On June 22, 2026, the White House signed Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks. That order turned post-quantum cryptography from a research topic into a compliance deadline. Under Executive Order 14412, federal high value assets must use quantum-resistant key establishment by December 31, 2030 and quantum-resistant digital signatures by December 31, 2031. Federal contractors come next. The first big milestone, implementation guidance from the Office of Management and Budget, falls due on or about September 20, 2026, 90 days after signing.
For more than 20 years, ibm/SEIMless has helped organizations build networks that protect people as well as data: patients, account holders, policyholders and employees who trust us with their information. Our view is that a quantum deadline is really a promise to those people. This guide explains what Executive Order 14412 requires, who it reaches beyond federal agencies, and what your organization can do in the next 270 days to get ahead of it.
| QUICK ANSWER
What is Executive Order 14412? Executive Order 14412 is a U.S. presidential order signed June 22, 2026 (91 FR 38483). It requires federal agencies to move high value assets and high-impact systems to NIST-approved post-quantum cryptography (PQC). Key establishment must be quantum-safe by December 31, 2030 and digital signatures by December 31, 2031. The order also directs the FAR Council to propose a rule requiring covered federal contractors to comply with NIST’s PQC-inclusive FIPS standards by December 31, 2030. |
Key Takeaways
- For the most sensitive federal systems, the target moves from the 2035 goal to 2030 (encryption) and 2031 (signatures).
- Contractors should expect a proposed FAR rule within 180 days of signing (around December 19, 2026), with a 2030 compliance date.
- Within 270 days, CISA and NIST are to define minimum elements for a cryptographic bill of materials (CBOM).
- Banks, hospitals and insurers are not directly bound, but their regulators, auditors and customers will likely treat Executive Order 14412 as the new benchmark.
Start with data in motion. Traffic captured today can be decrypted once a capable quantum computer exists.
Why Executive Order 14412 Arrived Now
The federal government has been preparing for this moment for years. National Security Memorandum 10 (May 2022) set a goal of mitigating as much quantum risk as feasible by 2035. OMB Memorandum M-23-02 required agencies to inventory quantum-vulnerable cryptography every year. Congress then wrote inventory duties into law with the Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260).
The standards arrived in August 2024. NIST published FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures and FIPS 205 (SLH-DSA) for
hash-based signatures. In March 2025, NIST selected HQC as a backup key-encapsulation algorithm. Its draft NIST IR 8547 proposes deprecating RSA and elliptic-curve algorithms after 2030 and disallowing them after 2035.
The timeline got shorter
Two developments pushed the government to move faster. First, the industry’s own estimates changed. On March 25, 2026, Google announced a 2029 target for its own PQC migration. It pointed to progress in quantum hardware, advances in error correction and new resource estimates for quantum factoring. Second, oversight bodies found gaps. A June 2025 GAO report concluded that the national quantum cybersecurity strategy lacked clear objectives and performance measures.
Behind both sits the threat we have written about in our harvest now, decrypt later analysis: adversaries record encrypted traffic today and wait for the quantum capability to read it. If your data has to stay confidential for ten years or more, it is already at risk. For the math behind that risk, see Shor’s algorithm explained.
What Executive Order 14412 Requires: The Deadline Calendar
The White House fact sheet gives a summary, but the order text sets the milestones. Here they are on one calendar. Dates shown as “on or about” are counted from the June 22, 2026 signing date. Official agency dates may differ.
| When | Milestone | Who |
| On or about Jul 22, 2026 (30 days) | Each agency names a PQC migration lead who reports to the CIO | All agencies |
| On or about Sep 20, 2026 (90 days) | OMB guidance: agencies review their inventories of high value assets and high-impact systems and submit migration plans | OMB, National Cyber Director, CISA |
| On or about Dec 19, 2026 (180 days) | NIST starts a PQC pilot on its own systems and speeds up module validation. The FAR Council proposes the contractor compliance rule. | NIST, FAR Council |
| Jan 1, 2027 | New National Security System acquisitions must comply with CNSA 2.0 (a separate NSA track) | NSA / NSS owners |
| On or about Mar 19, 2027 (270 days) | Guidance on minimum elements of a cryptographic bill of materials. The FAR Council proposes adding cryptographic vulnerabilities to contractor disclosure programs. | CISA, NIST, FAR Council |
| Dec 31, 2027 | NIST pilot migration complete | NIST |
| Dec 31, 2030 | PQC key establishment on high value and high-impact systems. Covered contractors comply with PQC-inclusive FIPS. | Agencies, contractors |
| Dec 31, 2031 | PQC digital signatures on high value and high-impact systems | Agencies |
Sources: Federal Register, EO 14412; NSA CNSA 2.0 FAQ.
“High-impact” means systems rated high under FIPS 199. “High value assets” are the systems designated under OMB M-19-03. These are the systems whose compromise would hurt the most.
