Quantum Security & PQC

Trump Signs PQC Executive Order 14412 with Hard 2030 and 2031 Deadlines for Federal Migration

Updated: September 2026

June 22, 2026 — President Trump signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” setting the first dated federal deadlines for moving government information systems to post-quantum cryptography. Every federal high-value asset and high-impact system must use PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031. Federal contractors face a 31 December 2030 compliance date through a Federal Acquisition Regulation amendment that the order requires only as a proposed rule, due 19 December 2026.

The order was published in the Federal Register on 25 June 2026 at 91 FR 38483, document number 2026-12909. (Day-one coverage widely reported the number as EO 14409, which was already taken). The companion quantum innovation order signed the same day is EO 14413.

Which date applies to you depends on how your systems are classified. If you hold federal high-value asset data, operate a FIPS 199 high-impact system, or sell to an organization that does, the operative year is 2030. For every other federal civilian system, OMB Memorandum M-26-15 keeps 2035.

Section 1 of the order states that ongoing cyber activity “presents the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational.” The order never uses the phrase, but that is Harvest Now, Decrypt Later, named as a present-day risk in the preamble of a presidential directive.

The News

The order’s own clocks, plus the plan deadline its implementing memorandum added:

DateRequirementAuthority
22 July 2026Each agency names a PQC migration leadEO §4(a)
20 September 2026OMB issues agency guidanceEO §4(b), met on 24 June
22 October 2026Agency PQC migration plans due to OMB and ONCDM-26-15
19 December 2026CMVP revision; contractor FAR proposed rule; first NSA report through CNSSEO §§6(b), 6(c), 5(c)
19 March 2027CBOM minimum elements; vulnerability-disclosure FAR proposed ruleEO §§5(d), 6(d)
31 December 2027NIST internal migration pilot completeEO §4(c)
31 December 2030Key establishment on HVAs and high-impact systems; contractor FIPS complianceEO §§4(b)(ii), 6(c)
31 December 2031Digital signatures on those systemsEO §4(b)(iii)
2035Remaining civilian systemsM-26-15 Phase 5

Definitions (Section 2). “High impact system” means a system rated high under FIPS 199 for confidentiality, integrity or availability. “High value asset” means anything designated as one under OMB M-19-03 or a successor. “Key establishment” takes its meaning from FIPS 203, the ML-KEM standard. “Digital signature” takes its meaning from FIPS 186-5, the existing Digital Signature Standard. A “PQC migration lead” is the employee or detailee who reports to the agency chief information officer and owns three duties: cryptographic inventory management across the organization, coordination with other agencies, and a prioritized migration plan.

Coordination (Section 3). The Director of OMB and the National Cyber Director lead strategic coordination and oversight, in consultation with the Assistant to the President for National Security Affairs and the Administrator of the Office of Electronic Government. Commerce, through NIST and in consultation with NSA and CISA, provides agencies with ongoing technical guidance on implementation and risk management.

Deadlines (Section 4). Within 30 days, each agency head had to identify a PQC migration lead and send the name and contact details to OMB and the National Cyber Director. Within 90 days, the Director of OMB had to issue guidance, consistent with 6 U.S.C. 1526(c), requiring each agency to review its inventory of high-value assets and high-impact systems excluding National Security Systems, transition those systems to PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031, and submit a plan to OMB and the National Cyber Director. Within 180 days, NIST must start a PQC migration pilot on a subset of its own systems, to finish no later than 31 December 2027.

Critical infrastructure and international (Section 5). Sector Risk Management Agencies, as defined by National Security Memorandum 22 of 30 April 2024, must work with CISA to help critical infrastructure owners and operators build their own migration plans. The Secretary of State, working with NIST, DHS, the National Cyber Director, the Secretary of War and the Director of National Intelligence, must identify and engage foreign governments and industry groups in key countries to encourage adoption of NIST-standardized PQC. Within 180 days and annually until migration is complete, the Director of NSA, in the role of National Manager for NSS, must report to the President through the Committee on National Security Systems on migration status. Within 270 days, DHS through CISA, coordinating with NIST, must publish guidance on the minimum elements for a cryptographic bill of materials that enable automated assessment of the cryptographic assets in a hardware or software element.

