CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Trump Executive Order Sets 2030 Deadline for Federal Post-Quantum Cryptography Migration

June 25, 2026

President Trump signed Executive Order 14409 on June 22, 2026, establishing hard deadlines for federal agencies to migrate high-value assets and high-impact systems to post-quantum cryptography (PQC). Key establishment must be completed by December 31, 2030, and digital signatures by December 31, 2031. National security systems are on a separate track.

The order addresses the ‘harvest now, decrypt later’ threat, where adversaries collect encrypted data today to decrypt it once a large-scale quantum computer exists. It accelerates the previous government-wide target from 2035 (set by National Security Memorandum 10 in 2022) by four to five years, aligning with NIST standards finalized in August 2024: FIPS 203 (ML-KEM, formerly CRYSTALS-Kyber) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures.

Key deadlines include: within 30 days, each agency head must name a PQC migration lead; within 90 days, OMB issues guidance for agencies to review inventories of high-value assets and high-impact systems and submit migration plans; NIST must complete a pilot migration on its own systems by December 31, 2027. The Federal Acquisition Regulatory Council has 180 days to propose a rule requiring covered contractors to meet NIST FIPS by December 31, 2030, and 270 days to propose a rule folding cryptographic flaws into contractor vulnerability disclosure programs. CISA and NIST are to publish minimum elements for a cryptographic bill of materials within 270 days.

The order also includes a companion order, ‘Ushering in the Next Frontier of Quantum Innovation,’ to advance quantum computing development. The practical impact is that federal teams and vendors must begin cryptographic inventory immediately to meet the deadlines.

CVEs: CVE-2026-11645

Companies: CISA, NIST, OMB, FAR Council