%3Aquality(100)&w=3840&q=75)
The Post-Quantum Executive Order
The transition to post-quantum cryptography (PQC) is becoming a growing priority for the U.S. government as organizations prepare for the potential impact of quantum computing on current encryption technologies. On June 22, 2026, the White House issued Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, outlining a federal approach to the transition.
The order directs federal agencies to identify and prioritize high value assets (HVAs) and high impact systems for PQC migration, while setting deadlines for adopting post-quantum protections for key establishment and digital signatures. It also has implications for federal contractors through proposed changes to federal procurement requirements. For government agencies and organizations supporting federal missions, the order provides a clearer roadmap for understanding cryptographic risks, prioritizing systems, and preparing for the post-quantum transition.
Why the Executive Order Matters
Public-key cryptography is behind many of the security tools government agencies and critical infrastructure rely on every day. RSA and elliptic-curve cryptography (ECC), for example, help secure:
Key establishment
Authentication
Digital signatures
Certificates and Public Key Infrastructure (PKI)
Secure communications
The challenge is that quantum computing could eventually weaken some of these protections. Even before that happens, sensitive information encrypted today could be collected and stored for future decryption as quantum capabilities advance.
Executive Order 14412 gives federal agencies a clearer path for preparing for this risk, from identifying priority systems to assigning responsibility for PQC migration and planning the transition. For federal contractors, the impact will depend on how the proposed FAR rule is finalized. The proposed changes could bring new PQC-related requirements, making the federal procurement process an important development to watch.
Post-Quantum Executive Order Requirements
Moving to post-quantum cryptography requires coordination across government agencies, cybersecurity and standards organizations, procurement authorities, and critical infrastructure stakeholders. The order assigns these groups roles in migration planning, technical guidance, federal procurement, and PQC preparation.
Federal Agency Migration Requirements
The order puts federal agencies on a clear timeline for getting started. Within 30 days, each agency must designate a PQC migration lead to oversee its cryptographic inventory, coordinate migration efforts, and develop a prioritized plan.
Within 90 days, OMB must issue guidance directing agencies to review their high value assets (HVAs) and high impact systems, excluding National Security Systems.
Agency migration planning must address:
Existing cryptographic technologies and dependencies
HVAs and high impact systems requiring priority assessment
Key establishment mechanisms
Digital signature mechanisms
Migration priorities and implementation plans
Alignment with applicable NIST standards and federal guidance
The order establishes two primary federal migration deadlines:
December 31, 2030 — Transition of HVAs and high impact systems to PQC for key establishment
December 31, 2031 — Transition of HVAs and high impact systems to PQC for digital signatures
NIST, CISA, and Federal Coordination
The order brings several federal organizations together to support the transition to PQC. NIST, CISA, NSA, OMB, and the National Cyber Director each have roles in helping agencies plan the transition, understand the risks, and put the right safeguards in place.
NIST, working with CISA and NSA, will provide guidance on implementing PQC and managing the risks that come with the transition. CISA and NIST will also develop guidance for a Cryptographic Bill of Materials (CBOM), giving organizations a clearer picture of the cryptography built into their hardware and software.
A CBOM can help organizations keep track of things such as:
Cryptographic algorithms
Cryptographic libraries
Certificates
Protocols
Hardware and software dependencies
Cryptographic modules
The order also calls for NIST to run a PQC migration pilot across a selected group of its information systems. The goal is to gain practical experience with the transition and use those lessons to help guide broader federal migration efforts.
Federal Procurement Requirements
The order also addresses federal contractors. Within 180 days, the FAR Council must publish a proposed rule that would require covered contractors to comply by December 31, 2030, with applicable NIST FIPS, including FIPS incorporating PQC-compliant algorithms. The order also calls for updates to contractor vulnerability disclosure requirements within 270 days. These updates would address reporting cryptographic vulnerabilities and identifying systems that lack encryption or use non-FIPS-approved algorithms.
Post-Quantum Executive Order Implications
The practical impact of the order differs across federal agencies, contractors, and critical infrastructure organizations.
Federal Agencies
Federal agencies will need to establish clear ownership for PQC migration and develop a detailed understanding of the systems covered by the order.
Key priorities include:
Identifying HVAs and high impact systems
Reviewing existing cryptographic inventories
Identifying key establishment and digital signature mechanisms
Developing migration plans
Assessing technology and supplier dependencies
Aligning migration activities with NIST standards and Federal guidance
The migration process extends beyond individual algorithms. Agencies will need to understand how cryptography is integrated into applications, infrastructure, certificates, security modules, communications protocols, and other systems.
Federal Contractors
For federal contractors, the immediate priority is understanding the proposed changes to the federal procurement framework.
Organizations supporting federal contracts should assess:
Existing cryptographic algorithms and modules
Dependencies on NIST FIPS
Software and hardware supplied to federal customers
Third-party cryptographic components
Certificate and key management processes
Vulnerability disclosure practices
Technology roadmaps and planned product updates
Monitoring the FAR rulemaking process will be important as the federal government moves from the direction established by the executive order toward enforceable procurement requirements.
Critical Infrastructure Organizations
Critical infrastructure organizations have a different path under the order. Rather than imposing the same federal migration deadlines, the order directs Sector Risk Management Agencies and CISA to assist owners and operators with PQC migration planning.
Organizations can use this planning process to identify where cryptography supports:
Essential services
Operational technology
Secure communications
Identity and access systems
Sensitive information
Connected infrastructure
Systems with long replacement cycles or complex technology dependencies may require particular attention because cryptographic changes can affect interoperability, availability, performance, and operational continuity.
Preparing for the Post-Quantum Transition
The post-quantum transition is already becoming a planning priority for organizations supporting the federal government. Executive Order 14412 gives agencies a clearer timeline for getting started, while proposed procurement changes could bring new requirements for federal contractors.
Agencies can begin by identifying priority systems and assigning migration ownership. Contractors can review their technology and supplier dependencies while following developments to the FAR rule. For both, having a clear picture of their current cryptographic environment can make the move to PQC more manageable when migration begins.
Initial preparation can focus on:
Establishing a current cryptographic inventory
Identifying systems that rely on public-key cryptography
Prioritizing HVAs and high impact systems
Assessing supplier and technology dependencies
Evaluating PQC and hybrid implementation options
Planning for certificate and key management changes
Tracking applicable federal standards and regulatory developments
A clear view of the existing cryptographic environment gives organizations a stronger basis for prioritizing migration, managing operational dependencies, and preparing for federal requirements.
%3Aquality(100)&w=3840&q=75)
BlackBerry for Secure Communications
For Environments Where Failure Isn’t an Option
BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.
Explore BlackBerry Secure Communications solutions