Procurement (Section 6). OMB, the Secretary of War, the NASA and GSA Administrators, consulting DHS, the DNI and NIST, must coordinate to identify cost-saving opportunities, including migration of cloud-based technologies, shared procurement of PQC tools, joint training programs and centralized technical support. Within 180 days, NIST must revise Cryptographic Module Validation Program processes to accelerate validations of cryptographic modules. Within 180 days, the FAR Council must publish a proposed rule requiring covered contractors to comply by 31 December 2030 with NIST FIPS, including all applicable FIPS incorporating PQC compliant algorithms. Within 270 days, the FAR Council must publish a second proposed rule requiring covered contractors to run vulnerability disclosure policies that accept reports of cryptographic vulnerabilities, including testing for lack of encryption and the use of non-FIPS approved algorithms.

General provisions (Section 7). Implementation is subject to the availability of appropriations. The order creates no right or benefit enforceable at law or in equity against the United States.

My Analysis

What EO 14412 Requires

Under EO 14412, each federal agency must find every system that qualifies as a high-value asset or rates high under FIPS 199, and switch each one to post-quantum algorithms for encrypted connections (key establishment) by the end of 2030 and for digital signatures by the end of 2031. Key establishment protects data travelling over a network. Digital signatures prove that software, certificates and documents have not been altered. The order sets the key-establishment deadline first because adversaries can collect encrypted traffic today and try to decrypt it later with a quantum computer. Attackers with a quantum computer could also forge signatures, but signature migration involves deeper dependencies on certificate chains and public-key infrastructure, which is why the order gives agencies an extra year for it.

National Security Systems are excluded from this order. NSA’s CNSA 2.0 governs them, with its own staggered dates running to 2033.

The order does not appropriate money. Section 7(b) makes every obligation subject to available appropriations. It does not revoke any earlier directive; NSM-10, M-23-02 and the Quantum Computing Cybersecurity Preparedness Act all remain in force. And Section 7(c) states that the order creates no enforceable right or benefit, meaning nobody can sue an agency for missing the deadline. OMB oversight and the budget process are the enforcement mechanism.

The one provision that will become legally binding on private companies is the FAR rule. Section 6(c) tells the FAR Council to publish a proposed rule by 19 December 2026 that would require covered contractors to meet PQC-incorporating FIPS by 31 December 2030. Once finalized and written into a contract, a FAR clause is a contract term, and a contractor can be held to it. Everything else in the order is direction to the executive branch.

The Signed Order Keeps the Leaked Draft’s Dates

On 24 May 2026 I published Post-Quantum Deadlines Likely to Compress Further, working from the leaked draft Nextgov/FCW reported on 20 May. I wrote then that the draft described 2030 and 2031 deadlines and contractor compliance requirements, and that the dates were compressing.

The signed text matches the leak on the points the public reporting actually described. The split between key establishment in 2030 and digital signatures in 2031 is in both. So are the contractor obligation, the scope limited to high-value assets and high-impact systems, and the carve-out for National Security Systems. The CBOM mandate and the CMVP acceleration provision do not appear in Nextgov’s published account of the draft, so I make no claim about those two.

I also listed four thresholds that would move my assessment. The first was that a signed order with the 2030/2031 dates intact would reshape vendor roadmaps within twelve months and justify pulling internal targets forward by a year. That threshold was crossed on 22 June.

That May piece flagged something else that arrives soon: the FIPS 140-2 sunset on 21 September 2026.

Who Counts as a Covered Contractor Is Still Undecided

The order does not define “covered contractor.” That definition will come in the proposed rule, and it will determine how far down the supply chain the obligation reaches. Prime contractors will flow the clause to their subcontractors; whether it extends to component suppliers and non-U.S. vendors selling into U.S. public procurement depends on the drafting. Watch regulations.gov and comment when the rule publishes, because the scope question is decided there. The rule was still unpublished on 20 September 2026.

