Post-Quantum Cryptography Migration Executive Order Issued

On June 22, 2026, the White House released an Executive Order for Securing the Nation Against Advanced Cryptographic Attacks.

(Note, this Executive Order was initially given EO #14409, but is now listed as EO #14412.)

The EO sets a path for migration and integration of Post-Quantum Cryptography for government agencies over the next 5 years.

See the end of this post for a more detailed look at each action included in the Executive Order.

KeyPair’s takeaways for the FIPS industry:

  1. The directive places clear pressure on the CMVP to continue process improvements, accelerate validations, and reduce queue times. We expect this mandate to drive NIST to provide the CMVP with the resources needed to expand automation, streamline reviews, and materially improve validation throughput.
  2. Modules in the CMVP queue with PQC algorithms tested are ahead of the curve. Agency Leads in charge of the migration will look to these modules first in their procurement and migration process.

Next steps for technology vendors: Solidify your PQC roadmap and ensure it includes a FIPS Validated module by developing your own or using a FIPS Inside approach.

Source: https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/

MilestoneDateWithin DaysResponsible PartyDeliverable
Order IssuedJune 22, 2026PresidentExecutive Order (EO # 14412)
Identify PQC Migration LeadsJuly 22, 202630Each Agency HeadNames and contact details to OMB
Issue PQC Transition GuidanceSeptember 20, 202690OMB Director (with CISA, National Cyber Director)Agency-wide PQC migration requirements and plans
Initiate NIST Pilot ProjectDecember 19, 2026180NIST DirectorPQC migration pilot on NIST systems
NSA NSS Status Report (Initial)December 19, 2026180NSA National Manager for NSSStatus report on National Security Systems PQC migration
NIST CMVP Process RevisionDecember 19, 2026180NIST DirectorAccelerated cryptographic module validation processes
FAR Council Contractor Rule (Proposed)December 19, 2026180FAR CouncilProposed FAR rule requiring PQC compliance by Dec 31, 2030
DHS Cryptographic Bill of MaterialsMarch 19, 2027270DHS through CISA DirectorPublic guidance on CBOM minimum elements
FAR Council VDP Rule (Proposed)March 19, 2027270FAR CouncilProposed FAR rule on contractor vulnerability disclosure programs
NIST Pilot CompletionDecember 31, 2027NIST DirectorCompleted PQC migration on selected subset of NIST systems
NSA NSS Status Reports (Annual)Annually from Dec 19, 2026NSA National Manager for NSSAnnual PQC migration status reports
Key Establishment for HVA/High Impact SystemsDecember 31, 2030All Federal AgenciesComplete transition to PQC for key establishment
Digital Signatures for HVA/High Impact SystemsDecember 31, 2031All Federal AgenciesComplete transition to PQC for digital signatures