The US Post-Quantum Deadline Is Now an Executive Order

June 22, 2026

EN | DE

The United States now has a civilian post-quantum deadline carrying the force of an executive order. Executive Order 14412, signed June 22, directs federal high value assets and high impact systems to adopt post-quantum cryptography for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. National Security Systems are carved out and stay on the existing CNSA 2.0 track under the NSA.

The two dates are the part worth reading closely. Key establishment and digital signatures are on separate clocks, a year apart. That gap is not an accident of drafting. It reflects a measurement reality the rest of the migration conversation tends to blur.

What the order requires

The scope is narrow and specific. The deadlines apply to high value assets as defined under OMB M-19-03 and to high impact systems, meaning any system assigned a FIPS 199 impact value of high for at least one security objective. National Security Systems are excluded, which keeps them on their own NSA-managed schedule rather than this one.

Agencies have 30 days to name a PQC migration lead and 90 days to receive OMB guidance requiring an inventory review and a written migration plan. NIST runs a migration pilot on its own systems, due by the end of 2027. The order also tells NIST to revise the Cryptographic Module Validation Program within 180 days to speed up FIPS 140 validations. When the bottleneck everyone complains about gets a deadline of its own, the schedule is meant to hold.

A year between the two clocks

Key establishment protects confidentiality. An adversary recording traffic today can decrypt it later once a quantum computer exists, the harvest-now-decrypt-later problem. That makes migrating key exchange urgent regardless of when the hardware arrives, because the exposure is already accruing on every long-lived secret in flight.

Digital signatures protect authentication. Forging one requires a quantum computer operating in real time, so the threat lands later. The engineering is harder, though. Post-quantum signatures are large, certificate chains carry several of them, and the public key infrastructure that issues and validates them moves slowly. Putting signatures a year behind key exchange is the order conceding that the harder half of the migration needs more runway.

Most posture reporting collapses these into one answer. A host either supports post-quantum cryptography or it does not. EO 14412 makes that framing inadequate for a federal program, because a system can be on pace for the 2030 key establishment deadline and behind on the 2031 signature deadline at the same moment. Those are two different measurements against two different dates.

Inventory becomes a federal requirement

The order does more than set dates. Within 270 days, CISA and NIST will publish minimum elements for a cryptographic bill of materials, built to let tools assess a system's cryptographic assets automatically. A federal CBOM baseline turns cryptographic inventory from a recommended practice into something procurement and oversight can check against.

Procurement carries the same direction outward. A proposed Federal Acquisition Regulation rule will require covered contractors to meet NIST FIPS, including the post-quantum standards, by the end of 2030. A second rule will require contractor vulnerability disclosure programs to accept reports of cryptographic weakness, including missing encryption and the use of non-FIPS algorithms. The order moves vendors from asserting cryptographic posture toward demonstrating it.

Posture is a trajectory, not a snapshot

A grade taken once tells you where a system sits today. It says nothing about whether the system is closing the gap to a deadline or drifting away from it. With two deadlines now in force, the question sharpens: is each asset improving toward 2030 for key establishment and 2031 for signatures, or holding stable in the wrong place. That is the measurement [PQ]probe is built to produce. It scans origin systems across protocols and scores key establishment and signature posture as separate trajectories against fixed dates.

The deadlines in EO 14412 mark when migration has to be finished. The harder number is how long the migration itself takes, measured against exposure that began the day the traffic went on the wire. The order compresses the runway. The clock was already running.