Just over four years is a short time for a vendor that has not started. Before a federal agency can buy a product, the product must use a PQC algorithm. The cryptographic module inside it must have been tested and certified through NIST’s Cryptographic Module Validation Program. And the version the customer runs must match the certified version. Those three steps happen one after another, and the certification step is where the timeline tends to compress.

NIST Module Validation Is the Bottleneck

Federal agencies are required to use cryptographic modules that NIST has validated. Without a validation certificate, an agency cannot buy the product. That requirement predates the quantum transition and applies to every cryptographic product the government buys. EO 14412 keeps that requirement and adds a condition: the validated modules must now contain post-quantum algorithms.

NIST runs the Cryptographic Module Validation Program jointly with the Canadian Centre for Cyber Security. A vendor submits its module to an accredited laboratory, the laboratory tests it, and NIST reviews the results and issues a certificate. The certificate names the specific algorithms, the specific software version and the specific security level. A product running a different version, or using an algorithm the certificate does not cover, is not validated.

Section 6(b) of the order tells NIST to revise this process to speed it up, by 19 December 2026. NIST owes that revision three months after a separate event it scheduled years ago: the retirement of FIPS 140-2.

On 21 September 2026, every remaining FIPS 140-2 certificate moves to the CMVP Historical list. The modules keep working in existing systems. But federal agencies are told not to specify Historical modules in new procurements, so a vendor whose only certificate is FIPS 140-2 has nothing current to show a contracting officer. I flagged this collision in May, before the order existed. The order has since added a second source of demand to the same queue: every agency now needs PQC-incorporating modules certified under FIPS 140-3, and every vendor selling to those agencies needs to get its PQC implementation through validation.

The last public throughput numbers are a few months old. In January 2026, David Hawes, who manages the CMVP at NIST’s computer security division, told the Information Security and Privacy Advisory Board that NIST’s last thirty cryptographic validations took an average of 348 days each, and that the queue backlog had come down from nearly two years in 2020 to roughly six months. The stated goal is days. Vendors measure the full cycle from laboratory submission through NIST certification, not just the NIST review, and their published estimates run to eighteen months and up. Both figures describe real time, but they cover different spans of the same process.

I corrected my own number here. I had been citing eighteen months as the validation time and presenting it as though it described NIST’s throughput. It does not. NIST’s own figures are better than the ones I was using, and the trend was improving before the order existed.

At the same January meeting, Kevin Stine, who directs NIST’s Information Technology Laboratory, said NIST had shed more than 700 positions since January 2025. He put his own laboratory’s losses at about 89 people over the previous year, against a remaining headcount of 289. The pending appropriations package, he said, would cut $13 million from the labs programme. Hawes said the queue improvement happened in spite of those losses.

The retirement of FIPS 140-2 pushes a cohort of vendors toward FIPS 140-3 submission at once. The executive order tells every federal buyer to demand PQC-incorporating FIPS by 2030. Both pressures converge on one programme that is smaller than it was and owes a redesign of its own processes by December.

Anyone can query the CMVP database and count how many active FIPS 140-3 certificates name an ML-KEM or ML-DSA implementation. That count is the single clearest indicator of whether the 2030 date is reachable. Hawes said in January that NIST had tested its first post-quantum module in the preceding weeks. Through 2026 the PQC modules have been queued, not certified. CIQ’s NSS module for Rocky Linux earned CAVP algorithm certification for ML-KEM and ML-DSA and entered the Modules in Process list in February. SafeLogic’s CryptoComply provider joined the CMVP queue in May, expecting validation before the end of the year. Modules in Process status records a queue position, not a validation result. If that queue does not start producing certificates, agencies will miss 2030 for reasons unrelated to their own effort.

The Order Never Names a Post-Quantum Signature Algorithm

Section 2 defines “key establishment” by reference to FIPS 203, the ML-KEM standard. It defines “digital signature” by reference to FIPS 186-5, the classical Digital Signature Standard that specifies ECDSA, EdDSA and RSA. FIPS 204 and FIPS 205 appear nowhere in the order, and neither does ML-KEM, ML-DSA or SLH-DSA by name.

