Skip to main content
Hero background

The Post-Quantum Executive Order

The transition to post-quantum cryptography (PQC) is becoming a growing priority for the U.S. government as organizations prepare for the potential impact of quantum computing on current encryption technologies. On June 22, 2026, the White House issued Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, outlining a federal approach to the transition. 

The order directs federal agencies to identify and prioritize high value assets (HVAs) and high impact systems for PQC migration, while setting deadlines for adopting post-quantum protections for key establishment and digital signatures. It also has implications for federal contractors through proposed changes to federal procurement requirements. For government agencies and organizations supporting federal missions, the order provides a clearer roadmap for understanding cryptographic risks, prioritizing systems, and preparing for the post-quantum transition. 

Why the Executive Order Matters

Public-key cryptography is behind many of the security tools government agencies and critical infrastructure rely on every day. RSA and elliptic-curve cryptography (ECC), for example, help secure: 

  • Key establishment 

  • Authentication 

  • Digital signatures 

  • Certificates and Public Key Infrastructure (PKI) 

  • Secure communications 

The challenge is that quantum computing could eventually weaken some of these protections. Even before that happens, sensitive information encrypted today could be collected and stored for future decryption as quantum capabilities advance. 

Executive Order 14412 gives federal agencies a clearer path for preparing for this risk, from identifying priority systems to assigning responsibility for PQC migration and planning the transition. For federal contractors, the impact will depend on how the proposed FAR rule is finalized. The proposed changes could bring new PQC-related requirements, making the federal procurement process an important development to watch. 

Post-Quantum Executive Order Requirements

Moving to post-quantum cryptography requires coordination across government agencies, cybersecurity and standards organizations, procurement authorities, and critical infrastructure stakeholders. The order assigns these groups roles in migration planning, technical guidance, federal procurement, and PQC preparation. 

Federal Agency Migration Requirements 

The order puts federal agencies on a clear timeline for getting started. Within 30 days, each agency must designate a PQC migration lead to oversee its cryptographic inventory, coordinate migration efforts, and develop a prioritized plan. 

Within 90 days, OMB must issue guidance directing agencies to review their high value assets (HVAs) and high impact systems, excluding National Security Systems. 

Agency migration planning must address: 

  • Existing cryptographic technologies and dependencies 

  • HVAs and high impact systems requiring priority assessment 

  • Key establishment mechanisms 

  • Digital signature mechanisms 

  • Migration priorities and implementation plans 

  • Alignment with applicable NIST standards and federal guidance 

The order establishes two primary federal migration deadlines: 

  • December 31, 2030 — Transition of HVAs and high impact systems to PQC for key establishment 

  • December 31, 2031 — Transition of HVAs and high impact systems to PQC for digital signatures 

NIST, CISA, and Federal Coordination 

The order brings several federal organizations together to support the transition to PQC. NIST, CISA, NSA, OMB, and the National Cyber Director each have roles in helping agencies plan the transition, understand the risks, and put the right safeguards in place. 

NIST, working with CISA and NSA, will provide guidance on implementing PQC and managing the risks that come with the transition. CISA and NIST will also develop guidance for a Cryptographic Bill of Materials (CBOM), giving organizations a clearer picture of the cryptography built into their hardware and software. 

A CBOM can help organizations keep track of things such as: 

  • Cryptographic algorithms 

  • Cryptographic libraries 

  • Certificates 

  • Protocols 

  • Hardware and software dependencies 

  • Cryptographic modules 

The order also calls for NIST to run a PQC migration pilot across a selected group of its information systems. The goal is to gain practical experience with the transition and use those lessons to help guide broader federal migration efforts. 

Federal Procurement Requirements 

The order also addresses federal contractors. Within 180 days, the FAR Council must publish a proposed rule that would require covered contractors to comply by December 31, 2030, with applicable NIST FIPS, including FIPS incorporating PQC-compliant algorithms. The order also calls for updates to contractor vulnerability disclosure requirements within 270 days. These updates would address reporting cryptographic vulnerabilities and identifying systems that lack encryption or use non-FIPS-approved algorithms. 

Post-Quantum Executive Order Implications

The practical impact of the order differs across federal agencies, contractors, and critical infrastructure organizations. 

Federal Agencies 

Federal agencies will need to establish clear ownership for PQC migration and develop a detailed understanding of the systems covered by the order. 

Key priorities include: 

  • Identifying HVAs and high impact systems 

  • Reviewing existing cryptographic inventories 

  • Identifying key establishment and digital signature mechanisms 

  • Developing migration plans 

  • Assessing technology and supplier dependencies 

  • Aligning migration activities with NIST standards and Federal guidance 

The migration process extends beyond individual algorithms. Agencies will need to understand how cryptography is integrated into applications, infrastructure, certificates, security modules, communications protocols, and other systems. 

Federal Contractors 

For federal contractors, the immediate priority is understanding the proposed changes to the federal procurement framework. 

Organizations supporting federal contracts should assess: 

  • Existing cryptographic algorithms and modules 

  • Dependencies on NIST FIPS 

  • Software and hardware supplied to federal customers 

  • Third-party cryptographic components 

  • Certificate and key management processes 

  • Vulnerability disclosure practices 

  • Technology roadmaps and planned product updates 

Monitoring the FAR rulemaking process will be important as the federal government moves from the direction established by the executive order toward enforceable procurement requirements. 

Critical Infrastructure Organizations 

Critical infrastructure organizations have a different path under the order. Rather than imposing the same federal migration deadlines, the order directs Sector Risk Management Agencies and CISA to assist owners and operators with PQC migration planning. 

Organizations can use this planning process to identify where cryptography supports: 

  • Essential services 

  • Operational technology 

  • Secure communications 

  • Identity and access systems 

  • Sensitive information 

  • Connected infrastructure 

Systems with long replacement cycles or complex technology dependencies may require particular attention because cryptographic changes can affect interoperability, availability, performance, and operational continuity. 

Preparing for the Post-Quantum Transition

The post-quantum transition is already becoming a planning priority for organizations supporting the federal government. Executive Order 14412 gives agencies a clearer timeline for getting started, while proposed procurement changes could bring new requirements for federal contractors. 

Agencies can begin by identifying priority systems and assigning migration ownership. Contractors can review their technology and supplier dependencies while following developments to the FAR rule. For both, having a clear picture of their current cryptographic environment can make the move to PQC more manageable when migration begins. 

Initial preparation can focus on: 

  • Establishing a current cryptographic inventory 

  • Identifying systems that rely on public-key cryptography 

  • Prioritizing HVAs and high impact systems 

  • Assessing supplier and technology dependencies 

  • Evaluating PQC and hybrid implementation options 

  • Planning for certificate and key management changes 

  • Tracking applicable federal standards and regulatory developments 

A clear view of the existing cryptographic environment gives organizations a stronger basis for prioritizing migration, managing operational dependencies, and preparing for federal requirements. 

BlackBerry for Secure Communications

For Environments Where Failure Isn’t an Option

BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.

Explore BlackBerry Secure Communications solutions