Skip to content
All standards
Compliance & mandatesUS NSM-10 (2022) + OMB M-23-02

NSM-10 & OMB M-23-02

National Security Memorandum 10 · OMB Memorandum M-23-02 — the US federal PQC migration mandate

Updated

NSM-10 and OMB M-23-02 are the two linked US federal instruments that turned post-quantum migration from a research topic into a compliance obligation. NSM-10 — the National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, issued 4 May 2022 — sets the national goal of mitigating quantum risk to vulnerable cryptography by 2035 and directs agencies to prepare and inventory. OMB Memorandum M-23-02, "Migrating to Post-Quantum Cryptography" (November 2022), operationalizes that goal for civilian agencies: inventory first, prioritize by sensitivity, and plan the migration.

Why it matters

These memoranda bind US federal agencies, but they have become the de-facto template that many regulated enterprises and vendors are adopting — because the logic is universal. You cannot migrate what you cannot see. The defining requirement of both instruments is not an algorithm swap; it is a cryptographic inventory of where vulnerable public-key cryptography lives, ranked by how much it matters. That inventory is what makes every later step — prioritization, budgeting, hybrid rollout — defensible rather than guesswork.

What each instrument requires

NSM-10 is the strategy layer: it names 2035 as the federal mitigation target and directs agencies to begin preparing systems and identifying vulnerable cryptography. M-23-02 is the execution layer, and its obligations are concrete:

  • Inventory the most sensitive and high-impact cryptographic systems that rely on quantum-vulnerable public-key cryptography.
  • Submit a prioritized inventory to the Office of the National Cyber Director (ONCD) and CISA — an initial version within roughly a year, updated annually thereafter.
  • Assess and plan migration, using the inventory to sequence which systems move first.
  • Budget for the transition, treating cost estimation as part of the mandate rather than an afterthought.
Pitfall

Inventory first — and 2035 is a deadline, not a start date

The mandate is inventory-first for a reason: organizations that jump straight to swapping algorithms before they have inventoried end up with blind spots — embedded systems, third-party libraries, and long-lived data they never enumerated. And 2035 is when mitigation must be complete, not when work should begin. Given real migration timelines, harvest-now-decrypt-later exposure, and multi-year procurement cycles, the work starts now.

How quantakrypto helps

We treat the inventory as the load-bearing deliverable it is. Our audit produces the prioritized cryptographic inventory these mandates demand — where quantum-vulnerable cryptography lives, in code, protocols, and dependencies, ranked by sensitivity so it maps directly onto the ONCD/CISA submission format. From there our migration engagement sequences and executes the move, aligned to the NIST deprecate-2030 / disallow-2035 timeline that the 2035 federal goal tracks, and to CNSA 2.0's 2033 milestone for national-security systems. If you are also anchoring to a management-system standard, the same inventory satisfies ISO 27001 A.8.24 on the use of cryptography.

Frequently asked questions

What is the difference between NSM-10 and OMB M-23-02?

NSM-10 is the strategy: a 2022 National Security Memorandum setting the national goal to mitigate quantum risk to vulnerable cryptography by 2035 and directing agencies to prepare and inventory. M-23-02 is the execution: a 2022 OMB memorandum that tells civilian agencies exactly what to do — inventory their most sensitive cryptographic systems, submit a prioritized inventory to ONCD and CISA, and plan and budget for migration.

What exactly must agencies submit, and how often?

M-23-02 requires a prioritized inventory of the systems most reliant on quantum-vulnerable cryptography, submitted to ONCD and CISA — an initial version within roughly a year of the memo and updated annually. The prioritization, not just the list, is the point: it drives which systems migrate first.

Do these mandates apply to private companies?

Legally they bind US federal agencies. In practice they have become the template many regulated enterprises and vendors adopt, because the underlying discipline — inventory before you migrate, prioritize by sensitivity, budget for the work — applies to any organization with long-lived sensitive data.

Is 2035 the deadline to start migrating?

No. 2035 is the federal target for completing mitigation of quantum risk, not a start date. It aligns with NIST IR 8547's disallow-after-2035 timeline and complements CNSA 2.0's 2033 milestone for national-security systems. Because migration and procurement take years, and because harvest-now-decrypt-later exposure is happening today, the inventory and planning work has to begin now.

Work with us on NSM-10 & OMB M-23-02

Related reading

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.