Skip to main content
CybersecurityVulnerability Management

US Government Accelerates Post-Quantum Cryptography Transition

Secure computer terminal on a plain surface in a government facility.

“Whole of government approach” is needed to advance quantum computing research while simultaneously preparing federal systems for security challenges those same technologies will create, an anonymous government source told CyberScoop prior to the signing of the Executive Order.

The Executive Order: Securing the Nation Against Advanced Cryptographic Attacks

The administration signed an Executive Order titled Securing the Nation Against Advanced Cryptographic Attacks that pushes federal agencies to accelerate their move to post-quantum cryptography (PQC). The directive explicitly instructs the Director of the National Security Agency with respect to National Security Systems (NSS), and the Director of OMB with respect to non‑NSS, to each issue requirements for agencies to support transition to PQC “as soon as practicable, but not later than January 2, 2030.” The order rejects the notion that agencies can wait until the mid-2030s to complete the transition, saying quantum readiness must begin well before the point at which quantum computers can break today’s public‑key encryption.

The quantum threat and "harvest-now-decrypt-later" attacks

Although cryptographically relevant quantum computers (CRQC) remain under development, the risk is already shaping cybersecurity planning. A blog post titled “The White House’s post-quantum executive order is an important milestone. It’s time to get to work” argues that “Post-quantum encryption is needed today to stop harvest-now-decrypt-later attacks, where an adversary collects encrypted traffic today and decrypts it later once quantum computers are powerful enough.” The Executive Order frames Q‑Day as the moment when CRQC can defeat current public‑key systems, and directs agencies to prepare now rather than wait for that moment.

Technical hurdles: confidentiality, authentication, and new standards

Transitioning to PQC is more complex than replacing one algorithm with another. Jeremy Corey, Senior Solutions Engineer at Cloudflare, said during the “Securing the DoW’s Digital Perimeter with Cloudflare One PQC” webinar that there are “two distinct challenges we face in the post‑quantum era: post‑quantum encryption that protects the confidentiality of information, and post‑quantum authentication that protects the integrity of information and resources.” The source highlights emerging approaches under evaluation — including ML‑DSA and Merkle Tree Certificates (MTCs) — that aim to deliver post‑quantum authentication. Agencies face operational hurdles from larger key sizes, new certificate formats, application dependencies, and interoperability requirements that must be addressed ahead of mandated deadlines.

Industry innovation, crypto‑agility, and vendor responsibility

The Executive Order lays out an ambitious federal roadmap, but the piece emphasizes that achieving it depends heavily on vendors and technology providers. Vendors that have already invested in crypto‑agility, hybrid cryptography, and quantum‑resistant architectures can reduce migration risk and implementation complexity, the source argues. It also recommends that agencies adopt solutions with PQC built into their core to simplify deployment and align with evolving federal guidance immediately.

What this means for technologists, policymakers, and procurement leaders

  • Technologists and security teams: Begin inventorying where cryptography is used, identify the types in use, and understand data lifecycle requirements; evaluate post‑quantum authentication options such as ML‑DSA and Merkle Tree Certificates, and plan for larger keys and interoperability changes.
  • Policymakers and agency leaders: Expect to receive and enforce requirements from the Director of the National Security Agency (for NSS) and the Director of OMB (for non‑NSS) by January 2, 2030, and to accelerate migration timelines compared with earlier mid‑2030s expectations.
  • Procurement leaders and vendors: Scrutinize supply chains and vendor capabilities; prioritize partners already offering crypto‑agile, hybrid, or PQC‑native architectures to reduce migration risk and align with the EO’s deadlines.

Quantum readiness, the source material makes clear, is no longer a distant planning exercise: the federal government has ordered a near‑term shift, industry must accelerate innovation, and agencies will have binding deadlines to meet. The Executive Order sets the destination; as the source puts it, “industry innovation will determine how quickly agencies can get there.”

Original story