What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The NSA’s October 1, 2026 announcement sets two milestones for National Security Systems (NSS): new commercial NSS must be capable of supporting quantum-resistant algorithms starting in 2027, and legacy NSS that cannot support them are to be phased out by 2030. These are NSS requirements, not universal deadlines for every commercial system. A separate federal schedule in Executive Order 14412 covers high-value assets and high-impact systems outside NSS, with deadlines for post-quantum key establishment in 2030 and digital signatures in 2031.
What the NSA’s CNSA 2.0 announcement requires
The NSA identifies CNSS Policy 15 as the governing policy for the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). Its October 1, 2026 announcement accelerates implementation planning for NSS: new commercial NSS must be capable of supporting quantum-resistant algorithms beginning in 2027, while legacy systems that cannot support them are slated for phase-out by 2030.
“Capable of supporting” describes a capability milestone for new NSS, not a claim that every system will switch algorithms on the same day. The legacy-system milestone is about systems that cannot support the new algorithms. NSA describes the transition as a long-term effort involving government, industry, academia, standards, and technical guidance.
Morgan Stern, NSA Effort Lead for Quantum Resistance, said on October 1, 2026: “We are working closely with academia and industry to develop standards and guidelines, educate stakeholders across the national security enterprise, and integrate advanced algorithms to strengthen our digital defenses.”
#1 Best Overall
How the NSS timeline differs from the wider federal schedule
Executive Order 14412, signed June 22, 2026, sets separate milestones for federal high-value assets and high-impact systems that are not NSS. The order distinguishes two cryptographic functions: establishing keys and applying digital signatures. Its dates should not be merged with NSA’s NSS acquisition and legacy phase-out milestones.
| System scope | Cryptographic function or milestone | Deadline or start | Responsible policy framework |
|---|---|---|---|
| New commercial NSS | Must be capable of supporting quantum-resistant algorithms | Starting in 2027 | NSA; CNSS Policy 15 and CNSA 2.0 |
| Legacy NSS unable to support quantum-resistant algorithms | Phase-out | By 2030 | NSA; CNSS Policy 15 and CNSA 2.0 |
| Federal high-value assets and high-impact systems outside NSS | Transition to PQC for key establishment | By December 31, 2030 | Executive Order 14412, with assigned federal planning and coordination responsibilities |
| Federal high-value assets and high-impact systems outside NSS | Transition to PQC for digital signatures | By December 31, 2031 | Executive Order 14412, with assigned federal planning and coordination responsibilities |
EO 14412 also assigns migration-planning and coordination work, calls for support to critical-infrastructure owners and operators, and includes a proposed contractor rule. A proposed rule is not the same as a final requirement. The order’s dates apply to the federal system categories it specifies; they do not make every company directly subject to those deadlines.
What post-quantum cryptography protects against
Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist attacks using both classical and quantum computers. NSA and NIST frame the transition as preparation for a future threat, not a response to evidence that a quantum computer can currently decrypt deployed encryption.
Rank #2
“Harvest now, decrypt later” and long-lived secrets
NSA warns that an adversary could collect encrypted information now, retain it, and try to decrypt it if future quantum capabilities make that possible. This “harvest now, decrypt later” risk is most relevant to information whose confidentiality must last for years or decades. It does not mean that the collected data has already been decrypted.
Authentication, signatures, and certificates
Confidentiality is not the only concern. NSA also describes a “trust now, forge later” risk involving authentication, signatures, and certificates. Digital signatures help establish whether a message, software update, or document came from the claimed signer and has not been altered. A transition therefore needs to address both key establishment and signature mechanisms, on the timelines and for the systems covered by the applicable policy.
Which PQC standards are ready, and what is still changing
NIST says three post-quantum standards are finalized and ready to implement. Its overview identifies ML-KEM and ML-DSA among the finalized standards; NIST describes them as standards for post-quantum key establishment and digital signatures, respectively. The transition is not a reason to deploy an unfinalized candidate in place of an approved standard: NIST distinguishes finalized standards from algorithms still under evaluation.