Section 4(b)(iii) still requires the transition to PQC for signatures, so the obligation is unambiguous. The drafting avoids freezing a list of algorithm names into the legal instrument. By pointing at categories and at “all applicable FIPS incorporating PQC compliant algorithms” in Section 6(c), the order stays valid when NIST adds FN-DSA or HQC and when parameter guidance changes. That is crypto-agility in the legal text, with M-26-15 and NIST guidance handling the algorithm-selection detail.

M-26-15 supplies the algorithms in its Appendix A: ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) for signatures, and SLH-DSA (FIPS 205) as a hash-based fallback, with FALCON and HQC named as candidates to follow. The memo also carries the order’s definitional quirk forward. Its footnote on the signature migration phase still points readers to FIPS 186-5 for what a digital signature is, four pages after its own appendix names ML-DSA as the algorithm to use. Agencies take their dates from the order and their algorithms from the memo’s appendix.

Agency Plans Are Due Five Months Before the CBOM Guidance

Agency migration plans are due to OMB and the National Cyber Director on 22 October 2026, under M-26-15’s 120-day clock. DHS, through CISA and coordinating with NIST, has until 19 March 2027 to publish minimum-element guidance for a cryptographic bill of materials.

Agencies are not writing their plans from nothing. M-23-02 already required them to inventory their cryptographic dependencies, including algorithm types, key lengths, vendor information and data protection periods. M-26-15 goes further: its Appendix A tells agencies to build an automated cryptographic inventory using software composition analysis against SBOMs, static and dynamic application security testing, and network scanners, and to have that data “populate a central Cryptographic Bill of Materials.”

So agencies must build the artefact five months before the federal government defines exactly what it should contain. Some will use CycloneDX, which already supports CBOM representations. Some will use whatever their discovery vendor produces. When the March 2027 guidance arrives, it will meet inventories built to different schemas. If you are building a cryptographic inventory now, federal or not, recording the fields CycloneDX already defines reduces the alignment work later.

Deadlines Without New Money

Section 6(a) directs OMB, the Secretary of War, NASA and GSA to coordinate on cost savings: cloud migration, shared procurement of PQC tools, joint training, centralized technical support. Section 7(b) makes the entire order subject to the availability of appropriations.

No agency receives new money for PQC migration under this instrument. Shared procurement and centralized support will help smaller agencies that cannot staff a cryptography programme. Neither pays for the hardware security modules, the certificate lifecycle rebuild or the vendor contract renegotiations that a high-value asset migration requires.

M-26-15 is more candid about where the money comes from. Its Appendix B requires each agency’s plan to contain “an estimate of funding and personnel resources required,” and it assigns the agency Chief Financial Officer responsibility for making sure those requirements appear in the annual budget request. So the funding mechanism is the ordinary appropriations cycle, one fiscal year at a time, against deadlines fixed to 2030 and 2031.

The deadlines are dated. The funding is annual and conditional. When those diverge, agencies report progress on paper and record the shortfall as accepted risk. The October plans will contain a resource estimate because the memo requires one. The FY2028 budget request is where to check whether those estimates were funded.

The Implementation Record, June to September 2026

(Updated in Sep 2026)

The administration published its implementing documents faster than the order required.

