The White House has directed federal agencies to start preparing for post-quantum cryptography (PQC) now—not because quantum computers are already breaking government encryption, but because sensitive data stolen today could be decrypted later. The directives set near-term planning duties and phased migration deadlines, while the sources available do not establish which agencies have tested systems or what those tests found.
What post-quantum cryptography means—and why agencies are preparing now
Post-quantum cryptography refers to cryptographic algorithms or methods designed to resist attacks by both quantum and classical computers. The aim is to replace vulnerable cryptographic functions before a cryptographically relevant quantum computer (CRQC) can threaten them.
The Office of Management and Budget says no CRQC is known to exist. It describes the timing of such a machine as uncertain, while warning that advances could produce one in the coming decade. The concern is that an adversary could collect encrypted information now and decrypt it later if a sufficiently powerful quantum computer becomes available. That risk makes long-lived or highly sensitive information a migration priority; it does not mean current encryption has already been broken. The White House order and OMB Memorandum M-26-15 frame this as preparation and risk reduction.
What the White House ordered
President Donald J. Trump signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” on June 22, 2026. It sets federal policy to transition information systems to NIST-approved PQC Federal Information Processing Standards (FIPS) and to assist critical-infrastructure owners and operators with their transitions.
#1 Best Overall
The order assigns strategic coordination and oversight to OMB and the National Cyber Director. The Department of Commerce, through NIST and in consultation with NSA and CISA, is to provide continuing technical guidance. Agency heads must designate migration leads, and OMB is directed to issue implementation guidance. These are instructions and deadlines, not evidence that each milestone has been completed.
Federal PQC deadlines at a glance
| Deadline | Required or directed action | Source and qualification |
|---|---|---|
| Within 30 days of June 22, 2026 | Each agency head identifies a PQC migration lead and sends the lead’s name and contact details to OMB and the National Cyber Director. | Executive Order 14412; a deadline in the order. |
| Within 90 days of June 22, 2026 | OMB issues guidance for agency reviews and migration planning, including treatment of high-value assets and high-impact systems. | Executive Order 14412; a deadline for OMB guidance. |
| Within 120 days of June 24, 2026 | Agencies submit a PQC Migration Plan to OMB and the National Cyber Director. | OMB M-26-15 states the deadline as 120 days. October 22, 2026 is the calculated calendar date. |
| December 31, 2027 | NIST pilot project reaches its completion target. | Executive Order 14412; a future target, not a report of completed testing. |
| December 31, 2030 | High-value assets and high-impact systems transition to PQC key establishment; agencies also prioritize migration of cryptographic systems to mitigate as much quantum risk as feasible. | Executive Order 14412 sets the system transition deadline; OMB M-26-15 sets the broader migration objective. |
| December 31, 2031 | High-value assets and high-impact systems transition to PQC digital signatures. | Executive Order 14412; a separate deadline from the key-establishment milestone. |
| Within 270 days of June 22, 2026 | CISA, coordinating with NIST, releases public guidance on minimum elements for a cryptographic bill of materials. | Executive Order 14412; intended to support automated assessment of cryptographic assets in hardware and software. |
The order’s review provision for high-value assets and high-impact systems excludes National Security Systems. NSA is separately directed to report annually on PQC migration status for agencies operating National Security Systems, beginning within 180 days. The order’s text sets these responsibilities and dates.
What agencies must do first
Assign responsibility across the agency
Agency heads are to name a PQC migration lead within 30 days of the June 22 order. OMB M-26-15 also calls for agency-wide governance: the work is not solely the CIO’s or CISO’s responsibility. Effective planning necessarily involves the offices that own systems, data, procurement, risk, and vendor relationships because cryptography is embedded across technology and supply chains.
Rank #2
Inventory systems and prioritize exposure
M-26-15 requires a prioritized migration of cryptographic systems in systems an agency owns or operates, aiming to mitigate as much quantum risk as feasible by December 31, 2030. Agencies need to understand where cryptography is used and assess systems by factors such as criticality, data sensitivity, cryptographic function, dependencies, and vendor readiness. The order’s distinct treatment of high-value assets and high-impact systems means agencies should not assume that one schedule or technical change fits every system.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Prepare and submit a migration plan
Agencies must send a PQC Migration Plan to OMB and the National Cyber Director within 120 days of the June 24, 2026 memorandum. The memorandum directs agencies to align plans with NIST Internal Report 8547, “Transition to Post-Quantum Cryptography Standards,” or its successor. That makes the plan a standards-based migration roadmap, rather than a general statement of intent.
Key establishment and digital signatures have different deadlines
PQC migration is not a single switch. The order separates two cryptographic functions, with different deadlines for high-value assets and high-impact systems:
- Key establishment: The processes that allow parties to establish shared cryptographic keys must transition to PQC by December 31, 2030 for the covered systems.
- Digital signatures: The mechanisms used to verify authenticity and integrity must transition to PQC by December 31, 2031 for those systems.
Those dates apply to the specified classes of systems in the executive order; they should not be misrepresented as a single universal deadline for every federal system or every cryptographic function.
What the standards references do—and do not—mean
The order calls for NIST-approved FIPS. OMB’s planning memorandum points agencies to NIST IR 8547 or a successor. NIST describes the federal PQC algorithms as FIPS standards intended to support implementation and interoperability. Agencies should distinguish approved standards from algorithms still under consideration: a candidate’s status or a reported flaw in a candidate is not the same as a break in an approved federal PQC standard.
For example, NIST’s PQC page reported on July 28, 2026 that a vulnerability was found in HAWK, a lattice-based signature algorithm under consideration for standardization. That report does not say an approved PQC FIPS was broken. See NIST’s post-quantum cryptography project page for its status information.
Rank #4
A separate federal preparation measure concerns transport security: an earlier executive-order amendment required agencies to support TLS 1.3 or a successor as soon as practicable and no later than January 2, 2030. That is adjacent preparation, not a substitute for the broader PQC migration requirements. The 2025 amendment states that TLS deadline.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for contractors and critical infrastructure
The order directs the FAR Council to publish a proposed rule requiring covered contractors to comply with applicable FIPS, including PQC standards, by December 31, 2030. It also directs a proposed rule concerning contractor vulnerability disclosure programs. These are rulemaking directions, not finalized regulations; the order alone does not establish that a final contractor rule is in force.
For critical infrastructure, the order directs Sector Risk Management Agencies to work with CISA to help owners and operators develop migration plans. It also directs the State Department and other agencies to encourage foreign governments and industry groups to adopt NIST-standardized PQC. It calls for coordination on cost-saving opportunities such as cloud migration and shared procurement, as well as accelerated cryptographic module validation processes.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
Does this mean agencies are already testing?
No agency-by-agency testing results are established by the directives described here. The order sets a NIST pilot completion target of December 31, 2027, but that is a future deadline, not proof that the pilot is finished or that agencies have completed tests. The available documents also do not establish whether OMB has issued the required 90-day guidance or whether contractor rules have advanced beyond the proposed-rule instructions.
The headline’s “Don’t wait to test” is a useful description of the urgency to prepare, not a verified quotation from the order or memorandum. What is established is the requirement to organize, inventory, plan, and migrate on specified timelines; claims about completed agency testing need separate agency or official status reporting.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

