On June 22, 2026, the White House released an Executive Order for Securing the Nation Against Advanced Cryptographic Attacks.
(Note, this Executive Order was initially given EO #14409, but is now listed as EO #14412.)
The EO sets a path for migration and integration of Post-Quantum Cryptography for government agencies over the next 5 years.

See the end of this post for a more detailed look at each action included in the Executive Order.
KeyPair’s takeaways for the FIPS industry:
- The directive places clear pressure on the CMVP to continue process improvements, accelerate validations, and reduce queue times. We expect this mandate to drive NIST to provide the CMVP with the resources needed to expand automation, streamline reviews, and materially improve validation throughput.
- Modules in the CMVP queue with PQC algorithms tested are ahead of the curve. Agency Leads in charge of the migration will look to these modules first in their procurement and migration process.
Next steps for technology vendors: Solidify your PQC roadmap and ensure it includes a FIPS Validated module by developing your own or using a FIPS Inside approach.
| Milestone | Date | Within Days | Responsible Party | Deliverable |
|---|---|---|---|---|
| Order Issued | June 22, 2026 | — | President | Executive Order (EO # 14412) |
| Identify PQC Migration Leads | July 22, 2026 | 30 | Each Agency Head | Names and contact details to OMB |
| Issue PQC Transition Guidance | September 20, 2026 | 90 | OMB Director (with CISA, National Cyber Director) | Agency-wide PQC migration requirements and plans |
| Initiate NIST Pilot Project | December 19, 2026 | 180 | NIST Director | PQC migration pilot on NIST systems |
| NSA NSS Status Report (Initial) | December 19, 2026 | 180 | NSA National Manager for NSS | Status report on National Security Systems PQC migration |
| NIST CMVP Process Revision | December 19, 2026 | 180 | NIST Director | Accelerated cryptographic module validation processes |
| FAR Council Contractor Rule (Proposed) | December 19, 2026 | 180 | FAR Council | Proposed FAR rule requiring PQC compliance by Dec 31, 2030 |
| DHS Cryptographic Bill of Materials | March 19, 2027 | 270 | DHS through CISA Director | Public guidance on CBOM minimum elements |
| FAR Council VDP Rule (Proposed) | March 19, 2027 | 270 | FAR Council | Proposed FAR rule on contractor vulnerability disclosure programs |
| NIST Pilot Completion | December 31, 2027 | — | NIST Director | Completed PQC migration on selected subset of NIST systems |
| NSA NSS Status Reports (Annual) | Annually from Dec 19, 2026 | — | NSA National Manager for NSS | Annual PQC migration status reports |
| Key Establishment for HVA/High Impact Systems | December 31, 2030 | — | All Federal Agencies | Complete transition to PQC for key establishment |
| Digital Signatures for HVA/High Impact Systems | December 31, 2031 | — | All Federal Agencies | Complete transition to PQC for digital signatures |
