REGULATIONS ACROSS REGIONS / INTERMEDIATE

United States: Federal PQC Deadlines, NYDFS, SEC And The State AI Patchwork

US post-quantum deadlines bind federal agencies and soon contractors. Private firms face sector encryption and disclosure rules instead. A map of who is bound by what, as of October 2026.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

The United States has one of the most detailed national post-quantum programmes, with dated milestones in a presidential executive order. It is easy to read too much into that. As of October 2026, those deadlines bind federal agencies, and a rule that would require federal contractors to meet NIST’s post-quantum standards by 2030 has been ordered but not yet proposed. Private companies are not under a general post-quantum mandate.

What private firms do face are sector rules on encryption, asset inventories and incident disclosure, set by regulators such as the New York State Department of Financial Services (NYDFS), the Securities and Exchange Commission (SEC) and the Federal Trade Commission (FTC). This article maps both layers and labels each item by its legal force. It is general information, not legal advice. For the full federal chronology and NSA’s CNSA 2.0 dates, see Cryptography Compliance.

Who Is Bound By What

The US picture is easiest to read as rings, from the most tightly regulated systems outwards.

  1. National Security Systems (Binding, NSS Only)Follow NSA guidance under CNSA 2.0, on their own dates. Excluded from the civilian rules below.
  2. Federal Agencies, Other Than National Security Systems (Binding On Agencies)Executive Order 14412, OMB M-26-15 and Public Law 117-260: plans, inventories, and post-quantum key establishment by end 2030 and signatures by end 2031 for high value assets and high impact systems. Full migration by 2035 is a planning phase.
  3. Federal Contractors (Proposed Rule Pending)A FAR rule is due to be proposed by 19 December 2026, requiring FIPS compliance including post-quantum algorithms by 31 December 2030.
  4. Private Sector (Sector Rules, No Post-Quantum Mandate)NYDFS encryption and asset inventory, FTC Safeguards Rule encryption, SEC incident disclosure and Regulation S-P.
US post-quantum and cryptography obligations by ring, as of October 2026. Only the inner three rings have post-quantum dates, and the contractor ring is still a pending rule.

Federal Agencies: The Binding Core

Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, was signed on 22 June 2026. Section 4(b) directs the Office of Management and Budget (OMB) to issue guidance that requires agencies to move all high value assets and high impact systems to post-quantum key establishment by 31 December 2030 and to post-quantum digital signatures by 31 December 2031.1 Strictly, the dates bind agencies through that OMB guidance rather than directly. OMB’s Memorandum M-26-15, issued two days later, builds them into its phases (key establishment for these systems in 2028 to 2030, signatures in 2031) and sets the objective of reducing as much quantum risk as feasible by 31 December 2030.2 Status: Binding on federal agencies, excluding national security systems: M-26-15 says it does not apply to them, and the order leaves them out of its inventory review.21

Under M-26-15, agencies must submit a post-quantum migration plan within 120 days, which falls on 22 October 2026, and must support TLS 1.3 or a successor no later than 2 January 2030, a date first set by Executive Order 14306. The memo describes five phases that agencies should follow: strategy and discovery in 2026 to 2027, pilots in 2027 to 2028, prioritised key establishment migration in 2028 to 2030, signature migration in 2031, and full migration by 2035. Plans must align with NIST IR 8547, which is still an initial public draft.2 Status: Binding on agencies. The memo’s recommendation that inventory data feed a central cryptographic bill of materials (CBOM) is Guidance within it.

The inventory duty itself is older. The Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260) requires OMB guidance directing agencies to keep a current inventory of information technology vulnerable to quantum decryption, and agencies to report it, and excludes national security systems.3 Status: Binding on agencies.