Two deadlines, two different problems
Executive Order 14412 splits the migration in two for a reason. Key establishment (the handshake that protects data in transit) comes first because it is the target of harvest-now-decrypt-later attacks. Much of that work can happen at the network layer, often without touching applications. Digital signatures come a year later because they run through certificate authorities, code-signing pipelines, firmware and identity systems. Post-quantum signatures are also larger, and that affects handshake performance. If certificates already strain your team, read our guide to certificate lifecycle management in 2026 before you plan the signature phase.
Who Executive Order 14412 Really Reaches
The order is written for federal agencies, but its effects spread outward through contracts, supply chains and regulators.
Federal contractors and the FAR flow-down
Contractors already handle federal information under clauses such as FAR 52.204-21. Executive Order 14412 directs the FAR Council to propose a rule requiring covered contractors to comply with NIST’s FIPS standards, including the PQC algorithms, by December 31, 2030. A second proposed rule would require contractor vulnerability disclosure programs to cover cryptographic weaknesses, including “the use of non-FIPS approved algorithms.” Neither rule has been proposed yet. Expect flow-down clauses to pass these obligations from prime contractors to subcontractors and managed service providers.
The defense industrial base
One day after the order, the Department of War released its Post-Quantum Cryptography Strategy. The strategy says every system must support PQC by the end of 2030 or be phased out, and must use PQC by the end of 2031. It also commits to moving the defense industrial base to PQC through the CMMC program, whose own rollout schedule is still changing. For National Security Systems, NSA’s CNSA 2.0 advisory keeps its own timeline.
Cloud, SaaS and technology vendors
Providers authorized through FedRAMP should expect PQC questions in authorization packages. CISA has already published a list of product categories that use PQC standards (January 2026). The list signals where federal buyers will look first: cloud services, web software, endpoint security and networking. If you sell technology, PQC support is quickly becoming a requirement to be considered at all.
Financial services, healthcare and insurance
These sectors are not named in Executive Order 14412, but they sit close to it. Public companies already report material cyber incidents under the SEC’s 2023 disclosure rules. New York’s NYDFS Part 500 now requires asset inventories. Banks follow FFIEC cybersecurity guidance, and healthcare organizations protect patient data under the HIPAA Security Rule. All of these frameworks draw on NIST. In our experience, once the federal government sets a date, examiners, auditors and cyber insurers start using it as the benchmark for “reasonable” security. For AI-driven risk in the same sectors, see our analysis of blind agent transfer in financial services.
The Inventory Problem Executive Order 14412 Exposes
You cannot migrate cryptography you cannot find. Federal agencies have had inventory duties since 2023, and CISA published a strategy for automated PQC discovery and inventory tools to help. The NIST National Cybersecurity Center of Excellence runs a Migration to Post-Quantum Cryptography project focused on the same problem. Even so, most private organizations still cannot produce a complete cryptographic inventory when asked.
That is why the order’s CBOM milestone matters. A cryptographic bill of materials lists the algorithms, key lengths, libraries, certificates and protocols inside a product or system. Once CISA and NIST define its minimum elements, expect CBOMs to show up in procurement questionnaires next to software bills of materials.
Where quantum-vulnerable cryptography hides
- WAN and VPN tunnels: IPsec and TLS overlays in SD-WAN deployments and site-to-site links. See how quantum computing affects security protocols.
- Carrier transport: traffic that is assumed to be private but is often unencrypted. Ask whether your MPLS traffic is safe.
- Edge devices: firewalls, load balancers and TLS terminators. These are the attack surface we covered in network edge security in 2026.
- Stored data: backups, archives and databases encrypted with keys protected by RSA or ECC.
- Identity and signing: PKI, code signing, firmware updates, SSO tokens and machine identities.
- Third parties: SaaS APIs, payment processors and managed service providers whose cryptography you do not control.
Crypto-Agility: The Capability Executive Order 14412 Quietly Demands
The PQC algorithms will keep changing. HQC is still being standardized, and implementation guidance keeps evolving. NIST’s CSWP 39 on crypto-agility, updated in June 2026, describes how to design systems so algorithms can be replaced without rebuilding them. NIST SP 800-227 gives recommendations for using key-encapsulation mechanisms such as ML-KEM.
Validation matters too. Executive Order 14412 directs NIST to speed up the Cryptographic Module Validation Program, and federal buyers will increasingly ask for modules validated under FIPS 140-3. Adoption is already underway: Cloudflare reports that more than two-thirds of browser traffic to its network uses post-quantum encryption. The network layer is where many enterprises can move fastest, because a quantum-safe transport protects every application that runs over it. That idea is the basis of our post-quantum cryptography migration playbook.
