CISA
Every article tagged CISA, newest first.
3 articles
CISA and G7 issue joint call to action on PQC
On September 3, 2026, CISA and the G7 Cyber Security Working Group published a jointly signed statement, co-signed by the UK, France, Germany, Canada, Japan and Italy's national cyber agencies, telling organizations they can no longer treat post-quantum migration as a future problem. It sets no new date and no new algorithm requirement. What is new is that seven governments signed the same page, which is a different kind of pressure than one more national deadline.
Executive Order 14412 sets a 2030 federal PQC deadline
Executive Order 14412, signed on June 22, 2026, gives the federal post-quantum migration dates that agencies have to plan against: key establishment by December 31, 2030 and digital signatures by December 31, 2031 for High Value Assets and high impact systems. It also directs the FAR Council to propose a rule carrying the same 2030 requirement to covered contractors. Here is what the order obliges, when each clock runs out, and which parts reach past the federal perimeter.
CISA's 2026 SBOM minimum elements: what changed, and why
CISA, with the NSA, FBI, and international partners, replaced the 2021 NTIA baseline for what a software bill of materials must contain. The new floor asks for cryptographic hashes on every component, a signature on the SBOM itself, full transitive-dependency depth, and machine-processable identifiers, and it applies to open-source, AI software, and SaaS. Here is what changed, why it was done, and why it lands next to the cryptographic bill of materials we build.
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.