Contractors And Vendors: What Is Coming

Several parts of the executive order reach beyond government. Section 5(d) gives CISA, working with NIST, 270 days to publish the minimum elements of a CBOM, due around 19 March 2027. Section 6(c) gives the FAR Council 180 days, to about 19 December 2026, to propose a rule requiring covered contractors to comply with NIST’s FIPS standards, including the post-quantum ones, by 31 December 2030. Section 6(d) adds a second proposed rule within 270 days so that contractor vulnerability disclosure programmes take in reports of cryptographic weaknesses.1 As of October 2026, neither FAR rule has been published. Status: Binding on the agencies that must act; for contractors it will be a Draft until the rule is proposed and finalised.

Procurement is already shifting. In January 2026 CISA published a list of product categories where post-quantum support is widely available, such as cloud platforms, browsers and web servers, messaging and data-at-rest encryption, and M-26-15 says agencies should require post-quantum capability when buying in those categories.4 Status: Guidance that steers federal purchasing.

Private Sector: Encryption And Disclosure Rules

For companies outside government, the binding hooks are sector rules that require strong encryption, not post-quantum migration.

NYDFS’s cybersecurity regulation, 23 NYCRR Part 500, as amended in November 2023, requires a written encryption policy that meets industry standards for nonpublic information in transit over external networks and at rest. Since 1 November 2025 it has also required a complete, documented asset inventory and multi-factor authentication for anyone accessing information systems, subject to limited exemptions.5 Status: Binding on NYDFS-regulated entities. This review found no NYDFS quantum guidance as of October 2026, but the asset inventory and the encryption policy are natural starting points for a cryptographic inventory.

The FTC Safeguards Rule requires covered financial institutions to encrypt customer information in transit over external networks and at rest, with compensating controls approved by a qualified individual where that is not feasible.6 Status: Binding. In health care, a proposed update to the HIPAA Security Rule would make encryption of electronic protected health information mandatory; it has been moved to the long-term agenda, with final action projected for July 2027.7 Status: Draft.

The SEC works through disclosure. Since 2023, public companies must report material cybersecurity incidents on Form 8-K within four business days of deciding they are material, and describe their cyber risk management annually.8 Banking and securities industry groups petitioned on 22 May 2025 for the incident item to be rescinded;9 this review found no proposed amendment as of October 2026. Status: Binding. The SEC’s amended Regulation S-P adds a duty to run an incident response programme. The notice clock starts when a firm learns that customer information has been, or probably has been, reached or used without permission. From then, the firm must tell the people whose sensitive information is, or probably is, affected as quickly as it can, and within 30 days at most. Limited exceptions apply. Compliance has applied from 3 December 2025 for larger firms and 3 June 2026 for smaller ones.10 Status: Binding.

Banking supervisors have said little on quantum. The OCC’s June 2026 cybersecurity report says banks should consider how to monitor quantum developments.11 Status: Guidance. No Federal Reserve, FDIC or FFIEC post-quantum expectation was found as of October 2026.

  1. In effect

    United States (New York) · New York State Department of Financial Services Binding

    Maintain a complete, documented asset inventory, alongside the expanded multi-factor authentication duty in section 500.12.

    23 NYCRR Part 500 (Second Amendment), section 500.13(a). Applies to NYDFS-regulated covered entities. Source · Explainer · Verified 7 Oct 2026

  2. In effect

    United States · US Securities and Exchange Commission Binding

    Smaller covered institutions must run an incident response programme. After learning of actual or probable unauthorised access to customer information, they must tell the people whose sensitive information is, or probably is, affected as quickly as they can and within 30 days at most, subject to limited exceptions.

    Regulation S-P amendments (Release 34-100155, 89 FR 47688, 3 June 2024). Applies to smaller broker-dealers, investment companies, investment advisers and transfer agents (larger entities from 3 December 2025). Source · Explainer · Verified 7 Oct 2026

  3. Upcoming

    United States · Office of Management and Budget Binding

    Submit a post-quantum cryptography migration plan to OMB and the Office of the National Cyber Director, no later than 120 days after the memorandum. The date shown is calculated by us as 120 days after 24 June 2026; the memorandum gives only the number of days.

    OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography (24 June 2026). Applies to US federal civilian agencies (excluding national security systems). Source · Explainer · Verified 7 Oct 2026

  4. Upcoming

    United States · The White House Binding

    The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, section 6(c). Applies to FAR Council; the contractor rule itself will be a proposal until finalised. Source · Explainer · Verified 7 Oct 2026

  5. Upcoming

    United States · The White House Binding

    CISA, in coordination with NIST, must release public guidance on the minimum elements of a cryptographic bill of materials within 270 days of the order. The date shown is calculated by us as 270 days after 22 June 2026.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, section 5(d). Applies to CISA and NIST (the resulting guidance is for public use). Source · Explainer · Verified 7 Oct 2026

  6. Upcoming

    United States · The White House Binding

    Agencies must support TLS 1.3 or a successor version as soon as practicable, and no later than this date, under requirements that the order directed OMB (for other systems) and NSA (for national security systems) to issue; OMB M-26-15 restates the date.

    Executive Order 14306 (6 June 2025), amending Executive Order 14144, section 4(f). Applies to US federal agencies, through OMB requirements for other systems and NSA requirements for national security systems. Source · Explainer · Verified 7 Oct 2026

  7. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(ii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  8. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(iii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

US federal post-quantum milestones and private-sector cyber rules, with live countdowns. Check the 'applies to' line: most post-quantum dates bind federal agencies only.

A Brief Word On AI

There is no comprehensive federal AI statute. Executive Order 14365 of December 2025 set up a Department of Justice task force to challenge state AI laws, but it does not itself override them.12 Several states have acted. Texas’s AI governance act took effect on 1 January 2026,13 California enacted a frontier AI transparency law (SB 53) in September 2025,14 and laws in Colorado and New York apply from 1 January 2027,1516 with New York’s frontier AI rules overseen by an office within NYDFS. Status: Binding under state law. AI Regulation At A Glance compares these with other regions, and AI Governance And Regulation covers frameworks in depth. For the global comparison, see the overview.

Footnotes

  1. The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, sections 4, 5 and 6, 22 June 2026. govinfo.gov ↩ ↩2 ↩3

  2. Office of Management and Budget, Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2 ↩3

  3. US Congress, Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260, sections 4 and 5, December 2022. govinfo.gov ↩

  4. CISA, “Product Categories for Technologies That Use Post-Quantum Cryptography Standards”, 23 January 2026. cisa.gov ↩

  5. New York State Department of Financial Services, 23 NYCRR Part 500 as amended, sections 500.12, 500.13 and 500.15, effective 1 November 2023. dfs.ny.gov ↩

  6. Federal Trade Commission, Standards for Safeguarding Customer Information, 16 CFR 314.4(c)(3). ecfr.gov ↩

  7. Office of Information and Regulatory Affairs, Unified Agenda entry RIN 0945-AA22, HIPAA Security Rule. reginfo.gov; Department of Health and Human Services, “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information”, proposed rule, 90 FR 898, 6 January 2025. federalregister.gov ↩

  8. US Securities and Exchange Commission, Release 33-11216, “Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure”, 26 July 2023. sec.gov ↩

  9. American Bankers Association and others, “Petition for Rulemaking on the Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rule”, SEC file 4-856, 22 May 2025. sec.gov ↩

  10. US Securities and Exchange Commission, “Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information”, Release 34-100155, 89 FR 47688, 3 June 2024. federalregister.gov ↩

  11. Office of the Comptroller of the Currency, “Cybersecurity and Financial System Resilience Report”, June 2026. occ.treas.gov ↩

  12. The White House, Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence”, 11 December 2025, 90 FR 58499. govinfo.gov ↩

  13. Texas Legislature, HB 149 (89th Legislature), bill history, signed 22 June 2025, effective 1 January 2026. capitol.texas.gov ↩

  14. Office of the Governor of California, “Governor Newsom signs SB 53, advancing California’s world-leading artificial intelligence industry”, 29 September 2025. gov.ca.gov ↩

  15. Colorado General Assembly, SB 26-189, signed 14 May 2026. leg.colorado.gov ↩

  16. New York State Senate, S8828, signed 27 March 2026 (Chapter 96). nysenate.gov ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.