Skip to content
All news
News

Executive Order 14412 sets a 2030 federal PQC deadline

By quantakrypto Research5 min read
TL;DR

Read this first

EO 14412, Securing the Nation Against Advanced Cryptographic Attacks, was signed on June 22, 2026 and published in the Federal Register three days later. It requires federal agencies to move High Value Assets and high impact systems to post-quantum key establishment by December 31, 2030, and to post-quantum signatures by December 31, 2031. Separately, it directs the FAR Council to publish a proposed rule requiring covered contractors to comply with NIST FIPS, including the PQC standards, by December 31, 2030. The OMB guidance that starts the agency planning cycle was due 90 days after signing, which is September 20, 2026.

Until this summer, the honest answer to "when does post-quantum actually have to be finished" was a draft. NIST IR 8547 proposed deprecating RSA and elliptic-curve cryptography in 2030 and disallowing them in 2035, and it remains an internal report rather than a binding instrument. Executive Order 14412 does not replace that timeline, it sits on top of it with something IR 8547 never had: dates an agency is obliged to plan against, and a procurement lever that carries them outside government.

What the order requires, and when

The order is short and unusually specific. Each obligation below names its section, so it can be checked against the text rather than taken on trust.

  • Section 4(a), within 30 days (July 22, 2026). Every agency head names a PQC migration lead and sends the name and contact details to OMB and the National Cyber Director. This deadline has already passed.
  • Section 4(b), within 90 days (September 20, 2026). OMB issues guidance requiring each agency to review its inventory of HVAs and high impact systems, transition them on the schedule below, and submit a migration plan to OMB and the National Cyber Director.
  • Section 4(b)(ii), December 31, 2030. All HVAs and high impact systems use PQC for key establishment.
  • Section 4(b)(iii), December 31, 2031. The same systems use PQC for digital signatures.
  • Section 4(c), within 180 days. NIST starts a PQC migration pilot on a subset of its own systems, to be completed no later than December 31, 2027.
  • Section 5(d), within 270 days (March 19, 2027). CISA publishes guidance on the minimum elements for a cryptographic bill of materials.
  • Section 6(b), within 180 days (December 19, 2026). NIST revises the Cryptographic Module Validation Program to accelerate validations.
  • Section 6(c), within 180 days (December 19, 2026). The FAR Council publishes a proposed rule requiring covered contractors to comply by December 31, 2030 with NIST FIPS, including all applicable FIPS incorporating PQC algorithms.

National Security Systems sit outside the Section 4 inventory review and stay on the CNSA 2.0 schedule, with NSA reporting on their migration status within 180 days and annually after that. If you are mapping obligations, CNSA 2.0 and this order are two different clocks over two different estates.

The procurement rule is what reaches past government

Sections 4 and 5 bind federal agencies. Section 6(c) is the one that makes this a supplier problem. It instructs the FAR Council to propose amending the Federal Acquisition Regulation so that covered contractors comply with NIST FIPS, including the post-quantum standards, by December 31, 2030. That is the same date the agencies themselves have for key establishment, which leaves a vendor no grace period behind its customer.

Two caveats are worth stating plainly, because the gap between a proposed rule and an enforceable clause is where most of the uncertainty lives. A proposed rule is not a final rule: it goes out for public comment, it can be narrowed, and "covered contractors" is defined in the rulemaking rather than in the order. The 180-day clock is on publication of the proposal, not on the obligation taking effect. What is settled is the direction and the target date, which is enough to start answering procurement questionnaires that will begin citing this order long before the FAR text is final.

Validation is the bottleneck the order quietly concedes

Section 6(b) tells NIST to revise the Cryptographic Module Validation Program to accelerate validations. That instruction is an admission about where the real queue forms. FIPS 203, 204 and 205 were finalized in August 2024, so the algorithms have not been the constraint for two years. Shipping them inside a module that carries a current certificate is a different exercise, and FIPS 140-3 validation is measured in quarters rather than weeks. An agency that has to buy validated modules, and a vendor that has to supply them, are both sitting behind the same queue that Section 6(b) is trying to shorten.

Cryptographic inventory stops being a best practice

Section 5(d) has CISA define the minimum elements for a cryptographic bill of materials. Minimum elements is the same phrasing that turned the software bill of materials from an idea into a procurement artifact, and it points the same way here. Every deadline in Section 4 is downstream of an inventory, because an agency cannot commit to transitioning HVAs it cannot enumerate, and a plan due to OMB is unfalsifiable without one. If you read the order as a sequence rather than a list, the CBOM is the first deliverable and everything else depends on it.

What this changes for planning

If your migration plan was pegged to 2035, this order does not move NIST IR 8547, but it does mean the systems your federal customers care about have to be done five years earlier, and that your own contractual exposure now has a published target date. If your plan was already pegged to 2030, the change is smaller in substance and larger in evidence: the date is now in an executive order rather than a draft report, which is a materially easier thing to take to a budget committee.

The near-term item is the one most likely to be missed. The OMB guidance under Section 4(b) is what converts these dates into an agency plan with a named owner, and it was due in late September 2026. Anyone selling into or operating within the federal estate should expect inventory questions to arrive on that cycle rather than on the 2030 one.

Decision

The useful next step

Nothing in this order can be answered from a policy document. Every obligation it creates resolves to a question about which algorithms are running where, in which modules, with which certificates. If you cannot produce that list today, produce it before the questionnaires arrive: a cryptographic inventory is the one deliverable that is a prerequisite for all of the others.

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.