A 270-Day Executive Order 14412 Readiness Plan
This plan follows the order’s own 30/90/180/270-day structure, adapted for private-sector organizations. It fits contractors, regulated enterprises and any company that holds long-lived sensitive data.
Days 0–30: Assign ownership
- Name a PQC migration lead who reports to the CIO or CISO, as the order requires of agencies.
- Brief the board on Executive Order 14412, the 2030 and 2031 dates, and your harvest-now-decrypt-later exposure.
- List the data that must stay confidential beyond 2030: patient records, financial records, intellectual property and legal files.
Days 31–90: Build a quantum impact inventory
- Run automated discovery across networks, endpoints and cloud. Rank systems by impact rather than waiting for a perfect audit.
- Send vendors a PQC questionnaire covering their algorithm roadmap, FIPS 140-3 validation status and whether they can supply a CBOM.
- Map your cryptography to the CISA PQC initiative categories so reports use a consistent vocabulary.
Days 91–180: Protect data in motion first
- Put quantum-resistant protection on your highest-risk WAN links, data center interconnects and cloud on-ramps.
- Pilot hybrid (classical plus PQC) key exchange and measure latency and compatibility.
- Track the FAR Council’s proposed rule and comment on it if you are a federal supplier.
Days 181–270: Prepare for CBOMs, disclosure and signatures
- Get your inventory into a form that can meet the coming CBOM requirements.
- Update your vulnerability disclosure policy to accept reports of cryptographic weaknesses.
- Draft the PKI and code-signing roadmap for the 2031 signature deadline, and budget for 2027–2031.
How ibm/SEIMless Helps You Meet Executive Order 14412
ibm/SEIMless combines more than 20 years of vendor-agnostic carrier, cloud and communications experience with its role as OEM of Exodus QRN quantum-resistant networking. That combination lets us work at the layer where Executive Order 14412 can be met fastest.
- Exodus QRN Data in Motion protects traffic across WAN, cloud and data center links against harvest-now-decrypt-later collection.
- Exodus QRN Data at Rest and Exodus Transparent Encryption protect stored data without rewriting applications.
- Exodus Key Management centralizes the key lifecycle so you can change algorithms quickly.
- QR Edge, the Exodus NxtGen Firewall and Zero Trust Content Security harden the edge. For background, read what zero trust means.
- MPLS replacement solutions and cloud services modernize transport while you migrate.
We encourage every buyer to ask each vendor, ibm/SEIMless included, for its exact algorithm list, validation status and CBOM plan. We are glad to walk you through ours. To see how the pieces fit, explore Exodus QRN infrastructure for the post-quantum era and why quantum-resistant networking is becoming a business necessity.
Frequently Asked Questions About Executive Order 14412
What is Executive Order 14412?
Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” was signed June 22, 2026. It requires federal agencies to move high value assets and high-impact systems to NIST-approved post-quantum cryptography, and it starts rulemaking that will extend PQC requirements to federal contractors.
When do the Executive Order 14412 deadlines take effect?
Agencies had 30 days to name migration leads. OMB guidance is due at 90 days (on or about September 20, 2026). The contractor rule is due to be proposed at 180 days, and CBOM guidance at 270 days. PQC key establishment is required by December 31, 2030 and PQC digital signatures by December 31, 2031.
Does Executive Order 14412 apply to private companies?
Not directly, with one major exception. Federal contractors will be covered once the FAR Council finalizes its rule, which proposes compliance by December 31, 2030. Other private organizations will feel the order through supply-chain flow-downs, customer requirements and regulators that rely on NIST standards.
What is a cryptographic bill of materials (CBOM)?
A CBOM is a machine-readable inventory of the cryptographic algorithms, keys, certificates, libraries and protocols in a product or system. Executive Order 14412 directs CISA and NIST to define its minimum elements so cryptographic risk can be assessed automatically.
How is Executive Order 14412 different from NSM-10 and OMB M-23-02?
NSM-10 set a 2035 goal, and M-23-02 required annual inventories. Executive Order 14412 adds binding 2030 and 2031 dates for the most sensitive federal systems, a named migration lead in every agency, procurement rules for contractors and CBOM guidance.
What should my organization do first?
Assign an executive owner, identify data that must stay confidential beyond 2030, and protect data in transit on your highest-risk links. Network-layer quantum-resistant protection can deliver results in months while application and PKI work continues.
Don’t Wait for the FAR Rule. Start Your Quantum-Safe Transition Today.
Executive Order 14412 sets the dates, but the people who depend on your organization need protection now. ibm/SEIMless and Exodus QRN can help you inventory your cryptography, protect data in motion and build a practical migration plan for your board.
- Call: 646-546-5245
- Email: in**@**********ss.com
- Visit: One Liberty Plaza, New York, NY 10006
More resources: About ibm/SEIMless · FAQs · Blog · Agentic AI security meets Q-Day















