Cybersecurity Policy Report, Federal Agencies Ordered to Submit Quantum Encryption Migration Plans Within 120 Days, (Jun 26, 2026)
Federal agencies will be required to submit plans for their adoption of encryption tools that can withstand a quantum-enabled cyber attack within 120 days under a directive issued yesterday by the White House Office of Management and Budget (OMB).
The OMB memorandum follows up on an executive order signed by President Trump on Monday that accelerates the timeline for federal agencies’ adoption of post-quantum cryptography (PQC). The previous deadline of 2035, set by the Biden administration, was moved to 2030 for higher-value systems (CPR, June 23).
“Agencies must execute a prioritized migration of cryptographic systems used in information systems that they own or operate with the objective of mitigating as much quantum risk as feasible by December 31, 2030,” OMB said.
“For decades, strong cryptography has enabled the United States Government to protect Federal information, securely deliver critical services to the American people, and guard against cyber-enabled fraud,” it noted.
“A quantum computer of sufficient power and sophistication (a cryptographically relevant quantum computer, or CRQC) will be able to decrypt data protected by many forms of cryptography that are commonly used today and thwart existing authentication protocols. After defeating such protections, a CRQC could take control of or impersonate devices, systems, and people,” it explained.
“A CRQC is not yet known to exist, but steady advancements in the quantum computing field may yield a CRQC in the coming decade,” OMB added.
The memo describes the three PQC standards already approved by the National Institute of Standards and Technology and their pros and cons. NIST is testing another nine standards (CPR, May 15).
OMB also offered agencies some tips to prioritize their migration, recommending that PQC should first be implemented on “high-impact systems” and “high-value assets,” as defined in previous OMB guidance. Agencies should start by inventorying their encrypted systems, conducting early pilots, and refining their migration strategies based on “lessons learned” from those pilots, OMB said.
To ensure that their cloud service providers implement PQC on the accelerated timetable, they should engage those providers “to delineate PQC migration responsibilities within the shared responsibility model” as outlined by the Federal Risk and Authorization Management Program (FedRAMP), OMB added.
“Given the scale and complexity of Federal IT environments, manual approaches to discovery and management of cryptography are often insufficient. Agencies should use automation when feasible and appropriate to achieve a comprehensive and continuously updated understanding of their cryptographic posture,” OMB recommended.
“Automation is critical for inventory management, policy enforcement, and compliance reporting,” it said. “Agencies should consider engaging their providers of cybersecurity services to determine if they offer automated solutions.”
News: FederalLegislation DataSecurity