A federal deadline for the quantum era
President Trump signed Executive Order 14412 on June 22, 2026, requiring federal agencies to move their most sensitive systems to post-quantum encryption by December 31, 2030, and to post-quantum authentication by December 31, 2031. The order also directs the FAR Council to write rules compelling federal contractors to meet post-quantum Federal Information Processing Standards by the end of 2030.
Federal procurement has historically been a powerful lever for pushing new technology across the broader economy. The U.S. government drove adoption of IPv6, routing security with RPKI, and DNSSEC through similar mandates. This order continues that tradition with post-quantum cryptography, and it arrives at a moment of accelerating risk. In April 2026, Cloudflare moved its own target for full post-quantum security to 2029, following research breakthroughs from Google and Oratomic. That has effectively accelerated the projected timeline for Q-Day — the point at which quantum computers can break RSA and Elliptic Curve Cryptography. NIST's earlier 2024 guidance had slated those algorithms for deprecation by 2030 and disallowal by 2035.
What the order applies to
The binding requirements target federal High Value Assets (HVAs) and high impact systems. HVAs, designated by OMB, are systems whose compromise would significantly harm national security, foreign relations, or public confidence. High impact systems carry a FIPS 199 rating of "high" for confidentiality, integrity, or availability, meaning a breach could cause loss of life, major financial damage, or substantial degradation of an agency's mission.
The order binds federal agencies but not critical infrastructure operators, state and local governments, academia, or civil society. That is why deadlines are only imposed on agencies:
Date | Requirement |
|---|---|
July 2026 | Each federal agency head identifies a PQC migration lead and provides their name and contact details to OMB and the National Cyber Director. |
September 2026 | OMB issues guidance requiring each agency to: (1) review their inventory of HVAs and high impact systems; (2) plan for PQC migration; and (3) submit that plan to OMB and the National Cyber Director. |
December 2030 | All HVAs and high impact systems must be transitioned to PQC for key establishment. |
December 2031 | All HVAs and high impact systems must be transitioned to PQC for digital signatures. |
National Security Systems sit outside these requirements entirely. The NSA manages them on a separate classified track with deadlines between 2030 and 2033, which were set back in 2022.
Encryption and authentication: two tracks, one race
The order splits the transition into two phases, and that split reflects reality. Post-quantum encryption is broadly deployable now, while post-quantum authentication is not. Cloudflare's own post-quantum roadmap targets full readiness including authentication by 2029, but the company is among the earliest adopters in the industry.
The order wisely anchors on NIST-standardized post-quantum algorithms rather than Quantum Key Distribution. QKD does not scale to the Internet because it requires dedicated physical links and specialized hardware between sender and receiver.
Post-quantum encryption addresses the harvest-now-decrypt-later threat, where an adversary records encrypted traffic today and decrypts it once quantum computers mature. This matters most for organizations that handle data with a shelf life of three to ten years: government agencies, banks, healthcare providers, defense contractors, and telecoms.
Post-quantum authentication prevents a future adversary with a quantum computer from forging certificates, signing malicious code, or gaining unauthorized access. Unlike encryption, this migration only becomes essential once a cryptographically-relevant quantum computer exists — but that day may not be far off. The order sets the authentication deadline for 2031, which signals the government considers a CRQC operationally possible around that time. The same day the executive order was signed, President Trump also issued a separate order to accelerate quantum computing deployment and commercialization.

Authentication is the harder migration for several reasons:
- ML-DSA digital signatures are larger than their classical counterparts, which can hurt performance in short-lived TLS connections.
- The dependency chain is longer, requiring coordinated upgrades across clients, servers, certificate authorities, certificate transparency logs, root stores, and browsers.
- Ecosystem deployment of post-quantum authentication is minimal compared with encryption.
The one-year gap between the encryption and authentication deadlines is tight. These tracks cannot proceed sequentially; the ecosystem must work on both in parallel, or the 2031 deadline will slip.
Standards work lives with the IETF. The TLS community is furthest along, with the PLANTS working group making progress on post-quantum certificates for TLS. Considerable work remains elsewhere in the protocol stack.
Pressure through the supply chain
The contract requirements may prove to be the order's most far-reaching element. The FAR Council must publish proposed rules requiring covered contractors to comply with NIST FIPS that incorporate post-quantum algorithms by December 31, 2030. Contractors must also implement vulnerability disclosure programs covering cryptographic vulnerabilities. These rules will go through notice-and-comment rulemaking, but the deadline is set one year earlier than the agency authentication deadline, so vendors are ready before their government customers need them.
CISA's recently published guidance, Product Categories for Technologies That Use Post-Quantum Cryptography Standards, divides product categories by readiness. Cloud platforms, web browsers and servers, chat and messaging software, and endpoint security products such as full disk encryption are already "widely available" in PQC-capable versions. For these, CISA advises procuring only PQC-capable products. Networking hardware, identity and access management systems, email servers, and databases are still "transitioning."
Together, the contractor deadline and the procurement guidance force the vendor ecosystem to ship PQC-compliant products on a fixed schedule. Products built to meet federal requirements will reach hospitals, banks, universities, and small businesses. Cloudflare, already subject to these rules as a vendor in the widely available category, has shipped post-quantum encryption across most of its products at no additional cost.
What “transition” actually means
The executive order tells agencies to “transition” systems to post-quantum cryptography, but it never defines the endpoint. Does a system that merely supports ML-KEM count, or must it reject classical-only handshakes entirely? The distinction matters: a server that offers post-quantum key exchange but still accepts a classical TLS handshake can be forced back to the weaker mode by an adversary who intercepts traffic. That leaves the same quantum-vulnerable connection the order aims to eliminate.
