Skip to content
All news
News

GSA starts post-quantum overhaul of federal PIV badges

By quantakrypto Research4 min read

Also mentioned

RSARSARivest, Shamir and AdlemanA widely used public-key algorithm for encryption and digital signatures whose security relies on the difficulty of factoring large numbers.Read the full entry, ECCECCelliptic curve cryptographyElliptic curve cryptography: the family of public-key algorithms whose security rests on the difficulty of the elliptic curve discrete logarithm problem.Read the full entry, ML-KEMML-KEMModule-Lattice-based Key Encapsulation MechanismModule-Lattice-Based Key-Encapsulation Mechanism, the NIST-standardized post-quantum KEM derived from CRYSTALS-Kyber and specified in FIPS 203.Read the full entry, ML-DSAML-DSAModule-Lattice-based Digital Signature AlgorithmModule-Lattice-Based Digital Signature Algorithm, the NIST-standardized post-quantum signature scheme derived from CRYSTALS-Dilithium and specified in FIPS 204.Read the full entry, TLSTLSTransport Layer SecurityTransport Layer Security, the protocol that encrypts and authenticates most internet traffic, including HTTPS. It uses key exchange, certificates, and symmetric encryption to protect a session.Read the full entry, FIPSFIPSFederal Information Processing StandardFederal Information Processing Standards, publicly announced standards developed by NIST for use in U.S. government computer systems, including cryptographic algorithms and modules.Read the full entry, NISTNISTNational Institute of Standards and TechnologyThe U.S. National Institute of Standards and Technology, the agency that develops and publishes cryptographic standards, including the FIPS series and post-quantum algorithms.Read the full entry, PQCPQCpost-quantum cryptographyCryptographic algorithms designed to run on today's classical computers while remaining secure against attacks by both classical and future quantum computers.Read the full entry are defined in the glossary.

TL;DR

Read this first

On August 24, 2026, GSA published a blog post describing two parallel efforts. First, a GSA-led interagency working group on Federal Identity, Credential, and Access Management (FICAM) modernization, required by OMB Memorandum M-26-15, held its first meeting on August 12, 2026 with 40 participants from 17 federal agencies, meeting biweekly to work through non-human identities, automation, and access management in a post-quantum environment. Second, GSA's FIPS 201 Evaluation Program, run out of its Physical Access Control System (PACS) lab, is expanding its testing to validate post-quantum-capable PIV badges, building access controls, and visitor passes for the government's Approved Products List. Both efforts implement NIST's June 12, 2026 working drafts of SP 800-73 (the PIV card interface) and SP 800-78 (PIV cryptographic algorithms), which add ML-KEM and ML-DSA to the PIV card standard through a dual-stack design that keeps the existing classical keys in place. GSA is also hosting a virtual Post-Quantum Cryptography Summit on September 16, 2026.

Forty people from seventeen agencies got on a call on August 12 to talk about badges. That undersells it. The PIV card is the credential that gets a federal employee through a door and onto a network, and it is exactly the kind of quantum-vulnerable public-key infrastructure Executive Order 14412 was written about: deployed at enormous scale, hard to rotate quickly, and invisible to most of the people who rely on it every day. GSA's blog post is the first concrete look at what moving that infrastructure actually involves, rather than what an order or a memo says it should involve.

The card gets a second stack, not a replacement

NIST's working drafts of SP 800-73 Parts 1 and 2 and SP 800-78 describe a dual-stack PIV card: the existing RSA or ECC key references and certificate containers stay exactly where they are, and new key references, certificate containers, and data objects for ML-DSA signatures and ML-KEM key establishment are added alongside them. A reader that only understands the classical stack keeps working. A reader upgraded to understand the new one can use it. Nobody has to reissue every badge in government on the day the standard ships, which is the only realistic way to move a credential this widely deployed. NIST is taking comment on the drafts through a public mailing list and a GitHub repository rather than a formal comment period, because these are working drafts, not the finished SP 800-73 and SP 800-78 revisions.

Physical access control is the part migration plans usually skip

  • The FIPS 201 Evaluation Program is what puts a badge reader, a door controller, or a visitor management system on GSA's Approved Products List in the first place, so a product cannot claim PIV compliance for federal buildings without passing through it.
  • That lab is now building post-quantum algorithms into its test suite, which means the vendors selling into federal physical security, not just federal IT, are the next ones facing a validation queue.
  • Most cryptographic migration writing, ours included, is about TLS and certificate authorities. A door lock that authenticates a badge is a cryptographic system too, and it was not on most people's list.

Where this sits on the EO 14412 timeline

OMB Memorandum M-26-15, issued two days after Executive Order 14412 was signed, is what actually assigns the work: it directs GSA to stand up this FICAM working group as part of turning the order's December 31, 2030 and 2031 deadlines into an agency-by-agency plan. The working group's first meeting and the PACS lab's test expansion are the first visible outputs of that assignment, arriving a month ahead of the order's own 90-day guidance deadline. If you track the 2030 and 2035 deadlines NIST set for retiring RSA and elliptic curve, this is what the early planning phase looks like from the inside: working groups, draft standards, and lab test suites, months before any badge in your wallet changes.

TL;DR

The point

If your organization sells identity, badge, or physical access hardware into the federal market, the FIPS 201 Evaluation Program's test suite is where your post-quantum requirement will actually get enforced, and it is being written now. If you operate PIV-authenticated systems, the dual-stack design means you are planning for a coexistence period, not a cutover weekend, so the immediate question is whether your own PIV-consuming applications and readers can be upgraded to recognize a second stack of keys without downtime.

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.