Read this first
EO 14412, Securing the Nation Against Advanced Cryptographic Attacks, was signed on June 22, 2026 and published in the Federal Register three days later. It requires federal agencies to move High Value Assets and high impact systems to post-quantum key establishment by December 31, 2030, and to post-quantum signatures by December 31, 2031. Separately, it directs the FAR Council to publish a proposed rule requiring covered contractors to comply with NIST FIPS, including the PQC standards, by December 31, 2030. The OMB guidance that starts the agency planning cycle was due 90 days after signing, which is September 20, 2026.
Until this summer, the honest answer to "when does post-quantum actually have to be finished" was a draft. NIST IR 8547 proposed deprecating RSA and elliptic-curve cryptography in 2030 and disallowing them in 2035, and it remains an internal report rather than a binding instrument. Executive Order 14412 does not replace that timeline, it sits on top of it with something IR 8547 never had: dates an agency is obliged to plan against, and a procurement lever that carries them outside government.
What the order requires, and when
The order is short and unusually specific. Each obligation below names its section, so it can be checked against the text rather than taken on trust.
- Section 4(a), within 30 days (July 22, 2026). Every agency head names a PQC migration lead and sends the name and contact details to OMB and the National Cyber Director. This deadline has already passed.
- Section 4(b), within 90 days (September 20, 2026). OMB issues guidance requiring each agency to review its inventory of HVAs and high impact systems, transition them on the schedule below, and submit a migration plan to OMB and the National Cyber Director.
- Section 4(b)(ii), December 31, 2030. All HVAs and high impact systems use PQC for key establishment.
- Section 4(b)(iii), December 31, 2031. The same systems use PQC for digital signatures.
- Section 4(c), within 180 days. NIST starts a PQC migration pilot on a subset of its own systems, to be completed no later than December 31, 2027.
- Section 5(d), within 270 days (March 19, 2027). CISA publishes guidance on the minimum elements for a cryptographic bill of materials.
- Section 6(b), within 180 days (December 19, 2026). NIST revises the Cryptographic Module Validation Program to accelerate validations.
- Section 6(c), within 180 days (December 19, 2026). The FAR Council publishes a proposed rule requiring covered contractors to comply by December 31, 2030 with NIST FIPS, including all applicable FIPS incorporating PQC algorithms.
National Security Systems sit outside the Section 4 inventory review and stay on the CNSA 2.0 schedule, with NSA reporting on their migration status within 180 days and annually after that. If you are mapping obligations, CNSA 2.0 and this order are two different clocks over two different estates.
The procurement rule is what reaches past government
Sections 4 and 5 bind federal agencies. Section 6(c) is the one that makes this a supplier problem. It instructs the FAR Council to propose amending the Federal Acquisition Regulation so that covered contractors comply with NIST FIPS, including the post-quantum standards, by December 31, 2030. That is the same date the agencies themselves have for key establishment, which leaves a vendor no grace period behind its customer.
Two caveats are worth stating plainly, because the gap between a proposed rule and an enforceable clause is where most of the uncertainty lives. A proposed rule is not a final rule: it goes out for public comment, it can be narrowed, and "covered contractors" is defined in the rulemaking rather than in the order. The 180-day clock is on publication of the proposal, not on the obligation taking effect. What is settled is the direction and the target date, which is enough to start answering procurement questionnaires that will begin citing this order long before the FAR text is final.
Validation is the bottleneck the order quietly concedes
Section 6(b) tells NIST to revise the Cryptographic Module Validation Program to accelerate validations. That instruction is an admission about where the real queue forms. FIPS 203, 204 and 205 were finalized in August 2024, so the algorithms have not been the constraint for two years. Shipping them inside a module that carries a current certificate is a different exercise, and FIPS 140-3 validation is measured in quarters rather than weeks. An agency that has to buy validated modules, and a vendor that has to supply them, are both sitting behind the same queue that Section 6(b) is trying to shorten.
Cryptographic inventory stops being a best practice
Section 5(d) has CISA define the minimum elements for a cryptographic bill of materials. Minimum elements is the same phrasing that turned the software bill of materials from an idea into a procurement artifact, and it points the same way here. Every deadline in Section 4 is downstream of an inventory, because an agency cannot commit to transitioning HVAs it cannot enumerate, and a plan due to OMB is unfalsifiable without one. If you read the order as a sequence rather than a list, the CBOM is the first deliverable and everything else depends on it.
What this changes for planning
If your migration plan was pegged to 2035, this order does not move NIST IR 8547, but it does mean the systems your federal customers care about have to be done five years earlier, and that your own contractual exposure now has a published target date. If your plan was already pegged to 2030, the change is smaller in substance and larger in evidence: the date is now in an executive order rather than a draft report, which is a materially easier thing to take to a budget committee.
The near-term item is the one most likely to be missed. The OMB guidance under Section 4(b) is what converts these dates into an agency plan with a named owner, and it was due in late September 2026. Anyone selling into or operating within the federal estate should expect inventory questions to arrive on that cycle rather than on the 2030 one.
The useful next step
Nothing in this order can be answered from a policy document. Every obligation it creates resolves to a question about which algorithms are running where, in which modules, with which certificates. If you cannot produce that list today, produce it before the questionnaires arrive: a cryptographic inventory is the one deliverable that is a prerequisite for all of the others.
References
- Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (whitehouse.gov) - the order as signed on June 22, 2026.
- EO 14412 in the Federal Register, 91 FR 38483 (federalregister.gov) - the published text, with section numbering.
- NIST IR 8547, Transition to Post-Quantum Cryptography Standards (csrc.nist.gov) - the 2030 and 2035 timeline the order sits on top of.
- CISA Post-Quantum Cryptography Initiative (cisa.gov) - the CISA programme carrying the critical-infrastructure and CBOM work.
- NIST Cryptographic Module Validation Program (csrc.nist.gov) - the validation queue Section 6(b) targets.
- quantakrypto: the NIST IR 8547 deadlines - what 2030 and 2035 mean for RSA and elliptic curve.
- quantakrypto: building a cryptographic bill of materials - the inventory every obligation in this order depends on.