Security.io Intelligence DeskFriday, 7 August 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Policy, Architecture and Cryptography · Executive briefing

US post-quantum programme moves from policy to named ownership

The first deadline under the 22 June executive order arrived on 22 July: federal agencies were required to identify a post-quantum migration lead. Procurement and product consequences now move closer.

RegulatoryData ProtectionSecurity Leadership
Read first

The first US federal post-quantum governance milestone has passed, while OMB requires detailed migration plans by 22 October. Federal suppliers, cloud providers and critical-infrastructure organisations should expect cryptographic evidence and product-roadmap questions to enter procurement well

Act now

Appoint one executive owner for cryptographic inventory, migration sequencing, architecture decisions, supplier engagement and progress reporting.

Accountable owner

CIO accountable for programme ownership; CISO, chief architect, procurement and product engineering jointly execute

Decision horizon

Appoint an enterprise owner immediately; establish the first defensible cryptographic inventory and supplier plan within 90 days

AssessmentHigh confidence
Emerging riskPublication of the proposed Federal Acquisition Regulation changes, CISA’s minimum elements for a cryptographic bill of materials, sector-specific guidance and vendor commitments for PQC-capable products.

What happened

The 22 June executive order required each federal agency head to identify a post-quantum cryptography migration lead and provide that person’s contact details to OMB and the National Cyber Director within 30 days. That first governance deadline arrived on 22 July. The order defines the lead as responsible for agency-wide cryptographic inventory management, development of a prioritised migration plan and coordination of cross-agency work. Public sources at publication do not establish whether every agency met the requirement.

OMB’s 24 June implementation memorandum requires agencies to submit migration plans within 120 days, making 22 October the next major planning deadline. Plans must prioritise high-impact systems, High Value Assets, highly sensitive data and information expected to remain mission-sensitive in 2030. The programme phases key-establishment migration through 2030, digital-signature migration in 2031 and broader completion by 2035. Systems unable to support PQC or hybrid cryptography are to be prioritised for replacement or decommissioning.

Why this matters now

The arrival of the first deadline changes post-quantum cryptography from an abstract standards discussion into an accountable programme with named ownership, planning dates and procurement consequences. The executive order directs a proposed Federal Acquisition Regulation change within 180 days that would require covered contractors to comply by the end of 2030 with applicable FIPS incorporating PQC algorithms. It also directs CISA to publish minimum cryptographic bill-of-materials elements.

Private enterprises are not broadly bound by the agency deadlines, but federal contractors, cloud providers and product vendors should expect customers to ask whether their systems can identify and replace quantum-vulnerable cryptography. Critical-infrastructure organisations are also explicitly within the policy’s assistance remit. Waiting for final contract clauses will compress discovery, testing, supplier negotiation and system replacement into a timetable governed by external customers rather than enterprise risk.

The decision for security leaders

Create ownership and inventory now rather than launching a speculative mass replacement of cryptography. The first objective is to locate asymmetric algorithms, identify data that must remain confidential beyond the migration horizon and determine which systems are configurable, upgradeable or structurally incapable of change. Prioritisation should combine confidentiality lifetime with business criticality, supplier lead time and normal refresh schedules.

Use planned modernisation to avoid duplicate expenditure. Cloud migrations, PKI changes, identity upgrades, network refreshes and software redevelopment should include explicit crypto-agility and PQC acceptance criteria. Procurement should reject unsupported claims of being quantum-safe and require named NIST standards, supported versions, performance constraints, interoperability plans and dates. Hybrid deployments should be piloted where justified, not assumed to be a simple universal bridge.

Evidence of closure

  • A named, funded programme owner with approved governance across security, architecture, procurement, legal, product and business units.
  • A versioned cryptographic inventory linking algorithms, keys, certificates and protocols to systems, owners, data lifetimes, suppliers and migration priority.
  • Supplier attestations or contractual roadmaps specifying supported NIST standards, product versions, release dates, dependencies and customer responsibilities.
  • A tested pilot demonstrating algorithm replacement or hybrid operation without unacceptable performance, interoperability, availability or recovery impact.

The Security.io assessment

The immediate executive decision is governance, not algorithm selection. Organisations that cannot name every place they depend on RSA, Diffie-Hellman or elliptic-curve cryptography cannot estimate cost, sequence migrations or answer customers. A cryptographic inventory should be treated as a maintained architecture and supply-chain artefact, not a one-off scanner output. It must link cryptography to systems, data, keys, owners, vendors, recovery processes and expected confidentiality lifetime.

The federal timetable is likely to influence commercial product roadmaps and contracting beyond the agencies directly covered. The proposed FAR change and future cryptographic bill-of-materials guidance could turn demonstrable crypto agility into a condition of market access. The prudent response is to establish evidence and purchasing leverage while standards-based products mature. Premature bespoke implementations create their own security and interoperability risk; inaction creates a shrinking replacement window for long-lived platforms and data already exposed to harvest-now, decrypt-later collection.

Questions for the morning meeting

  • Who owns the organisation’s cryptographic inventory, and can that person direct product, infrastructure and procurement changes?
  • Which data collected in 2026 must remain confidential in 2030 or beyond, and where is quantum-vulnerable cryptography protecting it?
  • What products would require replacement rather than configuration or software updates to support NIST-approved PQC?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network

Security.io Executive Roundtable: The 2027 CISO Agenda

CISO Roundtables & Executive events

View roundtables →
Invitation only
Sponsor's Notice · NoBrowser

Security.io CISO Dinner: The Secure Browser Decision

Virtual PC's & Secure Browsers in the Cloud

Request an invitation →
Black Hat week
Paid Placement · HackerFX

Security.io at Black Hat: Daily Intelligence Briefing

Catch the Daily News Where it Happens First

Follow the Black Hat desk →