US Federal PQC Policy From NSM-10 To The June 2026 Executive Order
US post-quantum policy moved from planning in 2022 to dated migration deadlines in 2026. Here is each instrument in order, what it added and why it matters beyond government.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
The United States has built its post-quantum policy one instrument at a time: a national security memorandum, a law, several executive orders and a series of memoranda from the Office of Management and Budget (OMB), the White House office that sets IT and security policy for federal agencies. Each one added something, and some changed what came before. Reading any one of them alone gives an incomplete picture.
This article puts the instruments in order, as of October 2026, and explains what each one requires and of whom. Most of these rules bind federal agencies, not private companies. They still matter to private firms, because they shape procurement, set expectations for suppliers and are widely copied.
The Chronology
- National Security Memorandum 10
Directs federal preparation for the move to quantum-resistant cryptography, with the goal of mitigating as much quantum risk as feasible by 2035.
- OMB Memorandum M-23-02
Requires agencies to submit a prioritised inventory of cryptographic systems by 4 May 2023 and every year after.
- Quantum Computing Cybersecurity Preparedness Act
Puts the inventory duty into law and requires OMB guidance on migration. National security systems are excluded.
- Executive Order 14144
A broad cybersecurity order with a section on post-quantum cryptography.
- Executive Order 14306
Strikes the post-quantum subsection of EO 14144 and inserts new text: a product categories list from the Cybersecurity and Infrastructure Security Agency (CISA), and support for Transport Layer Security (TLS) 1.3, the protocol behind most encrypted web traffic, by 2 January 2030.
- CISA Product Categories List
Lists product categories where post-quantum support is widely available or in transition.
- Executive Order 14412
Directs OMB to issue guidance requiring federal high-value assets and high-impact systems to use post-quantum key establishment by end 2030 and signatures by end 2031.
- OMB Memorandum M-26-15
Implements the order: migration plans within 120 days and a five-phase migration through 2035.
Sources: NSM-10 as cited in M-23-02 and EO 14306,12 the Act,3 EO 14306,2 CISA,4 EO 144125 and M-26-15.6
2022: Planning And Inventory
National Security Memorandum 10 set the direction. As quoted in later guidance, it gave the goal of mitigating as much quantum risk as is feasible by 2035.1 OMB Memorandum M-23-02 turned that into a task. Agencies had to send a prioritised inventory of their cryptographic systems to the Office of the National Cyber Director and CISA by 4 May 2023, and annually after that until 2035 or until replaced by later guidance.1
In December 2022, Congress passed the Quantum Computing Cybersecurity Preparedness Act. It requires agencies to maintain a current inventory of information technology that is vulnerable to decryption by quantum computers, and it requires OMB to issue migration guidance. The Act does not apply to national security systems.3
2025: A Reset
Executive Order 14144, signed on 16 January 2025, was a broad cybersecurity order that included post-quantum measures. Less than five months later, Executive Order 14306 amended it. Among other changes, it struck the post-quantum subsection and inserted new text in its place.2
The new text contains two concrete actions. CISA, in consultation with NSA, was to publish a list of product categories in which post-quantum products are widely available. And NSA, for national security systems, and OMB, for everything else, were to require agencies to support TLS 1.3 or a successor as soon as practicable and no later than 2 January 2030.2 OMB describes version 1.3 as the foundation for deploying post-quantum key exchange on federal networks.6 CISA published the product categories list on 23 January 2026, after the 1 December 2025 date in the order.4
2026: Dated Migration
On 22 June 2026 the President signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”. It required OMB to issue guidance within 90 days directing agencies to move all high-value assets and high-impact systems, other than national security systems, to post-quantum key establishment by 31 December 2030 and to post-quantum digital signatures by 31 December 2031.5
The order also reaches beyond agencies. It asks CISA, with NIST, to publish guidance on the minimum elements of a cryptographic bill of materials (CBOM), a structured list of the cryptography inside a product, within 270 days. It directs the Federal Acquisition Regulatory Council to propose, within 180 days, a rule requiring covered contractors to comply with NIST’s cryptographic standards, including post-quantum algorithms, by 31 December 2030. And it asks the agencies responsible for each critical infrastructure sector to help owners and operators develop migration plans.5
OMB moved two days later. Memorandum M-26-15 tells agencies to run a prioritised migration aimed at mitigating as much quantum risk as feasible by 31 December 2030, and to submit a migration plan within 120 days of 24 June 2026.6 By our count, that falls on 22 October 2026; the memorandum itself gives only the number of days.
What M-26-15 Asks Agencies To Do
The memorandum describes migration as a multi-year programme in five phases.6
- Phase 1: Strategy, Planning And Discovery (2026 to 2027)
Inventory, including high-value assets and high-impact systems, risk assessment, governance and accountable officials.
- Phase 2: Pilots And Early Migration (2027 to 2028)
Pilot projects, early migration of prioritised systems and plan refinement.
- Phase 3: Prioritised Migration (2028 to 2030)
Post-quantum key establishment for high-value, high-impact and highly sensitive systems.
- Phase 4: Signature Migration (2031)
Post-quantum digital signatures for the same priority systems.
- Phase 5: Full Migration (2035)
Remaining systems, based on risk and on what commercial products can support.
Two parts of the memorandum stand out for anyone outside government. Its appendix says manual discovery is often inadequate at this scale, and recommends a continuously updated inventory built with automated tools, including software composition analysis, code testing and network scanners for protocols and cipher suites, feeding a central CBOM.6 It also tells agencies to use the CISA product categories list and require post-quantum support when buying products in those categories.
Why It Matters Outside Government
Federal rules do not bind most private companies directly. They reach the private sector in three ways.
- Procurement. Agencies are told to require post-quantum support in listed product categories, and the proposed contractor rule would extend compliance duties to covered contractors.
- Shared tooling. The forthcoming CBOM guidance is meant to support automated assessment of the cryptography in hardware and software, which is likely to shape what customers ask vendors for.
- Critical infrastructure. The order asks sector agencies to help critical infrastructure owners plan their migrations.
- Upcoming
United States · Office of Management and Budget Binding
Submit a post-quantum cryptography migration plan to OMB and the Office of the National Cyber Director, no later than 120 days after the memorandum. The date shown is calculated by us as 120 days after 24 June 2026; the memorandum gives only the number of days.
- Upcoming
United States · The White House Binding
The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.
- Upcoming
United States · The White House Binding
CISA, in coordination with NIST, must release public guidance on the minimum elements of a cryptographic bill of materials within 270 days of the order. The date shown is calculated by us as 270 days after 22 June 2026.
- Upcoming
United States · The White House Binding
Agencies must support TLS 1.3 or a successor version as soon as practicable, and no later than this date, under requirements that the order directed OMB (for other systems) and NSA (for national security systems) to issue; OMB M-26-15 restates the date.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.
Footnotes
-
US Office of Management and Budget, “M-23-02: Migrating to Post-Quantum Cryptography”, 18 November 2022. whitehouse.gov ↩ ↩2 ↩3
-
The White House, “Executive Order 14306: Sustaining Select Efforts To Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144”, 6 June 2025, Federal Register 11 June 2025. govinfo.gov ↩ ↩2 ↩3 ↩4
-
US Congress, “Public Law 117-260: Quantum Computing Cybersecurity Preparedness Act”, sections 4 and 5, 21 December 2022. govinfo.gov ↩ ↩2
-
CISA, “CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump’s Executive Order 14306”, 23 January 2026. cisa.gov ↩ ↩2
-
The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026. govinfo.gov ↩ ↩2 ↩3
-
US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2 ↩3 ↩4 ↩5
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.