
Post-Quantum Cryptography Pt. 2 – Securing Against the Quantum Threat
August 26, 2026
Last year, we talked about preparing for a Post-Quantum Cryptography (PQC) future, as threat actors continued to adopt the “Harvest Now, Decrypt Later” approach. Now, the time has officially come to take action and secure against the quantum threat.
In the last few months, the government has issued several key mandates requiring federal agencies to adopt PQC. These directives have accelerated the previous PQC frameworks (listed in Part 1) into an updated, legally-binding migration timeline.
- Executive Order (EO) 14412, Securing the Nation Against Advanced Cryptographic Attacks: Agencies must complete full migration of their information systems to PQC by December 31, 2031.
- The Office of Management and Budget (OMB) Memorandum M-26-15: Agencies must prioritize high-risk systems and submit a formal PQC Migration Plan within 120 days.
Achieving PQC Compliance: A Four-Phased Approach
To comply with the 2026 PQC mandates, federal agencies must shift from discovery to active execution. The transition requires a structured, four-phased approach across governance, inventory management, and procurement.
1. Establish Cryptographic Governance
- Appoint a PQC Lead: Designate a single point of accountability to oversee the migration (e.g. someone in the Chief Information Officer (CIO), or Chief Information Security Officer (CISO), office).
- Align Policy: Update internal agency cybersecurity policies to reflect the new full-migration deadline: December 31, 2031.
- Coordinate Oversight: Establish reporting lines to regularly update the OMB and the Office of the National Cyber Director (ONCD).
2. Maintain a Dynamic Cryptographic Inventory
- Automate Discovery: Deploy automated tools to continuously discover assets using quantum-vulnerable algorithms (e.g. RSA and ECC) across your network.
- Categorize Assets: Tag assets based on data sensitivity, system dependencies, and whether they process national security information.
- Prioritize Risk: Focus on the high-risk targets first. In “Harvest Now, Decrypt Later” attacks, threat actors target systems that house long-term classified data or personally identifiable information (PII).
3. Implement NIST-Approved Standards
- Deploy Federal Information Processing Standards (FIPS) Algorithms: Replace legacy algorithms with NIST’s principal PQC standards (ML-KEM, ML-DSA, and SLH-DSA).
- Test Agility: Build "cryptographic agility" into IT architectures, allowing systems to swap encryption algorithms without breaking core functionality.
- Phase Out Old Protocols: Create a strict schedule, ahead of the 2031 deadline, for sunsetting legacy protocols.
4. Upgrade Procurement and the Supply Chain
- Audit Vendors: Require IT contractors and commercial vendors to provide a Software Bill of Materials (SBOM) that identifies any quantum-vulnerable components.
- Update FAR Clauses: Insert updated Federal Acquisition Regulation (FAR) clauses into new contracts, mandating that vendors supply PQC-ready products.
- Enforce Vendor Compliance: Vendors’ encryption software must meet federal vulnerability disclosure policies by the end of 2030.
In order to mitigate the “Harvest Now, Decrypt Later” threat, it is vital that Federal agencies accelerate their PQC compliance immediately. Recent mandates reflect the urgency and importance of this timeline, requiring full agency migration by December 31, 2031.
If your organization is planning (or actively navigating) a PQC migration, reach out to our team today to learn how the right partner can streamline the process, reduce risk, and accelerate your path to quantum-safe security.





