policy
Every article tagged policy, newest first.
3 articles
CISA and G7 issue joint call to action on PQC
On September 3, 2026, CISA and the G7 Cyber Security Working Group published a jointly signed statement, co-signed by the UK, France, Germany, Canada, Japan and Italy's national cyber agencies, telling organizations they can no longer treat post-quantum migration as a future problem. It sets no new date and no new algorithm requirement. What is new is that seven governments signed the same page, which is a different kind of pressure than one more national deadline.
Executive Order 14412 sets a 2030 federal PQC deadline
Executive Order 14412, signed on June 22, 2026, gives the federal post-quantum migration dates that agencies have to plan against: key establishment by December 31, 2030 and digital signatures by December 31, 2031 for High Value Assets and high impact systems. It also directs the FAR Council to propose a rule carrying the same 2030 requirement to covered contractors. Here is what the order obliges, when each clock runs out, and which parts reach past the federal perimeter.
Governments set the post-quantum deadlines. Their own sites are behind.
We added 201 government and public-sector sites to the PQC Observatory and measured them as their own panel. Just under a third negotiate post-quantum key exchange today. The pattern is not the one you would guess: several of the governments writing the migration mandates have not enabled it on their own front doors, while smaller states are already there.
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.