The US federal post-quantum mandates, mapped
If you sell to or operate within the US government, a specific chain of memoranda and standards drives your post-quantum obligations. NSM-10, OMB M-23-02, NIST IR 8547, and CNSA 2.0 — what each one requires.
US federal post-quantum requirements are not a single law; they are a chain of instruments, each doing a different job. Understanding the chain tells you which document to cite for which requirement — and it is a useful template even for private-sector programs, because vendors and partners increasingly inherit these obligations by contract.
- **NSM-10 (2022)** — National Security Memorandum 10 sets the national direction: migrate vulnerable cryptographic systems to quantum-resistant cryptography and prepare government-wide.
- **OMB M-23-02** — directs federal agencies to inventory cryptographic systems and prioritize them for migration, and to report on that inventory. This is the origin of the cryptographic-inventory requirement.
- **NIST FIPS 203/204/205 (2024)** — the approved algorithms agencies migrate to.
- **NIST IR 8547** — describes the transition to post-quantum standards, including guidance on deprecating quantum-vulnerable algorithms over time.
- **NSA CNSA 2.0** — the Commercial National Security Algorithm Suite 2.0 for national-security systems, with its own algorithm choices and adoption timeline running toward the early-to-mid 2030s.
Start with the inventory regardless of sector
Every one of these instruments depends on knowing where your cryptography is. The cryptographic inventory is both the first federal deliverable (M-23-02) and the thing that lets you sequence everything else by risk. It is the right first move even if no mandate applies to you yet.
The timelines matter: CNSA 2.0 and the federal transition guidance phase in over years, with the harvest-now-decrypt-later logic meaning the practical deadline for protecting long-lived data is earlier than the compliance deadline for finishing migration. Treat the mandate dates as the latest acceptable end, not the date to start. For the algorithm-to-obligation view, see which standard satisfies which obligation.