US Agencies Must File Post-Quantum Migration Plans Within 120 Days, Targeting 2030 Shift
Updated
Updated · Quantum Zeitgeist · Jul 31
US Agencies Must File Post-Quantum Migration Plans Within 120 Days, Targeting 2030 Shift
3 articles · Updated · Quantum Zeitgeist · Jul 31
Summary
OMB memorandum M-26-15 and Executive Order 14412, both issued in June 2026, require US federal agencies to submit post-quantum cryptography migration plans within 120 days—around Oct. 22, 2026.
The rules set post-quantum key establishment as the hard priority by Dec. 31, 2030, move signature migration into 2031, and aim for full migration by 2035, aligning agency plans with NIST’s transition guidance.
NIST’s core standards are already final—FIPS 203, 204 and 205 were published in August 2024—while draft transition guidance points to RSA-2048 and 112-bit elliptic-curve systems being deprecated after 2030.
The urgency rests on “harvest now, decrypt later” risk: data encrypted today can be stored and cracked later, making long-lived secrets vulnerable before a cryptographically relevant quantum computer actually arrives.
The mandate also reaches suppliers: a planned federal procurement rule would require covered contractors to comply with post-quantum FIPS standards by the end of 2030.
With 2030 deadlines looming, will rushing to adopt post-quantum cryptography expose organizations to unforeseen vulnerabilities in newly standardized algorithms?
Could the massive financial cost of migrating to post-quantum cryptography ultimately outweigh the actual risks of future quantum decryption?
How can enterprises secure legacy systems against quantum attacks when massive post-quantum keys threaten to break existing network infrastructure?