President Trump signed Executive Order 14409 on June 22, 2026, establishing legally binding timelines for migrating all federal information systems to post-quantum cryptography (PQC). The order sets December 31, 2030, as the deadline for key establishment and December 31, 2031, for digital signatures, using NIST-standardized quantum-resistant algorithms.

What the Order Requires

The executive order mandates adoption of three NIST standards: FIPS 203 (ML-KEM, derived from CRYSTALS-Kyber) for key exchange, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. NIST finalized these standards in August 2024.

Agencies must designate a PQC migration lead within 30 days and submit migration plans to the Office of Management and Budget and the National Cyber Director within 90 days. A NIST pilot program must be completed by December 31, 2027. Federal contractors face updated Federal Acquisition Regulation requirements through rules to be proposed within 180 to 270 days. CISA and sector risk management agencies will provide migration assistance to critical infrastructure operators.

Why It Matters

The order directly targets the “harvest now, decrypt later” threat: adversaries are currently collecting encrypted government and enterprise communications with the intent to decrypt them once fault-tolerant quantum computers become available. The inclusion of federal contractors in the mandate is the most commercially significant provision. Once updated FAR rules take effect, any organization selling to the federal government will face PQC compliance requirements, extending the migration mandate well into the private sector supply chain.

For Security Leaders

The 90-day agency migration planning deadline is the most operationally consequential near-term requirement. Most federal agencies, and many enterprises that will follow this framework, lack a current cryptographic asset inventory, which is the prerequisite for any sequenced migration. Security leaders in regulated industries or federal supply chains should begin building that inventory now, ahead of regulatory deadlines. The NIST NCCoE PQC Migration Project provides publicly available migration guidance and reference architectures. For a broader view of credential and authentication security practices, see: Brute Force Attacks on Password Managers: Risks and Mitigation Strategies for CISOs.

Source: The White House