductions in probationary staff. In January 2026, CyberScoop reported that NIST Information Technology Laboratory (ITL) director Kevin Stine said the agency had shed more than 700 positions since 2025. CyberScoop also reported Stine’s statement that ITL had 289 staff after losing about 89 employees over the preceding year. These are separately attributed figures, not a single current audited headcount. CyberScoop, January 21, 2026; NIST, June 2025.

Stine described the consequence as a change in how NIST allocates effort: “It’s forcing a very focused discussion on prioritization of our activities.” He said critical emerging technologies, work aligned with NIST’s strategy, and administration priorities would be at the top of the list and adequately resourced. That is an account of prioritization, not a quantified forecast of which projects will slip.

Why cryptographic validation takes sustained staff effort

NIST’s cryptographic module validation work assesses commercial information-technology hardware and software for compliance with cryptographic requirements. The process includes testing and reviewing technical documentation, which officials described as lengthy and sometimes unstructured. David Hawes, a program manager in NIST’s computer security division, summarized the purpose as determining whether federal purchasers and users can trust a product’s cryptography and whether it meets the applicable standard. A validation is therefore more than checking a product against a short list: human review is part of evaluating the evidence behind a compliance claim.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

CyberScoop reported that its review of NIST’s previous 30 cryptographic validations found an average of 348 days per project. The same January 2026 report said the backlog had fallen from nearly two years in 2020 to about six months at the time of reporting. The 348-day figure is an average project duration across that review; the backlog figures describe approximate waiting time. They measure different things and should not be read as contradictory or interchangeable.

Hawes said staffing losses made it harder to continue improving the queue. That is a warning about capacity, not evidence that a particular validation has been delayed or that every application will take longer.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

What the staffing changes do—and do not—establish

The reported figures and officials’ comments support a conclusion that NIST has less staffing capacity than before and is making prioritization decisions while maintaining labor-intensive work. They do not quantify how much slower validations or standards work have become because of the reductions. The cited reporting does not identify a specific NIST standard or deliverable that missed a date because of the cuts.

It is also important not to treat the 2025 agency-wide reduction, the later report of more than 700 positions shed since 2025, and the ITL staffing count as comparable snapshots. They refer to different dates and organizational scopes, and the January 2026 figures are reported statements rather than an independently verified current headcount.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GoTrust Idem Key C USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
  • Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.

How staffing pressure intersects with the PQC transition

NIST says three finalized post-quantum cryptography standards are ready to implement. Organizations should inventory where vulnerable algorithms are used and plan updates; readiness of the standards does not mean every vendor or agency has deployed them. NIST describes the standards as mandatory for federal systems and widely adopted elsewhere. NIST: Post-Quantum Cryptography.

Federal policy now gives covered systems staged migration dates. Executive Order 14412, dated June 22, 2026, directs agencies to review inventories of high-value assets and high-impact systems and sets these deadlines:

Rank #4
GoTrust Idem Key A USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-A & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. TAA compliant and supports Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Works with Chrome, Safari & Edge across major OS.
  • Plug & play USB-A Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication and identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise and daily use.
Cryptographic function Deadline for covered high-value assets and high-impact systems
PQC key establishment December 31, 2030
PQC digital signatures December 31, 2031

The order excludes National Security Systems from these requirements. It also directs NIST to provide continuing technical guidance, complete a PQC migration pilot on an appropriate subset of NIST systems by December 31, 2027, and revise Cryptographic Module Validation Program processes to accelerate validations. The directives are subject to applicable law and availability of appropriations. Executive Order 14412, June 22, 2026.

The deadlines make NIST’s validation capacity relevant to migration, but they do not show that cuts have already delayed PQC deployment or standards. The order’s instruction to accelerate validation processes is a policy directive; it is not itself evidence of a measured delay caused by staffing losses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why PQC migration involves more than changing an algorithm

NIST defines crypto agility as the ability to replace and adapt cryptographic algorithms across protocols, applications, software, hardware, firmware, and infrastructure while maintaining security and ongoing operations. In practice, that means organizations need to find where cryptography is embedded, understand dependencies, and coordinate updates across systems. A standard being available is only one step in that operational transition. NIST, Crypto Agility Considerations for the Transition to Post-Quantum Cryptography.

The timing of a quantum computer capable of threatening current cryptography is uncertain. NIST mathematician and cryptographic expert Andrew Regenscheid said, “We don’t know, but we do see significant progress in industry and the research community.” He also noted the “harvest now, decrypt later” risk: an adversary could collect encrypted information now and attempt to decrypt it in the future. Because migrations take years, NIST advises planning rather than waiting for a reliable date for such a machine. NIST interview, July 30, 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.