GSA Publishes a Post-Quantum Cryptography Buyer’s Guide for Federal Agencies
June 12, 2025 — The U.S. General Services Administration (GSA) has released version 1 of its Post-Quantum Cryptography Buyer’s Guide, providing federal agencies with a comprehensive roadmap for procuring quantum-resistant security solutions. The 33-page document details specific contract vehicles, use cases, and implementation strategies for agencies facing mandated cryptographic transitions.
The guide arrives as agencies scramble to meet annual inventory requirements under NSM-10 and prepare for NIST’s projected 10-to-20-year migration timeline. GSA’s Office of Information Technology Category structured the document around four core implementation phases: inventory of critical systems, assessment of current environments, transition planning, and ongoing maintenance.
The guide maps PQC purchases onto existing GSA contract vehicles, including 8(a) STARS III, Alliant 2, VETS 2, Enterprise Infrastructure Solutions (EIS), and the Highly Adaptive Cybersecurity Services (HACS) SIN. The guide emphasizes managed service options and “as-a-service” models to address the acute shortage of quantum security expertise across government.
GSA highlighted five specific use cases: Automated Cryptography Discovery and Inventory (ACDI) tools, PQC planning and implementation services, Quantum Security-as-a-Service (QSaaS), Quantum SD-WAN deployments, and integrated PQC-Zero Trust Architecture solutions. Each use case includes operational benefits, security advantages, and applicable GSA contract options.
The document confirms that no current ACDI tools capture all nine data elements required for annual ONCD and CISA reporting. Agencies must continue manual inventory processes while CISA develops standards for integrating automated discovery tools into its Continuous Diagnostics and Mitigation (CDM) program.
My Analysis
Finally. After two years of agencies flailing around trying to figure out how to actually buy PQC solutions, GSA steps up with real procurement guidance. This document matters because it transforms vague mandates into actionable contract vehicles.
The timing couldn’t be better. Agencies have annual inventory submissions due every May 4th. NIST’s standards dropped in August 2024. Yet until now, acquisition officers had no clear path from requirement to contract.
What strikes me most about this guide? GSA openly admits the talent crisis. They’re pushing managed services and “as-a-service” models hard. Translation: the government knows it can’t hire enough quantum security experts. Smart move. Why compete with Google and IBM for the handful of people who understand lattice-based cryptography when you can rent their expertise?
The ACDI Reality Check
Here’s the buried lede: those Automated Cryptography Discovery and Inventory tools everyone’s banking on? None of them yet meets the federal reporting requirement. GSA admits “there are no known ACDI tools that can capture all nine of the required data items.”
This creates a brutal catch-22. Agencies need comprehensive cryptographic inventories to plan their migrations. Manual inventories take forever and miss embedded crypto. Automated tools would solve this, but none yet covers the full reporting set. Meanwhile, the annual reporting deadlines keep coming.
I’ve seen this movie before. Remember when everyone needed continuous monitoring but the tools weren’t enterprise-ready? We’re about to watch history repeat itself, except this time with quantum implications.
Why QSaaS Makes Sense
The guide’s emphasis on Quantum Security-as-a-Service reflects ground truth. Most federal IT shops struggle to maintain current encryption standards. Now we’re asking them to implement ML-KEM, ML-DSA, and SLH-DSA while maintaining crypto-agility for future algorithm changes?
QSaaS flips the model. Instead of training your workforce on lattice mathematics, you subscribe to quantum-safe encryption. The vendor handles algorithm updates, compliance reporting, and that nasty hybrid transition period where you’re running classical and quantum-resistant crypto simultaneously.
GSA’s contract vehicles already support this model through EIS and cloud services SINs. Agencies can start pilots now without waiting for dedicated quantum contracts.
The Zero Trust Convergence
Smartest insight in the guide? The section on PQC-Zero Trust convergence. GSA recognizes these aren’t separate initiatives. Both require identity-based security, continuous monitoring, and crypto-agility. Both demand architectural overhauls.
Agencies implementing Zero Trust are already rearchitecting their networks. Adding PQC to that transformation costs far less than running separate projects. Shared expertise, shared contracts, shared disruption windows.
The guide even provides a comparison table showing how Zero Trust principles align with crypto-agility requirements. “Presume breach” in Zero Trust maps to “encrypt sensitive data.” “Verify explicitly” requires controlling cryptographic validation. Every Zero Trust tenet has a PQC parallel.
What’s Missing
For all its strengths, the guide sidesteps critical timeline questions. NIST projects 10-20 years for full migration. My Q-Day analysis suggests we might see cryptographically relevant quantum computers in the 2030s. That’s a narrow window.
The guide also glosses over interoperability nightmares. Federal systems don’t operate in isolation. They connect to state systems, contractor networks, international partners. How do you maintain quantum-safe communications when half your ecosystem runs deprecated algorithms?
Cost remains the elephant in the room. GSA mentions “assess funding required” but provides no benchmarks. From my discussions with agencies already piloting PQC, budget requests range from millions to tens of millions depending on system complexity.
The Path Forward
Despite these gaps, GSA deserves credit for creating the first practical procurement framework for PQC. This guide transforms abstract NIST standards into concrete acquisition strategies.
For CISOs and acquisition officers, the message is clear: stop waiting for perfect solutions. Use existing contract vehicles. Start with managed services. Build crypto-agility into every IT modernization project.
The guide’s real value? It gives bureaucrats cover. When leadership questions why you’re spending millions on “theoretical” quantum threats, you point to GSA’s official guidance. When procurement asks which contract vehicle to use, you reference Appendix A. When skeptics claim PQC is premature, you cite the annual inventory mandates.
Most importantly, this guide signals market maturity. GSA doesn’t create buying guides for vaporware. Their involvement means real solutions exist, contracts are in place, and agencies are already buying.
We’re past the “if” stage of post-quantum cryptography. GSA’s buyer’s guide moves us firmly into “how.” For federal agencies still treating quantum threats as science fiction, this document serves as a wake-up call. The procurement framework exists. The contracts are ready. The only question now: will agencies move fast enough?