Rank #3
NIST’s overview also says that the July 28, 2026 HAWK vulnerability finding concerned an algorithm still under consideration, which was subsequently withdrawn. NIST says the finding did not affect finalized standards such as ML-KEM and ML-DSA. Separately, NIST selected HQC as a fifth algorithm for post-quantum encryption in March 2025; that selection is distinct from the three standards NIST says are finalized and ready to implement.
Implementation involves more than choosing an algorithm. NIST says products, services, and protocols will need updates, and notes that industry standards groups, including the IETF, are incorporating PQC into protocols such as TLS. Compatibility work and agency guidance will therefore matter alongside the algorithm standards themselves.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Why the transition raises national-security and industry concerns
Data with a long confidentiality lifetime
Organizations need to identify information that would remain sensitive well beyond its creation or transmission. If intercepted ciphertext could still cause harm when decrypted years later, waiting until a system’s ordinary replacement cycle may leave too little time to migrate.
Rank #4
Complex dependencies across systems and vendors
Cryptographic algorithms can be embedded in applications, network protocols, devices, services, and operational processes. NSA characterizes the change as one of the largest and most complex migrations in computing history. Joint NSA, CISA, and NIST guidance emphasizes government-industry collaboration and vendor engagement because a change in one component can depend on updates elsewhere.
Deadlines depend on system category
NSA’s 2027 and 2030 milestones address NSS under CNSS Policy 15. EO 14412’s 2030 and 2031 deadlines apply to specified federal high-value and high-impact systems outside NSS. NIST’s standards can be used in commercial technologies, and protocols are evolving, but that does not mean every commercial organization is directly governed by either deadline. Contractors should distinguish the order’s proposed rule from any final requirement, and organizations should check applicable sector and agency guidance.
Costs and performance effects are not quantified here
The cited NSA, NIST, and White House materials do not provide a sourced implementation-cost estimate, measured performance penalty, or industry-wide adoption statistic. The work will require updates and coordination, but a specific budget, speed impact, or adoption rate should not be inferred from the policy dates alone.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
How organizations can prepare for PQC migration
Joint NSA/CISA/NIST guidance recommends beginning with readiness planning, inventory, prioritization, and vendor engagement. The following sequence turns those recommendations into an operational starting point; it is not a universal scoring formula or a substitute for applicable agency requirements.
- Assign ownership and establish a roadmap. Name the teams responsible for cryptographic transition and create a readiness plan with governance, dependencies, and decision points. NSA Cybersecurity Director Rob Joyce said in the agencies’ August 21, 2023 guidance announcement: “The transition to a secured quantum computing era is a long-term intensive community effort that will require extensive collaboration between government and industry. The key is to be on this journey today and not wait until the last minute.”
- Inventory cryptographic assets and dependencies. Identify systems, algorithms, certificates, protocols, and vendors that rely on cryptography, including dependencies that may sit inside products or services rather than in code your organization controls directly.
- Prioritize by risk and migration difficulty. Consider data sensitivity, how long confidentiality must last, system criticality, and dependencies that could slow replacement. The joint guidance calls for prioritizing sensitive and critical assets; it does not prescribe one scoring method for every organization.
- Ask vendors for documented plans. Request their PQC roadmap, compatibility approach, expected update path, and information about dependencies. Record which systems need vendor changes and which can be updated under your own control.
- Track the deadline that actually applies. Separate NSS obligations under CNSA 2.0 from EO 14412 milestones for covered non-NSS federal systems. For contractors and critical infrastructure, verify whether a rule is proposed or final and check current agency or sector-specific guidance rather than treating the dates as universal company deadlines.
- Revisit technical guidance as it develops. Monitor NIST standards and implementation guidance, as well as relevant agency instructions, so migration choices align with finalized standards and evolving protocol support.
What the milestones mean for readers
The immediate change is a policy-led migration schedule: NSS capability requirements begin in 2027, while unsupported legacy NSS are targeted for phase-out by 2030; covered non-NSS federal systems have separate deadlines for key establishment and digital signatures. The practical work starts before those dates with asset discovery, long-lived-data prioritization, vendor coordination, and migration planning. The quantum threat described by NSA and NIST is future-facing, but the systems and information that may need protection already exist.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