  • 12 June 2026, before the order. National Security Presidential Memorandum 12 rescinded NSD-42 of 1990 and NSM-8 of 2022. It re-established the Committee on National Security Systems with binding directive authority over all NSS and named the head of NSA as National Manager. EO 14412’s Section 5(c) requires the NSA to report through that committee, so NSPM-12 built the governance structure the order’s reporting requirement depends on.
  • 22 June. EO 14412 signed.
  • 23 June. The Department of War published its PQC Strategy, requiring DoW systems to support PQC or be phased out by the end of 2030, and to use PQC by the end of 2031 “unless otherwise noted,” with the intent to extend requirements across the defense industrial base. Those two qualifiers do more work than the headline dates, which I covered separately.
  • 24 June. OMB issued Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” signed by Director Russell T. Vought. It established a five-phase migration timeline running 2026–2035 and set the 120-day plan deadline. The order allowed ninety days for this guidance. OMB delivered on day two, 88 days early. The speed suggests OMB drafted the memo alongside the order.
  • 22 July. Thirty-day deadline for agencies to name PQC migration leads. No public roster or count of designated leads has been released by OMB or the Office of the National Cyber Director, so compliance with this deadline is not externally visible.
  • 20 September. The order’s ninety-day OMB guidance deadline, already satisfied.
  • Still ahead. 22 October 2026, agency migration plans. 19 December 2026, the CMVP revision, the contractor FAR proposed rule, and NSA’s first NSS report through CNSS. 19 March 2027, the CBOM minimum elements and the vulnerability-disclosure FAR rule. 31 December 2027, completion of NIST’s internal pilot.

Three months in, OMB and the Department of War have delivered the documents they owed, and NSPM-12 put the NSS governance structure in place before the order was signed. Every remaining deliverable requires rulemaking, validation throughput or appropriated money. Those are harder, and that is where federal programmes usually slip.

Allied Governments and Cloud Providers Set the Same Window

On 3 September 2026 the G7 Cybersecurity Working Group, led by France’s ANSSI under the French G7 presidency, published Preparing for the Post-Quantum Era: A Call to Action, co-issued by the cybersecurity agencies of all seven member states with the European Commission and ENISA as guests. The working group told organizations to treat the quantum threat as a business and economic risk first and a cryptographic one second, and warned that organizations that delay “may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.” I covered that document and its procurement signal in detail.

EO 14412 turns PQC compliance into a condition of selling to the U.S. federal government by 2030. ANSSI has already said it will stop certifying security products without PQC from 2027, and French government and critical infrastructure buyers require ANSSI certification. The EU, Canada, Australia and India are each setting their own migration clocks in the same 2028–2031 range. For a multinational, the binding date is the earliest one in any jurisdiction you operate in, not the most permissive.

Private companies are converging on the same window. Cloudflare pulled its own full-PQC target forward to 2029 in April 2026. Google set 2029 for itself in March. Google Cloud then published dated commitments with signatures trailing confidentiality by a year, the same key-establishment-first sequencing the order uses. When the largest infrastructure providers and the largest buyer adopt the same order of operations, that sequencing is settled.

Is Your Deadline 2030 or 2035?

NIST IR 8547 remains an Initial Public Draft. Its 2030 deprecation and 2035 disallowance dates are proposals, and anyone presenting them as settled policy is overstating them. EO 14412 changed the status of the earlier date for a specific population: for federal high-value assets and high-impact systems, and for the contractors that serve them, 2030 is now a compliance date and no longer a NIST proposal. M-26-15 keeps 2035 for the remaining federal civilian systems and requires agency plans to align with IR 8547 in the meantime.

So the answer depends on classification. If you hold federal HVA data or operate a high-impact system, or you sell to someone who does, plan to 2030. If neither applies, 2035 remains defensible, and the earliest binding date in your own sector or jurisdiction still governs.

Either way the immediate work is unchanged and now has less slack in it. Complete a cryptographic inventory, recording the fields CycloneDX already defines. At the next vendor contract renewal, require named delivery dates for PQC support. Separate the key-establishment and signature tracks in your programme plan: their risk profiles, dependencies and completion dates all differ. That separation is how I structured the PQC Migration Framework, and the federal calendar now uses the same split. And check whether the cryptographic modules your critical systems depend on hold an active FIPS 140-3 certificate, because from 21 September a FIPS 140-2 certificate is a historical document.

Arguing about when Q-Day arrives no longer changes what anyone has to do this year. A dated federal order, a memo with a five-phase schedule, a defense strategy and a G7 call to action all published within ten weeks of each other. Boards fund obligations, and for the systems EO 14412 covers, those now have dates on them.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.