The SSLv3 deprecation after the POODLE attack is a cautionary tale. Servers kept the old protocol enabled for years for backwards compatibility, letting attackers force downgrades and exploit known weaknesses. A clear definition of “done” that includes disabling quantum-vulnerable algorithms is needed to avoid repeating that mistake.
Crypto agility and inventories
The EO mandates a shift to specific NIST standards but says nothing about building systems that can swap algorithms again in the future. Crypto agility doesn’t mean supporting every algorithm simultaneously; it means architecting so that a future algorithm change is a configuration update rather than a re-architecture. OMB’s implementation guidance should make that an explicit requirement.
On inventories, the EO directs CISA and NIST to publish minimum elements for a cryptographic bill of materials (CBOM) within 270 days. In theory, a CBOM — a list of every algorithm, protocol, and implementation in a product — is useful. In practice, exhaustive inventories are slow to produce, may go stale before completion, and only capture what’s already in use. They don’t flag systems that should be using cryptography but aren’t, and listing keys without understanding their purpose does little to assess actual risk.
A more productive framing is a quantum impact inventory: what happens if a system or its data is compromised, how likely is that, and what mitigations apply? A drop-in replacement, software update, or compensating control like tunneling traffic over a post-quantum connection are all options. That approach directs effort toward the most exposed systems first, with a full CBOM filled in over time if the organization needs one.
OMB guidance should also address cost. If post-quantum security becomes a paid add-on, underfunded agencies and critical infrastructure operators will lag, and national resilience fails. Policy should resist vendor lock-in and pricing models that treat PQC as a premium tier.
Start now, not in 2030
There’s no reason to wait for the statutory deadlines or for a complete cryptographic inventory to begin migrating. Past cryptographic transitions have taken years, and the 2031 authentication deadline will arrive faster than procurement cycles suggest.
Immediate steps for any organization:
- Protect Internet-facing traffic first. Public traffic is the easiest for adversaries to harvest now. If your web traffic flows through Cloudflare, those connections are already largely covered by post-quantum encryption, and Cloudflare One extends that protection to private network traffic. If your provider doesn’t support post-quantum encryption, switch to one that does — even before individual applications inside your network are upgraded.
- Update procurement language. Require post-quantum encryption by default at no extra cost, with a roadmap for post-quantum authentication and crypto agility, in every technology purchase. Vendors without a plan should be questioned or replaced.
- Run a quantum impact inventory. Internal traffic is less exposed to harvest-now-decrypt-later risk since an adversary would need network access to capture it. Still, prioritize internal systems that handle sensitive data or touch the public Internet.
- Plan authentication now. Long-lived keys, root certificates, and code-signing infrastructure face the longest dependency chains and are prime quantum targets. Update software libraries and automate certificate provisioning now, even if post-quantum certificates aren’t yet available in your ecosystem.
The case for one global standard
Section 5(b) of the EO directs the State Department to encourage foreign adoption of NIST-standardized algorithms. That matters because cryptography migrations don’t happen in national isolation — two ends of a TLS connection must agree on the same algorithms.
NIST’s process has always been international. The AES competition selected a cipher designed by Belgian cryptographers; SHA-3 came from a Belgian-Italian team; ML-KEM, now the standard key agreement for post-quantum TLS, was largely built by European researchers. The winning algorithms are open and globally vetted, not U.S.-specific.
Fragmentation is the real risk. If jurisdictions mandate different algorithms, the result is cipher bloat and a larger attack surface: more code to write, test, and audit, plus more downgrade opportunities. It happened in IPsec, where the absence of an interoperable standard pushed vendors to ship proprietary post-quantum key agreement that couldn’t inter operate, delaying rollout for years. TLS avoided that by converging on a single hybrid key agreement, X25519MLKEM768, and deployment followed quickly.
What’s needed now is enough alignment among allied nations — common adoption of the same NIST algorithms, shared timelines, and mutual recognition of modules — that the Internet keeps working as one network with one cryptographic baseline. NIST should also get the resources it needs to deliver on the EO’s requirements alongside other demands like the AI Action Plan.
CMVP gets a long-overdue reset
The executive order also directs NIST to overhaul the Cryptographic Module Validation Program (CMVP) so that module validations move faster (Sec. 6(b)). After years of wrangling with CMVP, we're glad to see this in the order.
CMVP exists for a legitimate purpose: federal agencies and their contractors need assurance that a product's cryptography actually behaves as claimed — that AES is correctly implemented, that random number generators carry sufficient entropy. The program was designed for a steady state where cryptography changes infrequently.
That model doesn't fit the coming migration. CMVP needs to accommodate the realities of an accelerated transition, and the FedRAMP update stream — which allows updated modules into use before final validation — is a welcome move in that direction. It enables faster adoption of post-quantum cryptography and quick corrections to implementation flaws missed during validation. CMVP needs equivalent flexibility.
Start with what's exposed
This post-quantum executive order is a genuine milestone. It imposes concrete deadlines and puts supply chain pressure behind industry-wide adoption. For organizations beginning their own migration, the priority should be protecting public-facing Internet traffic and updating procurement requirements. A quantum impact inventory can follow, but don't let an incomplete cryptography inventory delay deploying post-quantum encryption on your most sensitive systems right away.
Internet-wide cryptographic deployment depends on standards from the IETF. The TLS community has made the most progress, but other protocol groups still have substantial work ahead. Expect further effort there in the coming months.
The path forward is to push post-quantum cryptography broadly, and quickly. Free TLS helped encrypt the web; free post-quantum cryptography will help secure it for the next generation. Cloudflare's PQC page has resources to start now.



