What happened
The 22 June executive order required each federal agency head to identify a post-quantum cryptography migration lead and provide that person’s contact details to OMB and the National Cyber Director within 30 days. That first governance deadline arrived on 22 July. The order defines the lead as responsible for agency-wide cryptographic inventory management, development of a prioritised migration plan and coordination of cross-agency work. Public sources at publication do not establish whether every agency met the requirement.
OMB’s 24 June implementation memorandum requires agencies to submit migration plans within 120 days, making 22 October the next major planning deadline. Plans must prioritise high-impact systems, High Value Assets, highly sensitive data and information expected to remain mission-sensitive in 2030. The programme phases key-establishment migration through 2030, digital-signature migration in 2031 and broader completion by 2035. Systems unable to support PQC or hybrid cryptography are to be prioritised for replacement or decommissioning.
Why this matters now
The arrival of the first deadline changes post-quantum cryptography from an abstract standards discussion into an accountable programme with named ownership, planning dates and procurement consequences. The executive order directs a proposed Federal Acquisition Regulation change within 180 days that would require covered contractors to comply by the end of 2030 with applicable FIPS incorporating PQC algorithms. It also directs CISA to publish minimum cryptographic bill-of-materials elements.
Private enterprises are not broadly bound by the agency deadlines, but federal contractors, cloud providers and product vendors should expect customers to ask whether their systems can identify and replace quantum-vulnerable cryptography. Critical-infrastructure organisations are also explicitly within the policy’s assistance remit. Waiting for final contract clauses will compress discovery, testing, supplier negotiation and system replacement into a timetable governed by external customers rather than enterprise risk.
The decision for security leaders
Create ownership and inventory now rather than launching a speculative mass replacement of cryptography. The first objective is to locate asymmetric algorithms, identify data that must remain confidential beyond the migration horizon and determine which systems are configurable, upgradeable or structurally incapable of change. Prioritisation should combine confidentiality lifetime with business criticality, supplier lead time and normal refresh schedules.
Use planned modernisation to avoid duplicate expenditure. Cloud migrations, PKI changes, identity upgrades, network refreshes and software redevelopment should include explicit crypto-agility and PQC acceptance criteria. Procurement should reject unsupported claims of being quantum-safe and require named NIST standards, supported versions, performance constraints, interoperability plans and dates. Hybrid deployments should be piloted where justified, not assumed to be a simple universal bridge.
Evidence of closure
- A named, funded programme owner with approved governance across security, architecture, procurement, legal, product and business units.
- A versioned cryptographic inventory linking algorithms, keys, certificates and protocols to systems, owners, data lifetimes, suppliers and migration priority.
- Supplier attestations or contractual roadmaps specifying supported NIST standards, product versions, release dates, dependencies and customer responsibilities.
- A tested pilot demonstrating algorithm replacement or hybrid operation without unacceptable performance, interoperability, availability or recovery impact.
The Security.io assessment
The immediate executive decision is governance, not algorithm selection. Organisations that cannot name every place they depend on RSA, Diffie-Hellman or elliptic-curve cryptography cannot estimate cost, sequence migrations or answer customers. A cryptographic inventory should be treated as a maintained architecture and supply-chain artefact, not a one-off scanner output. It must link cryptography to systems, data, keys, owners, vendors, recovery processes and expected confidentiality lifetime.
The federal timetable is likely to influence commercial product roadmaps and contracting beyond the agencies directly covered. The proposed FAR change and future cryptographic bill-of-materials guidance could turn demonstrable crypto agility into a condition of market access. The prudent response is to establish evidence and purchasing leverage while standards-based products mature. Premature bespoke implementations create their own security and interoperability risk; inaction creates a shrinking replacement window for long-lived platforms and data already exposed to harvest-now, decrypt-later collection.
Questions for the morning meeting
- Who owns the organisation’s cryptographic inventory, and can that person direct product, infrastructure and procurement changes?
- Which data collected in 2026 must remain confidential in 2030 or beyond, and where is quantum-vulnerable cryptography protecting it?
- What products would require replacement rather than configuration or software updates to support NIST-approved PQC?